Choose your next step from what you can still access
| What you see | Start here | Watch for |
| Facebook still opens on one device | Keep that session while checking contact details and security settings. | Do not remove your last usable recovery method before confirming a replacement. |
| You are logged out, but still receive recovery emails or texts | Identify your account and request a reset through Facebook. | Check the destination before requesting a code. |
| The email or phone now belongs to someone else | Use the hacked-account flow and any alternative verification it offers. | A normal reset may keep sending codes to the attacker. |
| A two-factor code is required, but you never set it up | Look for another verification option within the official login flow. | A password reset alone may leave that extra check in place. |
| Facebook explicitly says suspended or disabled | Follow the appeal instructions and deadline on that notice. | Account ownership and an enforcement decision are separate problems. |
| Your profile works, but your Page or business access is missing | Document the affected asset and use the Page or business recovery route. | Restoring a personal login does not necessarily restore business permissions. |
Facebook's official hacked-account guidance recommends a previously used device. Familiar does not mean safe: a computer with suspicious software should not receive new passwords. Button labels and available checks vary by device, region, and account situation.
Protect the inbox and phone that control recovery
Before sending more codes, check whether you can safely receive them. If the attacker can read your inbox, they may see the same recovery messages you do. Open your email provider directly rather than following a link in an unexpected message.
- Email: Set a unique password, check recovery contacts, and review unfamiliar sign-ins. Inspect forwarding rules, filters, connected applications, and app passwords, which can give another application access to your mailbox.
- Phone: If service suddenly stopped or you received an unexpected SIM or number-transfer notice, contact your carrier using its official website or a known number. Ask it to investigate unauthorized changes and secure the carrier account.
- Device: If someone installed remote-access software or an unfamiliar extension, stop using that device for recovery until you can establish that it is safe.
You do not need to diagnose every possible attack before taking action. Prioritize the contact method Facebook is offering and any device showing clear signs of compromise. If several accounts are affected, use the immediate hacked-account checklist to organize the wider response.
Keep a short record of the last successful login, the first suspicious change, and the recovery steps you attempt. Save security notices before deleting anything. Never include passwords, login codes, backup codes, or identity-document images in ordinary notes or messages to a helper.
If Facebook is still open on one device
An open session is useful, but it does not prove you still control every account setting. Some changes require your current password or another security check. If that check sends you to a contact method you do not control, stop at that point and use the changed-contact route below.
- Record the profile you are recovering. Save its address and the notices about changes. Do not confuse it with a separate profile using your name and photographs.
- Review the account's email and phone contacts. Open settings and Accounts Center. Check which Facebook profile you are editing, especially if several accounts appear. Where allowed, confirm a contact method you control before removing an unfamiliar one.
- Set a new, unique Facebook password. Use the account's own security controls. Do not reuse the password from the compromised inbox or another service.
- Review signed-in devices and security methods. End clearly unfamiliar sessions and remove authentication methods you did not authorize where the interface permits it. Keep track of which session is yours.
- Review connected access. Check linked accounts, applications, and any Page or business permissions. Remove access you can identify as unauthorized after preserving relevant evidence.
Facebook documents how to add and remove account email addresses. The exact settings sequence depends on your app and device. Follow the confirmation prompts rather than assuming that typing a new address has made it usable for recovery.
If a security change requires ending all sessions, make sure you understand the sign-in and recovery options that will remain. A blanket instruction to log out everywhere is risky when the password, email, and second verification method have already been changed by someone else.
If you are logged out but still receive Facebook codes
- Open Facebook's Find your account page or start from the hacked-account flow.
- Enter the account information requested. Check that the result is your original profile before continuing.
- Read the masked email address or phone number offered for the code. Choose only a destination you control.
- Request the code and enter it in the recovery session you opened yourself. Do not send it to someone claiming to help.
- Complete the remaining checks and set a unique password. Then review the account for unauthorized access.
If a code does not arrive, check spam or junk folders, mailbox rules, and phone reception. Facebook's login recovery guidance advises allowing a few minutes before requesting another code. If the destination is unfamiliar, requesting more codes will not solve the contact problem.
A successful password reset is one stage of recovery. If Facebook then asks for a two-factor code you cannot provide, continue with the verification problem below rather than repeatedly resetting the password you just changed.
If the hacker changed your email or phone number
Separate two situations: losing access to your own old inbox, and seeing a new address that was added without permission. Recovering your old mailbox can help with the first. It does not automatically remove an attacker-controlled address from Facebook.
- Start the hacked-account flow from a safe, previously used device. Follow its prompts to identify the original account.
- Check the original inbox for security notices. Look for the change notification and preserve it. If it offers an option to secure the account or reverse a change, verify the destination before using it. The sender's display name alone is not proof.
- Use another verification option if offered. The wording may differ, and some accounts will not receive an alternative. Do not assume a missing button is your mistake.
- Provide a secure contact address only when the official process asks for one. Make sure you can receive its messages and that nobody else has mailbox access.
- Keep the exact result. Save the screen, time, and any reference number if the process rejects the attempt or returns to the same page.
If a security-email link has expired or cannot be verified, return to the official recovery entry point. Do not forward the full recovery email or share its link publicly. Such links can contain information that grants account access.
For help interpreting the notice, see what to do when Facebook says your primary email changed. A notice helps establish the sequence of events; it is not a promise that reversal remains available.
If Facebook asks for a two-factor code you do not have
Two-factor authentication, or 2FA, adds a check after the password, such as a code from an authenticator app. The problem may be your lost phone or an authentication method the attacker added. Installing a new authenticator app does not recreate a method previously attached to the account.
Use a backup method you set up earlier only if Facebook still offers or accepts it. Previously saved recovery codes may no longer help if the authentication setup has changed. Never buy codes or give someone remote access in exchange for a promised bypass.
At the challenge, look for an alternative verification or help option. If one appears, follow it within the official flow. If none appears, preserve that screen and return to the hacked-account process. Do not disable security on unrelated accounts or change your profile information to imitate the attacker.
If Facebook confirms your identity but still returns you to the same challenge, record both the confirmation and the blocked screen. That distinction matters when explaining the unresolved problem: proving identity and restoring usable access have not yet produced the same result.
If Facebook offers an ID check or video selfie
Use only the identity check reached through the official recovery process. Read its accepted-document and privacy instructions before uploading anything. Do not send identity documents to a social-media account, a stranger in a message, or a website claiming to unlock Facebook.
Meta says its adaptive recovery process can include an optional video selfie. It also describes an in-app support hub and a Meta AI support assistant in supported regions. Availability varies; none is a guarantee that your account will offer that check or receive human review.
- Choose a document or verification method the screen actually accepts.
- Use a clear, readable image with good lighting and no glare. Follow the on-screen framing instructions.
- Do not digitally alter document details or invent matching account information.
- If the account name changed during the takeover, record the original and changed names. Explain that difference only where the process allows it.
- Save the submission confirmation and follow the stated next step rather than sending the same material repeatedly.
Do not assume a Facebook profile must always match a legal name exactly. Facebook's name guidance uses the name a person goes by in everyday life and describes alternatives to government ID for name confirmation. Your particular recovery check determines which evidence it will accept.
If the profile is suspended, disabled, or missing
Read the message shown when you attempt to log in. A missing profile in search is not enough to establish whether it was renamed, disabled, deleted, or made unavailable for another reason. Save the actual login notice before choosing a route.
If Facebook offers an appeal, follow its instructions and any deadline shown for your account. Explain the unauthorized access factually and preserve the supporting security notices. Do not repeatedly send a password reset when the unresolved issue is an enforcement decision.
Use recovery after a hack-related Facebook suspension or disablement for that separate path. If you see a deletion notice instead, attempt the official recovery flow promptly and follow any cancellation option presented. Do not assume the account can still be restored.
If your Page, business access, or ad account is affected
Check whether the personal profile works while a particular business asset does not. A restored profile may still lack the permissions needed to manage a Page. Conversely, another authorized administrator may retain business access while your profile is locked out.
Preserve the Page address, asset identifiers, access-change notices, and any unauthorized campaign or billing records you can lawfully access. Ask an existing authorized administrator to review suspicious access through their own account. Do not share a personal Facebook login or create a shared replacement identity.
Use Facebook Page and Business Portfolio recovery to address the missing permissions. If spending is continuing, preserve the billing evidence and use the available platform and payment-provider channels promptly. Do not wait for personal profile recovery before reporting unauthorized charges to the provider.
If recovery keeps returning to the same screen
A loop does not reveal its cause. It may reflect a security restriction, an unavailable verification option, an unresolved account state, or a technical failure. It is not proof that your device is infected or that another attempt will succeed after a fixed number of hours.
Stop and record the blocker: Note the exact message, which contact method Facebook offered, and the last step that succeeded. A useful next attempt changes a relevant condition, such as restoring inbox access, or follows a new instruction from Facebook.
- Honor any waiting period Facebook displays. Do not substitute a supposed universal recovery timetable.
- Keep a safe familiar device available. Avoid clearing its data as a routine troubleshooting step when it holds your remaining session.
- Check the secured inbox for a response or requested action before submitting again.
- If support is available inside the app or official Help Center, describe the specific blocked step and retain the reference number.
For independent help organizing a stalled recovery, review Hacked.com's Facebook recovery support. Keep the affected profile, timeline, and attempted steps together. Hacked.com is independent from Meta and cannot guarantee reinstatement or replace Meta's ownership checks.
Do not assume buying a subscription, contacting a supposed employee, or paying for a recovery tool will unlock the account. Evaluate any service by its stated work and limits, not a promise of special access.
After recovery, make sure access stays yours
Facebook opening again is a useful milestone. Finish by checking both who can sign in and who can regain access later.
- Confirm recovery contacts. Keep only email addresses and phone numbers you control, with a verified replacement before removing an old method you still need.
- Review security methods and sessions. Remove unauthorized methods and clearly unfamiliar logins. Add an authenticator or supported security key you control, and save fresh recovery codes somewhere secure.
- Check connected accounts and applications. Remove unfamiliar access and review anything the attacker changed.
- Review activity and business permissions. Preserve evidence of scam messages, posts, or access changes before cleaning them up.
- Warn affected contacts through a trusted channel. Explain which messages or payment requests were not yours without publishing private recovery information.
For a physical security key, check Facebook's device and browser compatibility instructions before buying one. Keep a usable fallback. A stronger sign-in method is most useful when you also know what to do if that device is lost.
If the attacker returns: Treat renewed unauthorized changes as an unresolved incident. Recheck the inbox, devices, account connections, and business permissions. Another Facebook password change alone may leave the same route open.
A recovery is more durable when the inbox, contact methods, devices, and account permissions all lead back to you. Keeping an accurate record makes it easier to distinguish a new intrusion from a restriction that never cleared.
When access remains blocked, the useful question is which ownership check or account decision is still unresolved. That gives the next action a purpose and keeps a frustrating recovery loop from turning into repeated exposure of your personal information.