# Facebook Hacked and Email Changed? What to Do First

> Hacker changed your Facebook email or phone? Use Meta's reversal link in your old inbox, then facebook.com/hacked on a familiar device. Malaysia steps too.

- URL: https://www.awarexone.com/research/facebook-hacked-email-phone-changed
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-29
- Topics: Facebook, Account recovery, Malaysia
- Related service: Facebook account recovery: https://www.awarexone.com/social-media-recovery/facebook-account-recovery

## Short answer

Open the inbox that used to be on your Facebook account, including spam, and find Meta's security email about the change. Check it comes from a real Meta domain, then use its link to reverse the change. If that fails, start Meta's hacked account flow on a device you have used before. Never share a login code.

## Summary

- When someone changes the email on your Facebook, Meta sends a message with a special link to the previous address so you can reverse the change.
- Search your old inbox, including spam, for that security email and check the sender is a real Meta domain such as facebookmail.com before you click.
- If the link is gone or does not work, start facebook.com/hacked on a phone or computer you have logged into Facebook with before.
- If neither works, find your account from a familiar device and choose No longer have access to these, then follow the identity checks with new contact details.
- Meta never asks for your password by email or chat, so ignore anyone offering to recover the account for payment or asking for your codes.
- Only Meta can return the account, and some hacked accounts do not come back, so secure your email and phone even while you wait.

An email from Facebook says the email address or mobile number on your account was changed, and it was not you. Your password no longer works, and the reset code goes to an address you have never seen.

The short answer: the first hour decides a lot, and the fastest way back is usually in your old inbox. Meta sends the previous email address a message with a link that reverses the change. If that fails, Meta's hacked account flow and its "No longer have access to these?" route are next, in that order.

This guide covers each of those routes, how to tell a real Meta email from a phishing copy, what to do if your phone number was also swapped, and the scams that target people in exactly this spot.

Last checked: 29 September 2026.

## What Should You Do If a Hacker Changed Your Facebook Email?

Open the inbox that used to be on your Facebook account and look for a recent security email from Meta. Meta's page on [recovering a hacked Facebook account](https://www.facebook.com/help/203305893040179) says that when an email is changed, it sends the previous address a message with a special link you can click to reverse the change and secure the account. If you cannot find it or it does not work, go to [facebook.com/hacked](https://www.facebook.com/hacked) on a phone or computer you have logged into Facebook with before. If both fail, use Meta's route for [accounts where you cannot reach the email or phone](https://www.facebook.com/help/132243923516844). Ignore anyone who claims they can reverse the change from inside Meta, and never share a login code.

## Which Situation Are You In?

"Email changed" covers several different states. Match what you see to a row below before you start, because the first step differs. Meta does not publish the exact subject lines of its security emails, and the wording can vary by language and region, so match on meaning rather than exact words.

*Common signs after a Facebook email or phone change and the first step for each, based on Facebook Help Center pages at the time of writing.*

| What you see | What it usually means | Your first step |
| --- | --- | --- |
| An email from Meta saying an email address was added or removed, and you did not do it | Someone with your password changed the contact email | Use the reversal link in that email straight away, after checking the sender |
| Your password stopped working, but your phone or laptop is still logged in | The attacker changed the password but your old session is still alive | From that logged-in device, change the password and log out every other session |
| Reset codes go to an email or number you do not recognise | Both your contact details were replaced | Start facebook.com/hacked on a familiar device |
| Facebook asks for a two-factor code you never set up | The attacker turned on two-factor authentication with their own app or number | Use facebook.com/hacked, then the "No longer have access to these?" route |
| Friends say your account is sending messages or links | The account is actively being used to scam contacts | Warn contacts from another channel while you work on recovery |

## Step 1: Find the Security Email in Your Old Inbox

This is the quickest route, and the one people skip because they assume the hacker cut them off completely. The attacker changed the address on Facebook, not your email account itself, so the old inbox should still be yours.

1. Log into the email account that used to be on Facebook. If that inbox was also hacked, recover it with your email provider first; Meta's help page suggests contacting your email provider for this.
2. Search the inbox, spam and promotions folders for recent mail from Facebook or Meta.
3. Check the sender address against the domains in the next section before you click anything.
4. Open the security email and use the link that reverses the email change.
5. Follow the prompts to set a new password that you do not use anywhere else.

If you still have the old email but the link does not appear, Meta's page on [logging in when you are locked out](https://www.facebook.com/help/105487009541643) suggests checking spam, making sure you have a signal, and waiting a few minutes before asking for a new code.

## How to Tell a Real Meta Email From a Phishing Copy

Attackers know you are waiting for a message from Facebook, so a fake one at this moment works well. Meta's page on [checking whether an email is really from Facebook](https://www.facebook.com/help/1634546593478660) gives three tests.

- The sender domain. Meta says real mail only comes from fb.com, facebook.com, facebookmail.com, instagram.com, meta.com, metamail.com or global.metamail.com, or a subdomain of these such as support.facebook.com. Watch for misspellings of any of them.
- The logo. In Gmail, Yahoo Mail or Apple Mail, Meta says you can trust the email if the Facebook logo appears beside the sender address.
- Your security history. If you are still logged in anywhere, open Accounts Center, then "Password and security", then "Recent emails", or go to facebook.com/recent_emails/security. Meta says security emails from the last year appear under the "SECURITY" tab.

> Note: **The link lives in your inbox, not in settings.** Meta says it may hide special links and security codes in the Recent emails list to protect your account. Use that list to confirm an email is genuine, then click the link from the email itself.

Meta's [phishing guidance](https://www.facebook.com/help/166863010078512) adds that it will never ask for your username or password by email or send a password in an attachment. It also warns that scammers have misused legitimate Meta notifications, such as Business Manager partner requests, so a real domain alone does not make every link safe. If a message pushes you to act fast or asks for a code, stop.

## Step 2: Start facebook.com/hacked on a Familiar Device

If the reversal link is missing, expired or already used by the attacker, Meta's [hacked accounts page](https://www.facebook.com/help/1216349518398524) sends you to facebook.com/hacked on a device you have used to log into Facebook before. At the time of writing, the flow opens with "What to do if your account has been hacked" and walks you through security steps.

- Use your usual phone or computer, and your usual browser. Meta says an old phone or a family member's laptop you once logged in from can also count.
- Meta says the link can help even if you are not sure the account was compromised.
- Answer every prompt yourself. Nobody else needs to see the screens or the codes.

## Step 3: When Both Fail, Use "No Longer Have Access to These?"

This is Meta's route for when the email and phone on the account are no longer yours. Its page on [recovering without your email or phone](https://www.facebook.com/help/132243923516844) sets out the steps, and again says to use a familiar device.

1. On that device, type facebook.com/login/identify into your usual browser.
2. Enter an email or mobile number you have used on the account. Meta says to try other addresses you may have forgotten were linked, and to include the country code with a phone number (for Malaysia, +60).
3. If that finds nothing, try your name or username. A friend can copy your username from the web address of your profile.
4. Select "No longer have access to these?". Meta says you might see "Forgotten account?" or "Recover" instead.
5. Give new contact details when asked. Meta says they must not have been used on your Facebook account before.
6. Follow the prompts to confirm the account belongs to you, then reset the password.

If Meta asks for a video selfie during the identity check and that step keeps failing, our guide to [Facebook video selfie problems](https://www.awarexone.com/research/facebook-video-selfie-verification-not-working) covers what usually causes it.

## What If the Hacker Also Changed Your Phone Number?

A changed phone number on Facebook usually means the attacker added their own. That is different from someone taking over your actual SIM, and the two need different fixes.

- If your phone still has signal and your number works, the attacker only changed the number on Facebook. Follow the three steps above.
- If your phone suddenly shows "No service" or "SOS only", call your carrier from another phone and ask whether a replacement SIM was issued. Take a MyKad to a carrier outlet if they ask you to.
- If Facebook asks for a two-factor code you never set up, the attacker has added their own method. Meta's page on [how two-factor authentication works](https://www.facebook.com/help/148233965247823) explains the methods they may have chosen: an authentication app, SMS or a security key.

That last case is harder, because a code you cannot receive blocks the normal login. Our guide on [what to do when a hacker turned on 2FA](https://www.awarexone.com/research/hacker-turned-on-two-factor) covers it in more detail.

## Once You Are Back In, Close Every Door

Getting the password back is half the job. An attacker who still has a session, a linked email or their own 2FA method can take the account again.

1. Log out every session you do not recognise. Meta's page on [logging out of other devices](https://www.facebook.com/help/211990645501187) shows the path: Accounts Center, "Password and security", "Where you're logged in", then "Select devices to log out".
2. Change your Facebook password again, and the password on the email account linked to it.
3. Check every email address and mobile number on the account, and remove any you do not recognise.
4. Turn on two-factor authentication with a method you control, and save the recovery codes offline.
5. Look for posts, messages, Page roles or ads you did not create, and delete them.

If friends received messages from your account asking for money or codes, tell them directly. Our piece on [a hacked account messaging your friends](https://www.awarexone.com/research/hacked-account-messaging-friends) has wording you can adapt.

## Evidence Checklist Before the Identity Check

- Screenshots of every Meta security email, including the sender address and the time it arrived.
- Your Facebook profile link, username and the name on the profile.
- Every email address and phone number you remember using on the account.
- The date and time you last had normal access, and the device you used.
- Access to a device you have logged into Facebook from before.
- A new email address and phone number that have never been on this account.
- Screenshots from friends of any messages the attacker sent.

## Mistakes That Cost People Their Account

- Clicking the "secure your account" link in an email without checking the sender domain first.
- Trying recovery from a new phone or an internet cafe computer instead of a familiar device.
- Ignoring the old inbox because the attacker "has the email now". They have the Facebook setting, not your inbox.
- Giving the attacker's email or number when asked for new contact details, or reusing an old one.
- Stopping once the password is back, without logging out unknown sessions or removing their 2FA.
- Creating a new account to message friends from. It can look like the attacker's work and confuse your contacts.
- Paying a stranger who replied to your post promising to recover the account.

> Warning: **Fake Meta support and recovery sellers.** Meta says its representatives will never request money or ask for passwords, payment details or other sensitive information over chat or email. A public post asking for help, whether written as "akaun Facebook kena hack" or "脸书被盗", can attract replies from accounts posing as Meta or as recovery hackers. Do not pay them, do not send your password, a login code or a recovery code, and do not install anything they send.

Our guide to [fake Meta support accounts](https://www.awarexone.com/research/fake-meta-support-scam-malaysia) shows how those approaches usually look.

## If Money Was Lost or a Code Was Shared in Malaysia

Deal with any money first. The government's [NSRC 997 hotline page](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline) says to call 997 within 24 hours of discovering a scam so authorities can try to block the bank accounts and transactions involved, then contact your bank and make a police report at the nearest station.

If you received a fake Facebook login page or a phishing email, you can report it to CyberSecurity Malaysia's [Cyber999 incident response centre](https://www.cybersecurity.my/portal-main/services/cyber999-overview) through its online form, email or app. Meta's phishing page also asks people to forward suspicious messages to phish@fb.com.

## Can Every Hacked Facebook Account Be Recovered?

No. Only Meta decides whether an account is returned, and nobody outside Meta can override that. Some accounts come back quickly through the reversal link. Others need several attempts at the identity check, and some are not restored at all, especially when the attacker has changed every contact detail and you have no familiar device left. Keep your screenshots and try again from a familiar device rather than giving up after one failed check.

## When a Case Review Makes Sense

Most readers can work through the routes above alone. A second pair of eyes helps when the identity check keeps failing, when the account runs a business Page or ads, or when you cannot tell whether a message from "Meta" is real. SocialSafe by AwareXone, our recovery service, looks at the case before anything is agreed, uses only Meta's official routes, and will tell you if you already have what you need. You can read about our [Facebook account recovery](https://www.awarexone.com/social-media-recovery/facebook-account-recovery) work, and our [Trust Center](https://www.awarexone.com/trust) lists what we will never ask for, starting with your password and codes.

## Frequently Asked Questions

### How long does the Facebook email reversal link work?

Meta does not publish a time limit for the link on its help pages. Use it as soon as you see it, because the attacker may try to lock you out further.

### Can I recover Facebook if the hacker changed both my email and phone number?

Often, yes. Start facebook.com/hacked on a familiar device, then use "No longer have access to these?" with new contact details and complete the identity checks, though Meta makes the final decision.

### Why does Facebook say my new email is already in use?

Meta says new contact details given during recovery must not have been used on the account before. Use an address or number that has never been linked to it.

### Is the Facebook security email in my inbox real?

Check that it comes from a Meta domain such as facebookmail.com or meta.com, spelled correctly. If you can still log in anywhere, confirm it under Recent emails in Accounts Center.

### Will Facebook call or message me to help recover my account?

Do not expect it. Meta says its representatives never ask for passwords or money over chat or email, so treat any unsolicited offer of help as a scam.

## Official sources

- [Facebook Help Center: Recover a Hacked Account (read 29 September 2026)](https://www.facebook.com/help/1216349518398524)
- [Facebook Help Center: Recover your Facebook account if you were hacked (read 29 September 2026)](https://www.facebook.com/help/203305893040179)
- [Facebook Help Center: Check if an email is really from Facebook (read 29 September 2026)](https://www.facebook.com/help/1634546593478660)
- [Facebook Help Center: Recover your Facebook account if you can't access your account email address or mobile phone number (read 29 September 2026)](https://www.facebook.com/help/132243923516844)
- [Facebook Help Center: Recover your Facebook account if you can't log in (read 29 September 2026)](https://www.facebook.com/help/105487009541643)
- [Facebook Help Center: How two-factor authentication works on Facebook (read 29 September 2026)](https://www.facebook.com/help/148233965247823)
- [Facebook Help Center: Log out of Facebook on another device (read 29 September 2026)](https://www.facebook.com/help/211990645501187)
- [Facebook Help Center: Protect yourself from phishing on Facebook (read 29 September 2026)](https://www.facebook.com/help/166863010078512)
- [Facebook: What to do if your account has been hacked (read 29 September 2026)](https://www.facebook.com/hacked)
- [MyGOV Malaysia: NSRC 997 Hotline (read 29 September 2026)](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline)
- [CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 29 September 2026)](https://www.cybersecurity.my/portal-main/services/cyber999-overview)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
