To protect a Facebook or Instagram account from hackers, turn on two-factor authentication with an authenticator app or security key (not just SMS), use a unique password, regularly check where you’re logged in, and remove apps you don’t recognise. Those four steps map directly to the four ways accounts actually get taken over: credential phishing, SIM swap, session theft and abuse of app permissions.
This post is written for people starting a cybersecurity career, so it goes further than a tips list. For each attack path you’ll see how it works technically, what defenders and SOC analysts can see, and what to practise. The recovery checklist at the end is built on Meta’s own help pages, and it works just as well for a friend who has just messaged you in a panic.
Everything here is for defence and learning. Only test systems and accounts you own or have written permission to test.
How do Facebook and Instagram accounts get hacked?
Almost every takeover is one of four paths, often chained together.
1. Credential phishing (including “Meta Support” lures)
The attacker gets you to type your password, and often your one-time code, into a page they control. Common lures:
- A message claiming your Page will be disabled for a copyright violation unless you “appeal” within 24 hours.
- A fake “verified badge” or “blue tick application”.
- A friend’s (already compromised) account asking you to vote in a competition, which leads to a fake login page.
Modern phishing kits often work as a real-time relay: as you type your password and your SMS or app code, the kit replays them to the genuine site and logs in at the same moment. That’s why a code from SMS or an authenticator app doesn’t fully stop phishing, while a security key does. A security key checks the website’s real domain before it responds, so a lookalike page gets nothing usable. Meta supports security keys as a two-factor method (Meta: how security keys work).
What defenders see: in an organisation, the lure usually arrives by email or direct message. Email gateways flag lookalike sender domains; web proxy logs show staff visiting newly registered domains with “meta”, “support” or “appeal” in the name. On Meta’s side, a login from a new device and location triggers alerts to the account owner.
2. SIM swap
The attacker convinces or bribes someone at a mobile network to move your number to a SIM they control, then requests SMS reset codes. MITRE ATT&CK tracks this as T1451, SIM Card Swap. It’s especially damaging where a phone number is both the recovery method and the second factor.
What defenders see: the victim’s phone suddenly shows “No service” or “SIM not provisioned”; password-reset emails or SMS arrive that the owner didn’t request. Telecom fraud teams see a SIM replacement followed quickly by account resets. For individuals, the defence is to stop relying on SMS: use an authenticator app or security key as your second factor and keep Meta’s recovery codes somewhere safe. Meta’s help centre says you can get 10 recovery codes to use when you can’t use your phone (Meta: how two-factor authentication works).
3. Session theft (cookie theft)
Once you’ve logged in, the site gives your browser a session cookie so you don’t log in on every page. Steal that cookie and you are logged in, with no password or second factor needed. MITRE describes this as T1539, Steal Web Session Cookie, and notes that stolen session cookies can bypass some multi-factor authentication. Two main routes:
- Infostealer malware, often hidden in cracked software, fake “AI photo editor” downloads or game cheats. It reads the browser’s cookie and password stores and uploads them.
- Adversary-in-the-middle phishing, where the relay kit from path 1 captures the session cookie the real site issues after login.
What defenders see: endpoint tools flag a non-browser process reading browser cookie databases. On the platform side, a session suddenly appearing from a different country or device type, without a fresh login, is the signature. For the owner, the tell-tale sign is an unfamiliar entry under “Where you’re logged in”.
4. OAuth consent and app-permission abuse
Here the attacker doesn’t take your password at all. You click “Continue with Facebook” on a quiz, a “see who viewed your profile” tool or a fake business tool, and grant it permissions. Depending on what you approve, the app may access profile data or Pages. For organisations, a related pattern is a fake partner requesting access to a business’s Page or ad account. MITRE’s related technique is T1528, Steal Application Access Token.
What defenders see: an unfamiliar app under the account’s connected apps list, or a new partner or admin on a business asset that nobody remembers adding. Meta explains how to find and remove apps you’ve connected in its help page on removing apps and games from Facebook.
The quiet multiplier: password reuse
If your Instagram password is the same as one leaked from another site, attackers can simply try it (“credential stuffing”). Unique passwords from a password manager remove this path completely. Our explainer on passwords, passkeys and MFA covers why.
How defenders detect a social media account takeover
Whether you’re protecting a brand’s Page in a SOC or helping a family member, the signals are similar.
| Signal | Likely attack path | Where you see it |
|---|---|---|
| Login alert from an unknown device or location | Phishing, credential stuffing | Meta login alerts, email |
| Unrequested password-reset or code messages | Phishing in progress, SIM swap | Email, SMS |
| Phone loses signal unexpectedly, then resets arrive | SIM swap | Handset, mobile network |
| Unfamiliar session in “Where you’re logged in” with no login alert | Session theft | Account security settings |
| Email or phone on the account changed | Takeover completed | Security email from Meta to the old address |
| Unknown app, partner or admin on a Page or ad account | OAuth or permission abuse | Connected apps list, business settings |
| Ad spend appearing on a business card you don’t recognise | Business account takeover | Payment notifications |
A detection exercise you can run in your own lab
SOC analysts often hunt for infostealers by watching who touches browser credential files. You can practise this on a Linux VM you own. Chrome on Linux keeps cookies in ~/.config/google-chrome/Default/Network/Cookies. Add an audit rule:
sudo auditctl -w /home/analyst/.config/google-chrome/Default/Network/Cookies -p r -k browser_cookies
Now read the file with something that isn’t Chrome, as an infostealer would (a harmless copy here):
cp ~/.config/google-chrome/Default/Network/Cookies /tmp/c.db
sudo ausearch -k browser_cookies -i | grep -E “comm=|exe=” | tail -2
type=SYSCALL msg=audit(10/10/2026 19:42:07.311:418) : arch=x86_64 syscall=openat success=yes exit=3 ppid=2210 pid=2391 auid=analyst uid=analyst comm=cp exe=/usr/bin/cp key=browser_cookies
The detection logic is simple and real: reads of the cookie database by any executable other than the browser itself are suspicious. Endpoint detection products apply the same idea at scale. Write that down as a one-line rule, and you’ve done the first half of a SOC analyst’s day.
The incident response view for a company Page or account
When a company’s Facebook Page or Instagram account is taken over, treat it as a security incident, not a social media problem.
- Contain: use Meta’s recovery flow from a device the admin has logged in from before. Revoke sessions, remove unknown admins, partners and apps.
- Scope: which admin account was compromised first, and how? Check the admin’s mailbox for the lure, their laptop for infostealer activity, and their phone for SIM-swap signs.
- Eradicate: if malware is involved, rebuild the device. A password reset on an infected laptop just hands the attacker the new password.
- Recover: restore content, warn followers about any messages or posts the attacker sent, and contact your bank if ad payments were made.
- Learn: move all admins to authenticator apps or security keys, cut the number of admins, and write the incident up.
The UK’s National Cyber Security Centre publishes a useful general sequence in its guidance on recovering a hacked account, including checking email forwarding rules, which attackers often set up on the mailbox behind the social account.
Recovery checklist: if your Facebook or Instagram account is hacked
Work through this in order. Speed matters most in the first hour.
- Go to facebook.com/hacked from a device you’ve used to log in before. Meta’s help page on recovering a hacked account explains the flow, including options if you’ve lost access to your email or phone.
- If you can still log in, change your password and log out every other session via Accounts Centre, Password and security, “Where you’re logged in” (Meta: log out on another device).
- Check the email and phone on the account. Remove anything that isn’t yours.
- Turn on two-factor authentication with an authenticator app or security key, and save your recovery codes offline.
- Remove unfamiliar apps and games (Meta help).
- If you manage a Page or ad account, review who has access and remove anyone unknown.
- Check your email, including spam, for a message from
security@mail.instagram.comabout a changed email address. Meta sends this to the original address, and it can include a link to reverse the change and secure the account. - Use instagram.com/hacked to choose your situation (hacked, lost two-factor access, and so on) and request a login link or security code.
- Meta may ask you to verify your identity, for example with a video selfie, if your account has photos of you. Use only the in-app or official flow.
- Once in, change your password, log out other sessions, and review your linked Facebook account and Accounts Centre.
Both platforms
- Secure the email account behind the social account first if it was also compromised: new password, check forwarding rules and recovery details.
- Warn your contacts that messages sent from your account recently may be fake, especially requests for money.
- Scan or rebuild any device you suspect, particularly if you recently installed cracked software.
- Never pay “recovery hackers”. People who message you offering to recover your account for a fee are, in practice, a second scam. Meta’s recovery flows are free.
Prevention: the defender’s hardening checklist
| Control | Stops | How |
|---|---|---|
| Security key 2FA | Phishing (including real-time relay), SIM swap | Accounts Centre, Password and security, Two-factor authentication (Meta) |
| Authenticator app 2FA | SIM swap, password-only attacks | Accounts Centre, Password and security, Two-factor authentication (Meta) |
| Unique password from a password manager | Credential stuffing | Generate a new one per site |
| Login alerts on | Slow-burn takeovers | Accounts Centre security settings |
| Monthly check of “Where you’re logged in” | Session theft | Log out anything you don’t recognise |
| Quarterly app review | OAuth abuse | Settings, Apps and websites |
| No cracked software on devices you log in from | Infostealers | Install only from official stores and vendors |
| Fewest possible admins on business Pages | Business account takeover | Remove former staff and agencies |
Account takeover follows the same patterns across platforms; see how attackers hijack WhatsApp in our WhatsApp account takeover explainer, and the wider principles in how account takeovers work and how defenders stop them.
What a cybersecurity beginner can practise from this
- Build the audit-rule exercise above and write it as a detection rule in plain English.
- Collect five phishing lures from your own inbox’s spam folder and annotate the sender domain, the urgency trick and the landing domain (don’t click them on your main machine).
- Map each attack path to its MITRE ATT&CK technique and one control.
- Write a one-page incident playbook for “company Instagram account taken over”, using the five-step response above.