# Facebook Business Manager Hacked? Recover It in Malaysia

> Meta business portfolio hacked in Malaysia? Secure the admins' Facebook profiles, stop the card, use Meta's official routes, remove unknown access and lock roles down.

- URL: https://www.awarexone.com/research/facebook-business-manager-hacked-malaysia
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-28
- Topics: Facebook, Business, Malaysia
- Related service: Business Manager recovery: https://www.awarexone.com/business-manager-recovery

## Short answer

Secure the personal Facebook account of every admin first, because all business access runs through those logins. Call your bank's fraud line to block the card linked to your ad accounts. Then contact Meta Support through Meta Business Support Home. Once back in, remove unknown people, partners and system users, and require 2FA. Only Meta can restore access.

## Summary

- Secure the personal Facebook account of every admin first, because all business access runs through those logins and attackers can add themselves back.
- Call your bank's fraud line to block the card linked to your ad accounts, then pause campaigns and remove unknown payment methods if you still can.
- Contact Meta Support through Meta Business Support Home, and use the hacked Page form if a Page was taken or moved.
- Once back in, remove unknown people, partners, system users and apps, require 2FA for everyone and keep two trusted people with full control.
- Real Meta support will not ask for your login or codes, so never appeal through links in messages claiming your Page will be disabled.
- Your bank decides any dispute over the card charges, and only Meta can restore access to a business portfolio.

It is Monday morning. Your bank sends an alert for a Meta ads charge nobody on your team approved. You open Meta Business Suite and find a name you have never seen listed with full control, a new ad account running campaigns in a language you do not use, and your marketing executive's access gone. Your Facebook Page may already have been moved out of your business portfolio.

This is a business portfolio takeover, the thing most Malaysian advertisers still call a hacked Business Manager. It is stressful, and the order you act in matters. Secure the personal Facebook accounts of your admins first, because every bit of business access runs through them. Stop the money with your bank. Then use Meta's official routes and remove every way back in the attacker left.

This guide covers the signs, the first hour, which Meta route fits which problem, card disputes with Malaysian banks, and how to set up roles so one stolen login cannot take the whole business with it.

Last checked: 28 September 2026.

## What should you do if your Facebook Business Manager is hacked?

Secure the personal Facebook account of every person with full control of the portfolio first: an admin whose login was taken goes to facebook.com/hacked, and everyone else changes their password, turns on two-factor authentication and logs out of unknown sessions. Call your bank's fraud line to block the card linked to your ad accounts and flag the charges. If you still have access, pause campaigns and remove payment methods and people you do not recognise. Then contact Meta Support through Meta Business Support Home, as Meta's own guidance on compromised business portfolios advises. Once you are back in, remove unknown people, partners and system users, require two-factor authentication for everyone, and keep two trusted people with full control. Only Meta can restore access to its products, and it makes the final decision.

## What a business portfolio is, and how a takeover shows up

A business portfolio is Meta's name for what used to be called Business Manager: one place that holds your Facebook Pages, Instagram accounts, ad accounts, payment methods and the people who work on them. Meta Business Suite is the tool you use to manage it. Accounts Center is where each person manages their own Facebook login, password and two-factor authentication. People with full control (formerly the business admin role) can add and remove people, assets and partners; people with partial access work only on what they have been assigned ([Meta Business Help Center](https://www.facebook.com/business/help/442345745885606)).

There is no separate business password. Everyone gets in through their personal Facebook account, so a portfolio is only as safe as the least protected admin profile. Meta says business portfolio compromises typically happen when an individual account is hacked, or accessed through malware or phishing ([Meta Business Help Center](https://www.facebook.com/business/help/25302697499431030)).

Meta lists the signs: people or admins added without approval, changed permissions, ad accounts and campaigns nobody created, sudden spend, and posts that do not look like yours. Security alerts about new logins, or suddenly losing access to a Page or ad account, point the same way.

*Common symptoms of a business portfolio takeover and where to start. Meta's screens change, so treat labels as correct at the time of writing.*

| What you see | Likely cause | First action |
| --- | --- | --- |
| A stranger has full control, or your own access was removed | An admin's personal account was hacked or phished, and the attacker promoted themselves | Secure that admin's Facebook account, then ask any remaining full-control admin to remove the stranger |
| Meta charges on your card you did not approve | Campaigns or a new ad account are running on your payment method | Call your bank's fraud line to block the card, then pause campaigns if you still can |
| A Page is missing from your portfolio | The Page was moved to another portfolio, or its admin was removed | Submit Meta's hacked Page recovery form |
| No legitimate person has full control any more | Every real admin was removed, or the only admin is a former staff member | Contact Meta Support through Business Support Home and prepare ownership documents |
| An admin cannot log in to Facebook at all | The password, email or phone on that personal account was changed | That admin starts at facebook.com/hacked on a device they have used before |
| Unknown partners, system users or apps in settings | Access the attacker planted to get back in after a password change | Remove them once you have full control, and note the dates for Meta |
| A message from "Meta Support" says your Page will be disabled | A phishing attempt, often how the takeover starts | Do not click. Check the account status in Business Support Home instead |

## Why the admins' personal Facebook accounts come first

Removing a stranger from the portfolio achieves little if they still control an admin's personal login. They will simply add themselves back. So close the door they came in through before you tidy up the room.

1. Any admin who is locked out of Facebook goes to [facebook.com/hacked](https://www.facebook.com/hacked), ideally on a phone or computer they have used for Facebook before, and follows the steps there. Our [Facebook account recovery guide](https://www.awarexone.com/research/facebook-account-recovery-malaysia) covers that process in detail.
2. Every admin who can still log in, not only the one you suspect, changes their Facebook password to one they use nowhere else.
3. Each admin turns on two-factor authentication. At the time of writing, Facebook's help page puts it under Settings, then Accounts Center, then Password and security, then Two-factor authentication ([Facebook Help Center](https://www.facebook.com/help/148233965247823)).
4. In the same Password and security area, each admin reviews where they are logged in and logs out of any device or location they do not recognise.
5. Each admin secures the email account behind their Facebook login. Whoever controls that inbox can reset the Facebook password again.
6. Scan and clean the computers and phones your admins use. Meta recommends this, and names malware as one of the ways admin accounts get compromised.

## Stop the money: your bank first, then Ads Manager

A support ticket to Meta will not stop the next charge. Your bank can block the card in minutes. Work through this in order:

1. Call the fraud line printed on the back of the card linked to your ad accounts. Ask the bank to block the card and flag the recent Meta charges as unauthorised.
2. If you still have access, open Ads Manager and pause every active and scheduled campaign across all ad accounts in the portfolio, including any you did not create.
3. Remove payment methods you do not recognise. Meta also recommends reviewing any shared credit lines and removing sharing you do not recognise.
4. In Billing and payments, open Payment activity and note the reference number for each suspicious charge. Meta gives each ad transaction a unique 10-character reference that also appears on bank statements ([Meta Help Center](https://www.facebook.com/help/messenger-app/1674680089468704)), which makes the dispute far easier.
5. Screenshot the campaigns, charges, new people and new ad accounts, with dates, before anything is deleted.

Sinar Harian reported in August 2024 on a Petaling Jaya phone accessories trader whose social media account was hacked and whose card then paid for ads he never approved. He had set a spending cap, the attacker changed it, and he only noticed when the monthly statement arrived. His bank blocked the card, but he was still waiting for a resolution from the platform eight months later ([Sinar Harian](https://www.sinarharian.com.my/article/682565/berita/semasa/rugi-rm80000-akaun-media-sosial-digodam-kad-kredit-disalah-guna)). Two lessons follow: turn on real-time transaction alerts with your bank, and call the bank the moment you see a charge you do not recognise.

If money left your account because you were tricked, for example by paying a fake "verification fee" through a link, call your bank's hotline or the National Scam Response Centre on 997 immediately, then make a police report.

## Which official Meta route fits your situation?

Meta has several routes, and each covers a different layer. Using the right one first saves days.

- An admin's personal account was taken: [facebook.com/hacked](https://www.facebook.com/hacked). Business access cannot be fixed while the person behind it is locked out.
- The portfolio shows unauthorised changes and you still have some access: Meta's guidance on a [hacked or compromised business portfolio](https://www.facebook.com/business/help/25302697499431030) says to contact Meta Support immediately. Support is reached through Meta Business Support Home, which also shows the status of your portfolios, ad accounts and Pages ([Meta Business Help Center](https://www.facebook.com/business/help/254088759757736)).
- A Facebook Page was taken or moved: Meta's [hacked Page recovery form](https://www.facebook.com/help/738660629556925). Meta says it aims to reply within a day, but some reviews take longer. Our [Facebook Page recovery](https://www.awarexone.com/facebook-page-recovery) page explains how we help with Page cases.
- Charges on an ad account you do not recognise: Meta's page on [unrecognised ad account activity](https://www.facebook.com/business/help/524424920973484) walks through billing reasons, budgets and other spenders on the account, and how to get further help.
- No legitimate person has full control: Meta accepts a [request for full control of a business portfolio](https://www.facebook.com/business/help/474856681929983) in listed situations, such as when no one has full control or the person with full control is a former employee or contractor with no ownership rights. At the time of writing, you start a chat in Business Support Home and choose "Business Manager admin dispute". Meta notes that an approved request does not remove existing users, so you still remove the intruders yourself.
- A linked Instagram professional account was taken too: that account has its own route. See [what to do in the first hour after an Instagram hack](https://www.awarexone.com/research/instagram-hacked-first-hour).

> Warning: **Real Meta support will not ask for your login.** Many takeovers start with a message claiming your Page or ad account breaks the rules and will be disabled unless you "appeal" through a link. Meta's Business Support Home lets you check whether an account really has an issue. Nobody legitimate, including Meta and AwareXone, needs your password, login code or backup codes. Our guide to the [fake Meta Support scam](https://www.awarexone.com/research/fake-meta-support-scam-malaysia) shows what these messages look like.

## Checklist: what to prepare before you contact Meta

Meta support works from what you can show. Gather this before you start the chat, so you can answer in one go and keep the same case moving.

- The business portfolio ID, every ad account ID and each Page and Instagram account name and URL.
- The names and Facebook profile links of your legitimate admins.
- A short timeline: when you first saw the problem, which people were added, which assets were affected, and what you have already done.
- Screenshots of the unknown people, partners, campaigns and charges, with dates visible.
- Payment activity reference numbers for the disputed charges, and your past ad invoices.
- For a full control request, Meta asks for three documents: identification for the person making the request, a document that proves the business owns the portfolio, and a signed attestation letter. The name on the ID must match the person signing.
- Your company registration documents, in the exact business name the portfolio uses.
- The case number from Meta, so you reply in the same thread instead of opening new cases.

Our guide on [how to prove you own a social media account](https://www.awarexone.com/research/prove-social-media-account-ownership) explains which evidence carries weight and what rarely helps. Never submit an edited document or claim ownership of something that is not yours: that can end a case for good.

## Remove every foothold once you are back in

Changing passwords is necessary but not enough. Attackers often plant more than one way back, and each has to be closed separately. With full control, go through Settings in Meta Business Suite:

- People: remove anyone you did not add and anyone who has left. Meta says removing a person revokes their access to the portfolio and any assets they could reach, and that if another person with full control needs to approve the removal, they do it under Requests in Settings ([Meta Business Help Center](https://www.facebook.com/business/help/353397428740939)).
- Partners: remove partner businesses you do not recognise. Meta treats removing people and removing partners as different actions, so doing one does not do the other.
- System users: these are non-human accounts that apps and integrations use to reach Meta's systems. Meta's developer documentation says long-lived tokens for apps with Standard access to the Marketing API do not expire based on time, and that this also applies to system user tokens ([Meta for Developers](https://developers.facebook.com/documentation/facebook-login/guides/access-tokens)), so a planted one can outlive every password change. Remove any you did not create.
- Apps and integrations: remove connected tools your team no longer uses.
- Ad accounts and payment methods: close ad accounts you did not create and remove unknown cards and shared credit lines.
- Pages and Instagram accounts: check each one is still owned by your portfolio, not merely shared with it or moved to another.
- Portfolio history: Meta's security guidance describes downloading a record of important events in the portfolio, which helps you spot changes to people, assets and details you missed.

## Role hygiene: set up the portfolio so one login cannot sink it

Whether a takeover costs an afternoon or the business is mostly decided before it happens. These settings come from Meta's [security best practices for business portfolios](https://www.facebook.com/business/help/608572510632070), as described at the time of writing.

- Two people with full control. Meta recommends, but does not require, two. It also enables second admin approval, so sensitive actions such as changing a full-control person's access need a second person to approve. Keep full control small; Meta suggests ten or fewer.
- Require two-factor authentication. Only a person with full control can turn the requirement on, and everyone it applies to must then set up two-factor authentication on their personal Facebook account before they can access the portfolio ([Meta Business Help Center](https://www.facebook.com/business/help/280940009201586)). Apply it to everyone with access, not only admins. Meta may also require it before advertisers can publish ads, including in certain portfolios more than 90 days old ([Meta Business Help Center](https://www.facebook.com/business/help/865384580786591)).
- Stronger methods than SMS. Meta describes passkeys as simpler and more secure than passwords and one-time codes, and its Security Center suggests removing people who have set up neither passkeys nor two-factor authentication until they do. Our [2FA setup guide](https://www.awarexone.com/research/two-factor-authentication-instagram-facebook-tiktok) compares the options.
- Least privilege. Add an agency as a partner with only the assets and tasks it needs, never as individuals with full control or through a shared login. Give staff partial access unless they manage people and settings.
- Business email addresses. Meta recommends removing people whose email addresses are not related to your business. If your admins sign in with personal Gmail accounts, moving them to a company domain makes offboarding clearer.
- Prompt offboarding. Remove people the day they leave. Meta also recommends removing anyone who has not logged in for 90 days, especially those with full control.
- Fewer targets. Close ad accounts that have not run ads in the last year, and work through the portfolio's Security Center recommendations.
- Alerts someone reads. Send security notifications to an inbox checked daily, and set an ad account spending limit. A limit will not stop an attacker with full control, but it caps damage from a compromised partial-access user.

Malaysia adds one more reason to keep your advertiser records tidy. Under the Risk Mitigation Code, in force from 1 June 2026 under the Online Safety Act 2025, MCMC requires licensed platforms with more than eight million Malaysian users to verify every advertiser before sponsored ads run, with platforms given a reasonable period to comply ([The Star](https://www.thestar.com.my/news/nation/2026/05/31/identity-verification-required-for-sponsored-ads-on-social-media-starting-tomorrow)). Keep that verification tied to the business and to people who still work there. Our [account security service](https://www.awarexone.com/services/account-security) can review your portfolio set-up with your team.

## Disputing the charges and reporting ad fraud in Malaysia

Your bank decides a card dispute, not Meta and not us. Give the bank the dates, amounts, Meta reference numbers and screenshots, say the charges came from a hacked business account, and ask how long you have to file. A police report helps; the ombudsman below lists one among documents that may support a banking dispute. Refunds are never certain.

If your bank's final decision does not resolve it, the Financial Markets Ombudsman Service (FMOS), appointed by Bank Negara Malaysia and the Securities Commission, handles disputes about unauthorised card transactions, including for small and medium businesses ([FMOS scope](https://www.fmos.org.my/en/our-scope/)). You must complain to the bank first. You can then go to FMOS within six months of the bank's final decision, or if the bank has not responded within 60 days ([FMOS](https://www.fmos.org.my/en/how-to-file-a-dispute/)).

On the Meta side, report the unauthorised spend through the ad account's support options, and report any fake support message inside the app where it arrived.

## When a structured recovery review helps

Most owners can work through the steps above themselves. Outside help earns its place when no legitimate admin has access left, when Meta support will not let you select the business, when the ownership documents do not match the portfolio name, or when the portfolio runs ads your revenue depends on.

SocialSafe by AwareXone, our recovery service, looks at the case before anything is agreed. We map which layer was taken, organise the ownership evidence and prepare the requests through Meta's official processes with you. Our [Business Manager recovery](https://www.awarexone.com/business-manager-recovery) page explains the service, and [business and creator recovery](https://www.awarexone.com/services/business-creator-recovery) covers cases that span several platforms. How we handle your information is set out on our [Trust Center](https://www.awarexone.com/trust).

> Note: **Meta makes the final decision.** AwareXone is an independent Malaysian company with no special access to Meta. We use the same official routes you can, prepared properly. Some portfolios come back quickly, some take weeks, and some are not restored.

## Frequently Asked Questions

### Is Meta business portfolio the same thing as Business Manager?

Yes. Meta renamed Business Manager to business portfolio, and you manage it through Meta Business Suite. The admin role is now called full control, and the employee role is partial access. Older guides, agencies and support staff still use the old names, so treat them as interchangeable when you search or talk to Meta.

### Can a hacker take over my business portfolio without my password?

Yes, through another route in. They may compromise a different admin's personal account, steal a logged-in session with malware, or trick someone into accepting a partner request or granting access. That is why every admin needs two-factor authentication and why you check people, partners and system users, not only your own password.

### Why did the attacker come back after we changed our passwords?

Usually because one path was left open: another admin is still compromised, a partner business or system user was not removed, a connected app still holds access, or malware on a work laptop captured the new password. Go through each admin account and every section of the portfolio's settings, then remove anything you did not add yourself.

### Someone removed me as admin. Can another admin put me back?

Yes, if another legitimate person still has full control and their own account is secure. They can remove the intruder and add you again. If second admin approval is on, a full-control person may need to approve the change under Requests. If no legitimate admin is left, contact Meta Support through Business Support Home.

### Will Meta refund ads the hacker ran on my card?

Nobody can promise that. Meta decides about its side, and your bank decides the card dispute. Block the card and dispute the charges with your bank straight away, keep Meta's reference numbers for each charge, and report the unauthorised spend through the ad account's support options. Keep all case numbers in one place.

### How long does Meta take to restore a hacked business portfolio?

Meta does not publish a fixed timeline. For hacked Pages, it says it aims to reply within a day but some reviews take longer. Portfolio and ownership cases often need several exchanges. Reply in the same case thread with complete information, and avoid opening duplicate cases, which can slow things down.

### Should I give my agency my Facebook login?

No. Add the agency as a partner in your business portfolio and assign only the assets and tasks it needs. A shared login cannot be audited, breaks two-factor authentication and leaves you exposed if anyone at the agency is phished. When the contract ends, remove the partner the same day.

### Do I need a police report for a hacked Business Manager?

It is not required by Meta to secure the account, but it helps if money is involved. Your bank may ask for one when you dispute unauthorised charges, and it supports a later complaint to the Financial Markets Ombudsman Service. If you were tricked into transferring money, call your bank or 997 first, then report to the police.

### Can AwareXone get my business portfolio back for me?

Only Meta can restore access to a business portfolio. SocialSafe by AwareXone reviews your case, helps you gather the right evidence and prepares requests through Meta's official routes. We never ask for your password or login codes, we have no special access to Meta, and sometimes the honest answer is that you can finish it yourself.

## Official sources

- [Meta Business Help Center: Recover a hacked or compromised business portfolio](https://www.facebook.com/business/help/25302697499431030)
- [Meta Business Help Center: About business portfolio and business asset permissions in Meta Business Suite](https://www.facebook.com/business/help/442345745885606)
- [Meta Business Help Center: Best practices for making a business portfolio more secure](https://www.facebook.com/business/help/608572510632070)
- [Meta Business Help Center: How to require two-factor authentication for people in your business portfolio](https://www.facebook.com/business/help/280940009201586)
- [Meta Business Help Center: About two-factor authentication for your business portfolio](https://www.facebook.com/business/help/865384580786591)
- [Meta Business Help Center: Submit a request to get full control of a business portfolio](https://www.facebook.com/business/help/474856681929983)
- [Meta Business Help Center: Remove people from your business portfolio in Meta Business Suite](https://www.facebook.com/business/help/353397428740939)
- [Meta Business Help Center: About Meta Business Support Home](https://www.facebook.com/business/help/254088759757736)
- [Meta Business Help Center: Troubleshoot unrecognised activity on your ad account](https://www.facebook.com/business/help/524424920973484)
- [Meta Help Center: Find your Meta ad charges on your credit card statement](https://www.facebook.com/help/messenger-app/1674680089468704)
- [Facebook Help Center: Recover a hacked Facebook Page that you manage](https://www.facebook.com/help/738660629556925)
- [Facebook Help Center: How two-factor authentication works on Facebook](https://www.facebook.com/help/148233965247823)
- [Facebook: hacked account help](https://www.facebook.com/hacked)
- [Meta for Developers: Access tokens (system user access tokens)](https://developers.facebook.com/documentation/facebook-login/guides/access-tokens)
- [Sinar Harian: hacked social media account and misused credit card (27 August 2024)](https://www.sinarharian.com.my/article/682565/berita/semasa/rugi-rm80000-akaun-media-sosial-digodam-kad-kredit-disalah-guna)
- [The Star: Identity verification required for sponsored ads on social media starting tomorrow (31 May 2026)](https://www.thestar.com.my/news/nation/2026/05/31/identity-verification-required-for-sponsored-ads-on-social-media-starting-tomorrow)
- [Financial Markets Ombudsman Service: How to submit a dispute to FMOS](https://www.fmos.org.my/en/how-to-file-a-dispute/)
- [Financial Markets Ombudsman Service: What FMOS can and cannot handle](https://www.fmos.org.my/en/our-scope/)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
