A large magnifying glass with a metal rim in blue halftone, beside the headline Page Back After a Hack? Check It Now.

Got Your Facebook Page Back After a Hack? What to Check

Got your Facebook Page back after a hack in Malaysia? Check who has full control, undo the attacker's changes, review ads and payments, and secure every admin.

11 min read
Short answer

Once you have your Facebook Page back, secure your own profile first, then open Page access and remove anyone you do not recognise. Check the business portfolio, Page management history, ads, payment methods and linked Instagram, and undo unfamiliar changes. Finally, make every admin turn on two-factor authentication or Advanced Protection.

Summary
  • Getting your Facebook Page back is only half the job, because the attacker may still have access through another admin, a partner or a linked account.
  • Start by unlocking and securing your own profile, logging out of unknown sessions, then open Page access and remove anyone you do not recognise.
  • Next, check the business portfolio, Page management history, posts, ads, payment methods and the linked Instagram account, and undo every change you did not make.
  • Make every remaining admin turn on two-factor authentication or Advanced Protection, since one weak admin profile can hand the Page straight back to the attacker.
  • Ignore Page violation or copyright messages with login links, and never give anyone your password, login codes or backup codes, whoever they claim to be.
Table of contents13 sections
  1. 01What Should You Check After Getting Your Facebook Page Back?
  2. 02First, Secure Your Own Profile Again
  3. 03Who Has Access to Your Page Now?
  4. 04Check the Business Portfolio, Partners and Ad Accounts
  5. 05Find Out What the Attacker Changed
  6. 06Ads, Payment Methods and Unexpected Charges
  7. 07Linked Instagram and Other Connected Accounts
  8. 08Lock Down Every Remaining Admin
  9. 09How Attackers Get Back In
  10. 10Mistakes That Undo a Recovery
  11. 11Evidence to Keep, and Reporting in Malaysia
  12. 12When a Case Review Makes Sense
  13. 13Frequently Asked Questions

Meta replied, you can switch into your Page again, and the relief is real. Then you notice a post you never wrote, an admin name you do not know, or an ad campaign still running. The Page is back, but you are not sure it is clean.

The short answer: treat the first hour after recovery as part of the recovery. Secure your own profile, remove every person and partner you do not recognise, undo the attacker's changes, check the money side, and make every remaining admin lock their account down. Skip a step and the same attacker can walk back in.

This guide is a post-recovery checklist for Page owners and small business teams. If you have not got the Page back yet, start with our guide to a Facebook Page hacked with the admin removed instead.

Last checked: 5 October 2026.

#What Should You Check After Getting Your Facebook Page Back?

Meta's own page on recovering a hacked Facebook Page lists four things to do after you regain access: unlock your account if Meta locked it for security, look through your Page and business portfolio and undo any changes you do not recognise, turn on Advanced Protection or other security steps, and watch for scams and phishing. In practice that means checking who has access, what they changed, what they spent and how they got in. Work through the checklist below in order, on a computer if you can, because some settings are easier to read on a larger screen.

#First, Secure Your Own Profile Again

A Page has no password of its own. It is managed through personal profiles, so your profile is the front door. If Meta locked it, open Facebook and follow the prompts to unlock it before anything else.

  1. Change your Facebook password to one you have never used anywhere else, and change the password on the email account linked to Facebook too.
  2. In Accounts Centre, open "Password and security", then "Where you're logged in". Meta's page on logging out of other devices shows how to select unknown sessions, or "Select all", and log them out.
  3. Check that the email address and mobile number on your profile are yours. Remove anything the attacker added.
  4. In your email account, delete any forwarding rules or filters you did not create. Attackers use these to read Facebook security emails quietly.
  5. If your phone lost signal around the time of the hack, ask your carrier whether your SIM was replaced.

#Who Has Access to Your Page Now?

This is the most important check. Meta says that someone with Facebook access with full control has the same power as you: they can add people, remove anyone including you, or delete the Page. Attackers often add a spare profile so they keep a way back in.

To review access, switch into the Page first. Meta's help page on giving, editing and removing Page access says you need full control to change anyone's access, and that there are three types to look at:

  • Facebook access, with full or partial control: these people can switch into the Page. Anyone with full control can change settings and access.
  • Task access: these people work through tools such as Meta Business Suite or Ads Manager and cannot switch into the Page, but Meta says they can still post, reply to messages and run ads.
  • Community Manager access: these people moderate live stream chat. Meta says they can delete comments and ban users from live streams.

Remove every name you do not recognise, at every level, not only full control. Then downgrade people who do not need full control. At the time of writing the path is usually "Settings and privacy", "Settings", "Page setup", "Page access", but labels vary by app version and region.

If your Page sits inside a business portfolio, access is also managed there, and the labels can differ from the ones on Facebook. Meta has a separate article on Page access for Pages in a business portfolio. Check the Page there as well as on Facebook itself.

#Check the Business Portfolio, Partners and Ad Accounts

If you use Meta Business Suite, the attacker may have changed things at portfolio level, which a Page check alone will not show. Meta's page on a hacked or compromised business portfolio lists the signs to look for:

  • New people or admins added without approval, or permissions changed.
  • New or reactivated ad accounts and campaigns your team did not create.
  • Sudden increases in ad spend, invoices or charges.
  • Posts with copy, images or targeting that are not like your business.

The same page recommends running "Security Checkup" in your business portfolio settings, requiring two-factor authentication for everyone in the portfolio, removing people whose email addresses are not related to your business, closing ad accounts that have not run ads in the last year, and removing any shared credit line you do not recognise. Look under "Partners" too, and remove any business you did not invite. Our guide to a hacked Facebook Business Manager covers a full portfolio takeover in more depth.

#Find Out What the Attacker Changed

Page management history is the record of what was done on your Page and by whom. Use it to build a list of changes to reverse. Meta's help page on management history warns that it does not show actions by system users, so a clean history does not prove nothing happened. You can also download your business history in Business Manager.

Then check each of these by hand against how the Page looked before:

Common changes found after a Facebook Page takeover and how to undo them, based on Meta Help Centre pages read on 5 October 2026.
What to checkWhat attackers often doWhat to do
Page access and Community Manager listAdd a spare profile so they can returnRemove every unknown person at every access level
Page name, username, profile and cover photoRename the Page or change the photo to run a scamRestore the originals and note the dates
Contact details, website link and buttonsPoint customers to a scam site or numberCorrect them and test each link
Posts, Reels, Stories and scheduled postsPublish crypto or giveaway scams, or schedule them for laterDelete them and check the scheduled queue
Inbox and automated repliesMessage followers or set up replies with scam linksReview sent messages and switch off unknown automations
Ads, ad accounts and payment methodsRun ads on your card or add their own payment methodPause unknown ads, review billing, call your bank
Linked Instagram accountLink an account they control, or keep access to yoursDisconnect anything unfamiliar and secure your Instagram

#Ads, Payment Methods and Unexpected Charges

Money is where a Page hack hurts a small business most. In Ads Manager, open "Activity history" for your campaigns. Meta's guide to viewing ad activity history says it shows who changed what and when, including budget changes and changes to the payment method for the account. Pause or delete any campaign your team did not create, and remove any payment method you do not recognise.

If your card was charged for ads you did not run, call your bank's hotline straight away and keep screenshots of the charges. Our guide to Facebook ads charged to your card after a hack walks through the billing side step by step.

#Linked Instagram and Other Connected Accounts

A Page and an Instagram professional account are often linked, and an attacker who controlled one may have touched the other. Meta's page on connecting or disconnecting Instagram and your Page puts the setting under "Settings and privacy", "Settings", "Linked accounts" while switched into the Page. Check that the Instagram account shown is yours. If it is not, click "Disconnect account" and confirm. Look at any other account listed there in the same way. Meta notes that disconnecting a subscribed Page and Instagram account can, in some cases, cancel an active Meta Verified subscription.

Then log in to the Instagram account itself, change its password, review its logged-in devices and turn on two-factor authentication there too.

#Lock Down Every Remaining Admin

Your Page is only as strong as the weakest profile with access to it. Ask each remaining admin, editor and task-access user to do the following on their own account, not yours:

  1. Turn on two-factor authentication. Meta's two-factor guide offers a security key, an authentication app or text message codes, plus 10 recovery codes for when the phone is unavailable. An app or security key is stronger than SMS if a SIM swap is a risk.
  2. Turn on Advanced Protection under "Password and security" in Accounts Centre. Meta lists Page admin accounts among those at higher risk of phishing, and says some business accounts are required to turn it on.
  3. Store recovery codes offline, somewhere only that person can reach.
  4. Log out of sessions they do not recognise.
  5. Check their own email account for forwarding rules and unknown logins.

If one admin will not secure their account, reduce their access until they do. For a longer routine for the whole team, use our business social account protection checklist.

#How Attackers Get Back In

A second takeover usually comes through a door the first clean-up missed. Watch for these:

  • A second compromised admin. If a staff member or agency profile was the way in, recovering your own profile changes nothing until theirs is secured too.
  • A spare profile or partner business still listed in Page access or the portfolio.
  • A fake "Page violation" or copyright notice asking you to log in through a link. Our guide to fake copyright violation messages shows how these are built.
  • A Business Manager partner request from a business you do not know. Meta's phishing page warns that these can arrive from the genuine facebookmail.com domain with phishing links inside.
  • Malware on a shared office computer. Meta's portfolio security advice includes scanning and cleaning the devices of everyone with access.

Meta lists the email domains it writes from, including facebook.com, facebookmail.com, fb.com, meta.com and metamail.com, and says its representatives never request money or ask for passwords or payment details over chat or email. Forward suspicious messages to [email protected].

#Mistakes That Undo a Recovery

  • Leaving an unknown name in task access because it does not look powerful. Task access can still post and run ads.
  • Removing every admin except yourself, then losing your own profile. Keep two trusted people on full control.
  • Deleting the attacker's posts before taking screenshots. You may need them for your bank, the police or Meta.
  • Assuming management history caught everything, when it does not show system user actions.
  • Paying someone who messages you offering to "protect" or "verify" the Page. Nobody legitimate needs your password, login code or backup codes.

#Evidence to Keep, and Reporting in Malaysia

Even with the Page back, keep a record. Save screenshots of unknown admins, posts, ads and charges with the date visible, the email from Meta confirming recovery, and the date you regained access. If customers were sent scam links from your Page, a short public post explaining what happened helps them avoid it.

If money left your account or a customer was scammed, the NSRC's FAQ on the NFCC website says to contact your bank's 24-hour hotline or the NSRC on 997 as soon as you find the fraudulent transaction, and to make a police report at the nearest station. A phishing link that led to the takeover can be reported to CyberSecurity Malaysia's Cyber999 incident response centre by online form, email or its app.

#When a Case Review Makes Sense

Most Page owners can finish this checklist alone. A second opinion is worth it when the Page keeps getting taken again, several admins or a whole business portfolio were compromised, or the Page carries a large share of your sales. SocialSafe by AwareXone, AwareXone's recovery service, reviews the case before anything is agreed, works only through Meta's official tools, and will tell you plainly when there is nothing more an outsider can add. It is best effort, and Meta decides. You can see how we approach Facebook Page recovery, and our Trust Center lists what we never ask for, starting with passwords and login codes.

#Frequently Asked Questions

My Facebook Page is recovered but still posting things I did not write. Why?
Someone still has access, or the posts were scheduled before you got back in. Check Page access at every level, the business portfolio and the scheduled post queue, and secure every admin profile.
How do I remove an unknown admin from my Facebook Page?
Switch into the Page, open Page access in the Page settings, find the person and remove them. You need Facebook access with full control to do this, and Meta warns that a Page left with nobody on full control is deactivated.
Can I undo everything the hacker changed on my Page?
Most changes can be reversed by hand, such as the name, links, posts and access. Do not count on deleted content or lost followers coming back, and screenshot what you find before you fix it.
Will the hacker get my Page back again?
They can if any door is left open: another compromised admin, a spare profile, a partner business or a phishing message you click later. Removing unknown access and turning on two-factor authentication for every admin closes the usual routes.
Page Facebook dah dapat balik selepas kena hack, apa perlu disemak?
Semak Page access dan buang sesiapa yang anda tidak kenali, kemudian semak portfolio perniagaan, iklan, kaedah pembayaran dan akaun Instagram yang dipautkan. Pastikan setiap admin menghidupkan pengesahan dua faktor, dan jangan kongsi kata laluan atau kod log masuk dengan sesiapa.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Facebook Page recovery.