Skip to content
Security basics for everyone

Social media account takeover: how Facebook and Instagram accounts get hacked, and the defender's checklist

How to protect my Facebook account from hackers: the four takeover paths, how defenders detect them, and a recovery checklist from Meta's help pages.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

To protect a Facebook or Instagram account from hackers, turn on two-factor authentication with an authenticator app or security key (not just SMS), use a unique password, regularly check where you’re logged in, and remove apps you don’t recognise. Those four steps map directly to the four ways accounts actually get taken over: credential phishing, SIM swap, session theft and abuse of app permissions.

This post is written for people starting a cybersecurity career, so it goes further than a tips list. For each attack path you’ll see how it works technically, what defenders and SOC analysts can see, and what to practise. The recovery checklist at the end is built on Meta’s own help pages, and it works just as well for a friend who has just messaged you in a panic.

Everything here is for defence and learning. Only test systems and accounts you own or have written permission to test.

How do Facebook and Instagram accounts get hacked?

Almost every takeover is one of four paths, often chained together.

1. Credential phishing (including “Meta Support” lures)

The attacker gets you to type your password, and often your one-time code, into a page they control. Common lures:

  • A message claiming your Page will be disabled for a copyright violation unless you “appeal” within 24 hours.
  • A fake “verified badge” or “blue tick application”.
  • A friend’s (already compromised) account asking you to vote in a competition, which leads to a fake login page.

Modern phishing kits often work as a real-time relay: as you type your password and your SMS or app code, the kit replays them to the genuine site and logs in at the same moment. That’s why a code from SMS or an authenticator app doesn’t fully stop phishing, while a security key does. A security key checks the website’s real domain before it responds, so a lookalike page gets nothing usable. Meta supports security keys as a two-factor method (Meta: how security keys work).

What defenders see: in an organisation, the lure usually arrives by email or direct message. Email gateways flag lookalike sender domains; web proxy logs show staff visiting newly registered domains with “meta”, “support” or “appeal” in the name. On Meta’s side, a login from a new device and location triggers alerts to the account owner.

2. SIM swap

The attacker convinces or bribes someone at a mobile network to move your number to a SIM they control, then requests SMS reset codes. MITRE ATT&CK tracks this as T1451, SIM Card Swap. It’s especially damaging where a phone number is both the recovery method and the second factor.

What defenders see: the victim’s phone suddenly shows “No service” or “SIM not provisioned”; password-reset emails or SMS arrive that the owner didn’t request. Telecom fraud teams see a SIM replacement followed quickly by account resets. For individuals, the defence is to stop relying on SMS: use an authenticator app or security key as your second factor and keep Meta’s recovery codes somewhere safe. Meta’s help centre says you can get 10 recovery codes to use when you can’t use your phone (Meta: how two-factor authentication works).

3. Session theft (cookie theft)

Once you’ve logged in, the site gives your browser a session cookie so you don’t log in on every page. Steal that cookie and you are logged in, with no password or second factor needed. MITRE describes this as T1539, Steal Web Session Cookie, and notes that stolen session cookies can bypass some multi-factor authentication. Two main routes:

  • Infostealer malware, often hidden in cracked software, fake “AI photo editor” downloads or game cheats. It reads the browser’s cookie and password stores and uploads them.
  • Adversary-in-the-middle phishing, where the relay kit from path 1 captures the session cookie the real site issues after login.

What defenders see: endpoint tools flag a non-browser process reading browser cookie databases. On the platform side, a session suddenly appearing from a different country or device type, without a fresh login, is the signature. For the owner, the tell-tale sign is an unfamiliar entry under “Where you’re logged in”.

4. OAuth consent and app-permission abuse

Here the attacker doesn’t take your password at all. You click “Continue with Facebook” on a quiz, a “see who viewed your profile” tool or a fake business tool, and grant it permissions. Depending on what you approve, the app may access profile data or Pages. For organisations, a related pattern is a fake partner requesting access to a business’s Page or ad account. MITRE’s related technique is T1528, Steal Application Access Token.

What defenders see: an unfamiliar app under the account’s connected apps list, or a new partner or admin on a business asset that nobody remembers adding. Meta explains how to find and remove apps you’ve connected in its help page on removing apps and games from Facebook.

The quiet multiplier: password reuse

If your Instagram password is the same as one leaked from another site, attackers can simply try it (“credential stuffing”). Unique passwords from a password manager remove this path completely. Our explainer on passwords, passkeys and MFA covers why.

How defenders detect a social media account takeover

Whether you’re protecting a brand’s Page in a SOC or helping a family member, the signals are similar.

Signal Likely attack path Where you see it
Login alert from an unknown device or location Phishing, credential stuffing Meta login alerts, email
Unrequested password-reset or code messages Phishing in progress, SIM swap Email, SMS
Phone loses signal unexpectedly, then resets arrive SIM swap Handset, mobile network
Unfamiliar session in “Where you’re logged in” with no login alert Session theft Account security settings
Email or phone on the account changed Takeover completed Security email from Meta to the old address
Unknown app, partner or admin on a Page or ad account OAuth or permission abuse Connected apps list, business settings
Ad spend appearing on a business card you don’t recognise Business account takeover Payment notifications

A detection exercise you can run in your own lab

SOC analysts often hunt for infostealers by watching who touches browser credential files. You can practise this on a Linux VM you own. Chrome on Linux keeps cookies in ~/.config/google-chrome/Default/Network/Cookies. Add an audit rule:

sudo auditctl -w /home/analyst/.config/google-chrome/Default/Network/Cookies -p r -k browser_cookies

Now read the file with something that isn’t Chrome, as an infostealer would (a harmless copy here):

cp ~/.config/google-chrome/Default/Network/Cookies /tmp/c.db
sudo ausearch -k browser_cookies -i | grep -E “comm=|exe=” | tail -2
type=SYSCALL msg=audit(10/10/2026 19:42:07.311:418) : arch=x86_64 syscall=openat success=yes exit=3 ppid=2210 pid=2391 auid=analyst uid=analyst comm=cp exe=/usr/bin/cp key=browser_cookies

The detection logic is simple and real: reads of the cookie database by any executable other than the browser itself are suspicious. Endpoint detection products apply the same idea at scale. Write that down as a one-line rule, and you’ve done the first half of a SOC analyst’s day.

The incident response view for a company Page or account

When a company’s Facebook Page or Instagram account is taken over, treat it as a security incident, not a social media problem.

  1. Contain: use Meta’s recovery flow from a device the admin has logged in from before. Revoke sessions, remove unknown admins, partners and apps.
  2. Scope: which admin account was compromised first, and how? Check the admin’s mailbox for the lure, their laptop for infostealer activity, and their phone for SIM-swap signs.
  3. Eradicate: if malware is involved, rebuild the device. A password reset on an infected laptop just hands the attacker the new password.
  4. Recover: restore content, warn followers about any messages or posts the attacker sent, and contact your bank if ad payments were made.
  5. Learn: move all admins to authenticator apps or security keys, cut the number of admins, and write the incident up.

The UK’s National Cyber Security Centre publishes a useful general sequence in its guidance on recovering a hacked account, including checking email forwarding rules, which attackers often set up on the mailbox behind the social account.

Recovery checklist: if your Facebook or Instagram account is hacked

Work through this in order. Speed matters most in the first hour.

Facebook

  • Go to facebook.com/hacked from a device you’ve used to log in before. Meta’s help page on recovering a hacked account explains the flow, including options if you’ve lost access to your email or phone.
  • If you can still log in, change your password and log out every other session via Accounts Centre, Password and security, “Where you’re logged in” (Meta: log out on another device).
  • Check the email and phone on the account. Remove anything that isn’t yours.
  • Turn on two-factor authentication with an authenticator app or security key, and save your recovery codes offline.
  • Remove unfamiliar apps and games (Meta help).
  • If you manage a Page or ad account, review who has access and remove anyone unknown.

Instagram

  • Check your email, including spam, for a message from security@mail.instagram.com about a changed email address. Meta sends this to the original address, and it can include a link to reverse the change and secure the account.
  • Use instagram.com/hacked to choose your situation (hacked, lost two-factor access, and so on) and request a login link or security code.
  • Meta may ask you to verify your identity, for example with a video selfie, if your account has photos of you. Use only the in-app or official flow.
  • Once in, change your password, log out other sessions, and review your linked Facebook account and Accounts Centre.

Both platforms

  • Secure the email account behind the social account first if it was also compromised: new password, check forwarding rules and recovery details.
  • Warn your contacts that messages sent from your account recently may be fake, especially requests for money.
  • Scan or rebuild any device you suspect, particularly if you recently installed cracked software.
  • Never pay “recovery hackers”. People who message you offering to recover your account for a fee are, in practice, a second scam. Meta’s recovery flows are free.

Prevention: the defender’s hardening checklist

Control Stops How
Security key 2FA Phishing (including real-time relay), SIM swap Accounts Centre, Password and security, Two-factor authentication (Meta)
Authenticator app 2FA SIM swap, password-only attacks Accounts Centre, Password and security, Two-factor authentication (Meta)
Unique password from a password manager Credential stuffing Generate a new one per site
Login alerts on Slow-burn takeovers Accounts Centre security settings
Monthly check of “Where you’re logged in” Session theft Log out anything you don’t recognise
Quarterly app review OAuth abuse Settings, Apps and websites
No cracked software on devices you log in from Infostealers Install only from official stores and vendors
Fewest possible admins on business Pages Business account takeover Remove former staff and agencies

Account takeover follows the same patterns across platforms; see how attackers hijack WhatsApp in our WhatsApp account takeover explainer, and the wider principles in how account takeovers work and how defenders stop them.

What a cybersecurity beginner can practise from this

  • Build the audit-rule exercise above and write it as a detection rule in plain English.
  • Collect five phishing lures from your own inbox’s spam folder and annotate the sender domain, the urgency trick and the landing domain (don’t click them on your main machine).
  • Map each attack path to its MITRE ATT&CK technique and one control.
  • Write a one-page incident playbook for “company Instagram account taken over”, using the five-step response above.

Questions

Can someone hack my Facebook if I have two-factor authentication?

It's much harder, but SMS and app codes can be phished in real time, and stolen session cookies can bypass a login entirely. Security keys plus regular session checks close most of the gap.

How do I know if someone else is logged in to my account?

Check "Where you're logged in" under Password and security in Accounts Centre. Each entry shows device, location and time.

Will Meta contact me on Messenger about a copyright violation?

Treat any message threatening to disable your account unless you log in via a link as a phishing attempt. Check your account status from inside the official app instead.

I've lost access to my email and phone. Can I still recover my account?

Meta's hacked-account flows include options for this situation; start at facebook.com/hacked or instagram.com/hacked and follow the identity verification steps.