
Facebook Hacked and Ads Charged My Card: What to Do
Someone hacked your Facebook and ran ads on your card? Secure the profile, read the receipts, stop the ads, then report it to Meta and your Malaysian bank.
Treat it as a hacked account first and a billing problem second. Secure the profile at facebook.com/hacked, then open Payment activity in Billing and payments to see each charge. Pause unknown ads, remove people you do not recognise, and report the charges to your card issuer and Meta Support the same day. Meta and your bank decide any refund.
Summary- Unknown Facebook ad charges usually mean someone got into your profile or ad account and spent through the card saved there.
- Secure the profile first at facebook.com/hacked, because anything you fix in billing can be undone while the attacker still has access.
- Then open Payment activity in Billing and payments, note each Transaction ID, pause the unknown ads and remove people you do not recognise.
- Report the charges to your card issuer the same day and contact Meta Support for ads payment issues with your ad account ID.
- Nobody from Meta, your bank or Bank Negara Malaysia will ask for your card's security digits, password or login codes, so end any call that does.
- Meta and your bank each make their own decision about the charges, and nobody outside them can promise a refund.
Table of contents13 sections
- 01What Should You Do If Hackers Ran Facebook Ads on Your Card?
- 02Hack or Normal Billing? Read the Signs First
- 03Step 1: Take the Facebook Profile Back
- 04Step 2: Find Every Charge in Billing and Payments
- 05Step 3: Stop the Ads and Remove the Intruder
- 06Step 4: Call Your Card Issuer the Same Day
- 07Step 5: Contact Meta Support for Ads Payment Issues
- 08If the Bank Does Not Resolve It: The BNM Route
- 09Evidence Pack for Meta and Your Bank
- 10Fake Meta Billing and Bank Fraud Unit Calls
- 11What Meta and the Bank Will and Will Not Promise
- 12When a Case Review Makes Sense
- 13Frequently Asked Questions
Your bank app shows a charge from Meta or Facebook that you never approved. Or you open Facebook and find ads you did not create, promoting a shop or a link you have never seen, all paid for with the card you once saved for a boost.
The short answer: treat it as a hacked account first and a billing problem second. Lock the attacker out, then use Meta's own billing screens to see exactly what was charged, stop the spending, and report it to Meta and to your card issuer at the same time.
This guide covers a personal profile or a small ad account. For a whole business portfolio taken over, see our guide to a hacked Facebook Business Manager.
Last checked: 5 October 2026.
#What Should You Do If Hackers Ran Facebook Ads on Your Card?
Secure the profile at facebook.com/hacked before touching billing. Then open "Billing and payments", go to "Payment activity" and click each "Transaction ID" to see which ads ran and which card paid. Pause the ads you did not create, remove people you do not recognise from "Ad account roles", and call your card issuer the same day. Then contact Meta Support with your ad account ID and the transaction details. If the bank does not resolve your complaint, Bank Negara Malaysia's BNMLINK is the next step. Meta and the bank decide on any refund.
#Hack or Normal Billing? Read the Signs First
Not every surprise charge is a hack. Meta's page on unrecognised ad account activity explains that you are charged as ads run, when your costs reach your payment threshold or on your monthly bill date, and that being charged several times a month, or even after you stopped an ad, can be normal. A forgotten boost can do exactly that.
| What you see | What it usually means | First action |
|---|---|---|
| A charge after you stopped your own ads | Usually normal: Meta bills for delivery that already happened | Open the receipt and check the ads listed match yours |
| Several charges in one month for ads you did run | Often your payment threshold being reached more than once | Check the "Billing reason" on each receipt |
| Charges for ads you have never seen, often for shops, crypto or links in another language | Someone else created ads in your ad account | Secure the profile, then pause the ads and check "Ad account roles" |
| A new person in "Ad account roles" or your business portfolio | An attacker added themselves so they can keep spending | Remove them once you control the profile |
| Your ads paused, admins removed or payment method changed without you | Meta may have acted to protect the account after spotting suspicious activity | Read your notifications and contact Meta Support before re-enabling anything |
| Facebook emails about a new email, phone or password you did not set | The profile itself was taken over | Go to facebook.com/hacked and use the reverse link Facebook sent to the old email |
| Someone you share the card or ad account with ran an ad | Not a hack, but still a charge you did not expect | Ask them before reporting it, as Meta's page suggests |
#Step 1: Take the Facebook Profile Back
Billing fixes do not hold while the attacker can still log in. Facebook's page on recovering a hacked account points you to facebook.com/hacked and says to use a device you have logged in from before. It lists the signs: a changed profile picture, posts or messages you did not write, two-factor authentication that has stopped working, and emails about a new email address, phone number or password.
- Go to facebook.com/hacked on a phone or computer you normally use for Facebook, and follow the steps.
- If the attacker changed your email, look in the old inbox. Facebook says it sends a message with a special link that lets you reverse the change.
- Change your password and the password of the email account linked to Facebook.
- In "Where you're logged in", log out every device or location you do not recognise.
- Turn on two-factor authentication with an authenticator app, and save the backup codes somewhere offline.
If the recovery steps stall because the email and phone on the account are both gone, keep going with Facebook's routes for lost contact details, but do not wait on the steps that only need your bank. Step 4 works even while you are locked out. If the charges came from boosted posts on Instagram rather than Facebook, our guide to Instagram ad charges after a hack follows the same logic inside the Instagram app.
#Step 2: Find Every Charge in Billing and Payments
Meta's receipts tell you more than your card statement does. According to Meta's unrecognised activity page, you open "Payment activity" in "Billing and payments" and click the "Transaction ID" of each charge. The receipt shows how much you paid, when, which payment method was charged, which ads the money went to, and a "Billing reason" such as reaching your payment threshold.
- Download the receipt for every charge you do not recognise.
- Write down the Transaction ID, the date, the amount and the last digits of the card shown.
- Note the names of the ads or campaigns, and what they promoted.
- Take screenshots with the date visible, in case the attacker deletes the campaigns.
- Find your ad account ID. Meta says it appears next to the ad account name at the top of the Account Overview page in Ads Manager.
#Step 3: Stop the Ads and Remove the Intruder
Once you control the profile, cut off the spending. Turn off every campaign, ad set and ad you did not create. Then check who has access: Meta's page says to go to "Account settings" and look under "Ad account roles". Remove anyone you do not know. If the ad account sits inside a business portfolio, check its people list too.
Removing the card is less simple than it sounds. Meta's page on removing a payment method says you first need to pause active ads and clear any outstanding balance with "Pay now", and that it can take up to 48 hours after ads are paused for delayed ad events to be captured. You also need admin permissions, or full control if the ad account is in a business portfolio. That is one more reason to call your bank in parallel rather than waiting until the card can be removed in Facebook.
#Step 4: Call Your Card Issuer the Same Day
Your bank controls the card and Meta controls the ad account, so report to both. Call the number on the back of your card or on the bank's official website, not a number from a text message. Tell them the card was used for Facebook ads you did not authorise, give the dates and amounts from your receipts, and ask what they can do about the card and the transactions. Bank Negara Malaysia's page on unauthorised use of a credit or debit card defines it as charging purchases without the cardholder's consent, and advises keeping copies of every communication and document.
Ask the bank whether it needs a police report for its investigation, and keep the reference number it gives you. If you were also tricked into handing over card details or a code, or money left your bank account another way, BNM's National Fraud Portal statement tells scam victims to contact their financial institution or the National Scam Response Centre on 997 immediately.
#Step 5: Contact Meta Support for Ads Payment Issues
Meta has a support route for billing problems, reached from inside its business tools. Its page on reaching Meta Support for ads payment issues describes it: from the Meta Business Help Centre, click "Get Support" at the top right, scroll down and choose "Start chat", then select the affected ad account if asked.
- Explain in two or three sentences that your account was hacked and ads you did not create were charged to your card.
- Give the sequence of events: when you lost access, when you got back in, what you changed.
- Paste your ad account ID and the Transaction IDs from Step 2.
- Say that you have reported the transactions to your card issuer, and keep any case number Meta gives you.
If the ad account was disabled after the hack, that becomes an appeal of its own; our guide to a disabled Facebook ad account covers the request for review.
#If the Bank Does Not Resolve It: The BNM Route
Bank Negara Malaysia handles complaints about banks only after the bank has had its chance. Its complaints page sets out three steps:
- Lodge your complaint with your bank's Complaints Unit. BNM notes that the business or claims unit is not the Complaints Unit, and it will not accept complaints that skipped this step.
- Get a response and a final decision from the Complaints Unit, following up in writing so there is a record.
- If there is no response after 14 days, refer the case to BNMLINK. If you disagree with the decision, BNM lists other redress channels, including the Financial Markets Ombudsman Service and legal assistance.
Know the limits. BNM's page says it does not take cases about a bank's commercial decisions, or cases on entities under the purview of other regulators or law enforcement agencies such as the police. BNMLINK cannot order Meta to do anything; Meta's side stays with Meta Support.
#Evidence Pack for Meta and Your Bank
- Your Facebook profile URL, and your ad account ID from Ads Manager.
- Every receipt you downloaded, with Transaction IDs, dates, amounts and the card's last digits.
- Screenshots of the ads and campaigns you did not create, with the date visible.
- Screenshots of unknown people in "Ad account roles" or the portfolio.
- Facebook security emails about password, email or phone changes, and the date you lost access.
- Your card statement lines for the same charges.
- Bank, Meta Support and police reference numbers, with the date of each contact.
#Fake Meta Billing and Bank Fraud Unit Calls
People who have just been hacked are a favourite target for a second scam. Expect messages that look like Meta billing alerts, and calls from someone claiming to be your bank's fraud team or Bank Negara Malaysia.
- Check the sender. Facebook says its emails come only from fb.com, facebook.com, facebookmail.com, instagram.com, meta.com, metamail.com or global.metamail.com and their subdomains, and to watch for misspellings (Facebook Help Centre).
- Ignore anyone offering a refund for a payment upfront, or offering to "recover" the ad money through contacts at Meta. Nobody can get that.
- Scam scripts arrive in English, Bahasa Malaysia and Chinese. A script in your own language is not a sign it is real.
For more on the fake support messages that follow a hack, see our explainer on fake Meta support scams in Malaysia.
#What Meta and the Bank Will and Will Not Promise
Meta decides what happens on the ad account, and your bank decides what happens on the card. Neither publishes a promise that unauthorised ad charges will be returned. Some people get the account back and the charges sorted; some get the account back and still dispute the charges; some profiles do not come back at all.
What you control is speed and clarity: lock the attacker out, stop further spend and report to both sides with the same evidence. Meta's page on hacked or compromised business portfolios covers the recovery route if the attacker reached further than one ad account; in the meantime, check billing and payment activity regularly so an unusual change is caught early.
#When a Case Review Makes Sense
You can do every step above alone, and most people should start there. A review is worth it when you cannot get the profile back, when the attacker sits inside a business portfolio you depend on, or when Meta's replies keep missing the point. SocialSafe by AwareXone looks at the case first and tells you honestly whether an official route is still open. We work only through Meta's own forms and support, never ask for your password, login codes or card details, and cannot promise an outcome. You can read how we handle Business Manager recovery, and our Trust Center sets out what we will never ask for.
#Frequently Asked Questions
Why was I charged for Facebook ads after I turned them off?
Will Meta refund ads a hacker ran on my card?
Can I dispute Facebook ad charges with my bank in Malaysia?
Why can't I remove my card from my Facebook ad account?
Someone called about suspicious Meta charges and asked for my card's CVV. Is it real?
Official sources
- Facebook Help Centre: Recover your Facebook account if you were hacked (read 5 October 2026)
- Facebook: What to do if your account has been hacked (read 5 October 2026)
- Meta Business Help Centre: Troubleshoot unrecognised activity on your ad account (read 5 October 2026)
- Meta Business Help Centre: How to get guidance and reach Meta Support for ads payment issues (read 5 October 2026)
- Meta Business Help Centre: Remove a payment method from your Meta ad account (read 5 October 2026)
- Meta Business Help Centre: Recover a hacked or compromised business portfolio (read 5 October 2026)
- Facebook Help Centre: Check whether an email is really from Facebook (read 5 October 2026)
- Bank Negara Malaysia: Unauthorised Use of Credit or Debit Card (read 5 October 2026)
- Bank Negara Malaysia: Lodge Complaint (read 5 October 2026)
- Bank Negara Malaysia: Enquiries or Complaints, BNMLINK (read 5 October 2026)
- Bank Negara Malaysia: National Fraud Portal to solidify coordinated efforts in curbing financial scams (read 5 October 2026)
Need help with your account?
Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Business Manager recovery.




