
Got Your Facebook Page Back After a Hack? What to Check
Got your Facebook Page back after a hack in Malaysia? Check who has full control, undo the attacker's changes, review ads and payments, and secure every admin.
Once you have your Facebook Page back, secure your own profile first, then open Page access and remove anyone you do not recognise. Check the business portfolio, Page management history, ads, payment methods and linked Instagram, and undo unfamiliar changes. Finally, make every admin turn on two-factor authentication or Advanced Protection.
Summary- Getting your Facebook Page back is only half the job, because the attacker may still have access through another admin, a partner or a linked account.
- Start by unlocking and securing your own profile, logging out of unknown sessions, then open Page access and remove anyone you do not recognise.
- Next, check the business portfolio, Page management history, posts, ads, payment methods and the linked Instagram account, and undo every change you did not make.
- Make every remaining admin turn on two-factor authentication or Advanced Protection, since one weak admin profile can hand the Page straight back to the attacker.
- Ignore Page violation or copyright messages with login links, and never give anyone your password, login codes or backup codes, whoever they claim to be.
Table of contents13 sections
- 01What Should You Check After Getting Your Facebook Page Back?
- 02First, Secure Your Own Profile Again
- 03Who Has Access to Your Page Now?
- 04Check the Business Portfolio, Partners and Ad Accounts
- 05Find Out What the Attacker Changed
- 06Ads, Payment Methods and Unexpected Charges
- 07Linked Instagram and Other Connected Accounts
- 08Lock Down Every Remaining Admin
- 09How Attackers Get Back In
- 10Mistakes That Undo a Recovery
- 11Evidence to Keep, and Reporting in Malaysia
- 12When a Case Review Makes Sense
- 13Frequently Asked Questions
Meta replied, you can switch into your Page again, and the relief is real. Then you notice a post you never wrote, an admin name you do not know, or an ad campaign still running. The Page is back, but you are not sure it is clean.
The short answer: treat the first hour after recovery as part of the recovery. Secure your own profile, remove every person and partner you do not recognise, undo the attacker's changes, check the money side, and make every remaining admin lock their account down. Skip a step and the same attacker can walk back in.
This guide is a post-recovery checklist for Page owners and small business teams. If you have not got the Page back yet, start with our guide to a Facebook Page hacked with the admin removed instead.
Last checked: 5 October 2026.
#What Should You Check After Getting Your Facebook Page Back?
Meta's own page on recovering a hacked Facebook Page lists four things to do after you regain access: unlock your account if Meta locked it for security, look through your Page and business portfolio and undo any changes you do not recognise, turn on Advanced Protection or other security steps, and watch for scams and phishing. In practice that means checking who has access, what they changed, what they spent and how they got in. Work through the checklist below in order, on a computer if you can, because some settings are easier to read on a larger screen.
#First, Secure Your Own Profile Again
A Page has no password of its own. It is managed through personal profiles, so your profile is the front door. If Meta locked it, open Facebook and follow the prompts to unlock it before anything else.
- Change your Facebook password to one you have never used anywhere else, and change the password on the email account linked to Facebook too.
- In Accounts Centre, open "Password and security", then "Where you're logged in". Meta's page on logging out of other devices shows how to select unknown sessions, or "Select all", and log them out.
- Check that the email address and mobile number on your profile are yours. Remove anything the attacker added.
- In your email account, delete any forwarding rules or filters you did not create. Attackers use these to read Facebook security emails quietly.
- If your phone lost signal around the time of the hack, ask your carrier whether your SIM was replaced.
#Who Has Access to Your Page Now?
This is the most important check. Meta says that someone with Facebook access with full control has the same power as you: they can add people, remove anyone including you, or delete the Page. Attackers often add a spare profile so they keep a way back in.
To review access, switch into the Page first. Meta's help page on giving, editing and removing Page access says you need full control to change anyone's access, and that there are three types to look at:
- Facebook access, with full or partial control: these people can switch into the Page. Anyone with full control can change settings and access.
- Task access: these people work through tools such as Meta Business Suite or Ads Manager and cannot switch into the Page, but Meta says they can still post, reply to messages and run ads.
- Community Manager access: these people moderate live stream chat. Meta says they can delete comments and ban users from live streams.
Remove every name you do not recognise, at every level, not only full control. Then downgrade people who do not need full control. At the time of writing the path is usually "Settings and privacy", "Settings", "Page setup", "Page access", but labels vary by app version and region.
If your Page sits inside a business portfolio, access is also managed there, and the labels can differ from the ones on Facebook. Meta has a separate article on Page access for Pages in a business portfolio. Check the Page there as well as on Facebook itself.
#Check the Business Portfolio, Partners and Ad Accounts
If you use Meta Business Suite, the attacker may have changed things at portfolio level, which a Page check alone will not show. Meta's page on a hacked or compromised business portfolio lists the signs to look for:
- New people or admins added without approval, or permissions changed.
- New or reactivated ad accounts and campaigns your team did not create.
- Sudden increases in ad spend, invoices or charges.
- Posts with copy, images or targeting that are not like your business.
The same page recommends running "Security Checkup" in your business portfolio settings, requiring two-factor authentication for everyone in the portfolio, removing people whose email addresses are not related to your business, closing ad accounts that have not run ads in the last year, and removing any shared credit line you do not recognise. Look under "Partners" too, and remove any business you did not invite. Our guide to a hacked Facebook Business Manager covers a full portfolio takeover in more depth.
#Find Out What the Attacker Changed
Page management history is the record of what was done on your Page and by whom. Use it to build a list of changes to reverse. Meta's help page on management history warns that it does not show actions by system users, so a clean history does not prove nothing happened. You can also download your business history in Business Manager.
Then check each of these by hand against how the Page looked before:
| What to check | What attackers often do | What to do |
|---|---|---|
| Page access and Community Manager list | Add a spare profile so they can return | Remove every unknown person at every access level |
| Page name, username, profile and cover photo | Rename the Page or change the photo to run a scam | Restore the originals and note the dates |
| Contact details, website link and buttons | Point customers to a scam site or number | Correct them and test each link |
| Posts, Reels, Stories and scheduled posts | Publish crypto or giveaway scams, or schedule them for later | Delete them and check the scheduled queue |
| Inbox and automated replies | Message followers or set up replies with scam links | Review sent messages and switch off unknown automations |
| Ads, ad accounts and payment methods | Run ads on your card or add their own payment method | Pause unknown ads, review billing, call your bank |
| Linked Instagram account | Link an account they control, or keep access to yours | Disconnect anything unfamiliar and secure your Instagram |
#Ads, Payment Methods and Unexpected Charges
Money is where a Page hack hurts a small business most. In Ads Manager, open "Activity history" for your campaigns. Meta's guide to viewing ad activity history says it shows who changed what and when, including budget changes and changes to the payment method for the account. Pause or delete any campaign your team did not create, and remove any payment method you do not recognise.
If your card was charged for ads you did not run, call your bank's hotline straight away and keep screenshots of the charges. Our guide to Facebook ads charged to your card after a hack walks through the billing side step by step.
#Linked Instagram and Other Connected Accounts
A Page and an Instagram professional account are often linked, and an attacker who controlled one may have touched the other. Meta's page on connecting or disconnecting Instagram and your Page puts the setting under "Settings and privacy", "Settings", "Linked accounts" while switched into the Page. Check that the Instagram account shown is yours. If it is not, click "Disconnect account" and confirm. Look at any other account listed there in the same way. Meta notes that disconnecting a subscribed Page and Instagram account can, in some cases, cancel an active Meta Verified subscription.
Then log in to the Instagram account itself, change its password, review its logged-in devices and turn on two-factor authentication there too.
#Lock Down Every Remaining Admin
Your Page is only as strong as the weakest profile with access to it. Ask each remaining admin, editor and task-access user to do the following on their own account, not yours:
- Turn on two-factor authentication. Meta's two-factor guide offers a security key, an authentication app or text message codes, plus 10 recovery codes for when the phone is unavailable. An app or security key is stronger than SMS if a SIM swap is a risk.
- Turn on Advanced Protection under "Password and security" in Accounts Centre. Meta lists Page admin accounts among those at higher risk of phishing, and says some business accounts are required to turn it on.
- Store recovery codes offline, somewhere only that person can reach.
- Log out of sessions they do not recognise.
- Check their own email account for forwarding rules and unknown logins.
If one admin will not secure their account, reduce their access until they do. For a longer routine for the whole team, use our business social account protection checklist.
#How Attackers Get Back In
A second takeover usually comes through a door the first clean-up missed. Watch for these:
- A second compromised admin. If a staff member or agency profile was the way in, recovering your own profile changes nothing until theirs is secured too.
- A spare profile or partner business still listed in Page access or the portfolio.
- A fake "Page violation" or copyright notice asking you to log in through a link. Our guide to fake copyright violation messages shows how these are built.
- A Business Manager partner request from a business you do not know. Meta's phishing page warns that these can arrive from the genuine facebookmail.com domain with phishing links inside.
- Malware on a shared office computer. Meta's portfolio security advice includes scanning and cleaning the devices of everyone with access.
Meta lists the email domains it writes from, including facebook.com, facebookmail.com, fb.com, meta.com and metamail.com, and says its representatives never request money or ask for passwords or payment details over chat or email. Forward suspicious messages to [email protected].
#Mistakes That Undo a Recovery
- Leaving an unknown name in task access because it does not look powerful. Task access can still post and run ads.
- Removing every admin except yourself, then losing your own profile. Keep two trusted people on full control.
- Deleting the attacker's posts before taking screenshots. You may need them for your bank, the police or Meta.
- Assuming management history caught everything, when it does not show system user actions.
- Paying someone who messages you offering to "protect" or "verify" the Page. Nobody legitimate needs your password, login code or backup codes.
#Evidence to Keep, and Reporting in Malaysia
Even with the Page back, keep a record. Save screenshots of unknown admins, posts, ads and charges with the date visible, the email from Meta confirming recovery, and the date you regained access. If customers were sent scam links from your Page, a short public post explaining what happened helps them avoid it.
If money left your account or a customer was scammed, the NSRC's FAQ on the NFCC website says to contact your bank's 24-hour hotline or the NSRC on 997 as soon as you find the fraudulent transaction, and to make a police report at the nearest station. A phishing link that led to the takeover can be reported to CyberSecurity Malaysia's Cyber999 incident response centre by online form, email or its app.
#When a Case Review Makes Sense
Most Page owners can finish this checklist alone. A second opinion is worth it when the Page keeps getting taken again, several admins or a whole business portfolio were compromised, or the Page carries a large share of your sales. SocialSafe by AwareXone, AwareXone's recovery service, reviews the case before anything is agreed, works only through Meta's official tools, and will tell you plainly when there is nothing more an outsider can add. It is best effort, and Meta decides. You can see how we approach Facebook Page recovery, and our Trust Center lists what we never ask for, starting with passwords and login codes.
#Frequently Asked Questions
My Facebook Page is recovered but still posting things I did not write. Why?
How do I remove an unknown admin from my Facebook Page?
Can I undo everything the hacker changed on my Page?
Will the hacker get my Page back again?
Page Facebook dah dapat balik selepas kena hack, apa perlu disemak?
Official sources
- Facebook Help Centre: Recover a hacked Facebook Page that you manage (read 5 October 2026)
- Facebook Help Centre: Give, edit or remove Facebook Page access (read 5 October 2026)
- Facebook Help Centre: About Facebook Page access (read 5 October 2026)
- Meta Business Help Centre: About Page access (read 5 October 2026)
- Meta Business Help Centre: Recover a hacked or compromised business portfolio (read 5 October 2026)
- Facebook Help Centre: View your Page management history (read 5 October 2026)
- Meta Business Help Centre: How to view activity history for your ads in Meta Ads Manager (read 5 October 2026)
- Facebook Help Centre: Connect or disconnect an Instagram account and your Page (read 5 October 2026)
- Facebook Help Centre: Log out of Facebook on another device (read 5 October 2026)
- Facebook Help Centre: How two-factor authentication works on Facebook (read 5 October 2026)
- Facebook Help Centre: How to enable Advanced Protection on Facebook (read 5 October 2026)
- Facebook Help Centre: Protect yourself from phishing on Facebook (read 5 October 2026)
- NFCC: National Scam Response Centre FAQ (read 5 October 2026)
- CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 5 October 2026)
Need help with your account?
Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Facebook Page recovery.




