Hacked.com

Online Account Recovery

Hacked Facebook and Instagram advertising

Stop unauthorized Meta ads and continued account access

Unknown Facebook or Instagram advertising is both an account-control incident and a payment incident. Pausing a campaign does not remove the person, partner, session, integration, or stolen administrator identity that created it. Replacing a card does not restore business control. Preserve evidence, stop continued access safely, and run the Meta and payment-provider responses in parallel.

Reviewed 2026-08-27 by the Hacked.com recovery team. Hacked.com is independent from Meta and never asks for passwords or authentication codes.

Request a Callback

The qualification callback is free. After that call, an admin may send a $249 assessment-session link, a $1,499 full recovery offer, or $599 Personal Account Recovery. The assessment is credited once toward either same-case paid service, whichever is ordered first.

Recovery-or-refund guarantee

Recover your Meta business assets, or request a refund

If we cannot resolve the Meta business issue covered by your agreement, you can close the engagement and receive the amount paid minus documented professional time at $199 per hour. Read the Refund Policy

This is a service-fee refund guarantee. Meta controls restoration decisions, reversals, and response times.

Protect the remaining control first

1

Contact the card issuer promptly about unauthorized charges and ask what evidence it needs before replacing or blocking the payment method.

2

Preserve campaign, ad, billing, administrator, partner, and activity screenshots before removing access where safe.

3

Secure the personal profiles, email accounts, devices, and browser extensions used by business administrators.

Determine where the unauthorized activity started

The visible charge is often the last step of the incident. Identify whether the attacker used a compromised administrator, an unknown business partner, a stolen session, a malicious integration, or payment information outside the ad account.

What you see

Unknown campaigns or ads appear inside Ads Manager

What it usually means

Someone with direct, partner, system-user, integration, or stolen-session access used the ad account.

Next decision

Preserve campaign IDs, creatives, destinations, timestamps, spend, and the actor history where visible before pausing delivery and removing persistence.

What you see

Unknown people or partners were added

What it usually means

The attacker may retain business-level access even after a personal password reset.

Next decision

Secure legitimate administrators and email first, record every unknown role and assigned asset, then remove unauthorized access in an order that will not lock out the business.

What you see

The bank shows Meta charges but no matching business activity is visible

What it usually means

The charge may belong to another ad account, a different Meta payment surface, a stolen card, or a statement descriptor that needs investigation.

Next decision

Compare statement date and amount with Meta billing records, ask authorized staff whether they recognize it, then use the correct Meta or card-issuer reporting path.

What you see

The attacker returns after campaigns are paused

What it usually means

A profile, email account, session, partner, system user, integration, device, or browser token remains compromised.

Next decision

Stop repeating only the campaign response and re-audit the full administrator control plane before making more ad-account changes.

What you see

Meta restricted the account after the fraudulent ads

What it usually means

The business now has two linked problems: compromise containment and an enforcement review created by attacker activity.

Next decision

Document the compromise timeline, unauthorized ads, containment completed, affected entity, and corrective actions before requesting review.

Preserve financial and platform evidence

Keep originals in a controlled business location and share redacted copies. Do not put complete card data, passwords, codes, or identity documents into a public form.

  • Ad account ID, campaign and ad IDs, creatives, destination URLs, start times, spend, currencies, and screenshots of delivery before it is stopped.
  • Billing transaction IDs, Meta invoices, statement dates and amounts, payment-method changes, and the payment provider's fraud reference number.
  • People, partners, system users, integrations, connected apps, active sessions, security emails, and administrator role changes around the incident.
  • A device and browser-extension check for every administrator who had access when the unknown activity began.
  • Meta support and review case IDs, the precise refund or enforcement remedy requested, and a log of what access was removed and when.

Containment mistakes that allow more spend

Financial containment and platform recovery affect each other, but neither one replaces the other. Coordinate them so evidence is preserved and access is not left open.

  • Replacing the card while leaving unknown administrators, partners, sessions, integrations, or malware active.
  • Removing every visible role before securing a trusted administrator and recording who controlled each asset.
  • Deleting campaigns and ads before saving IDs, destinations, timestamps, spend, and billing evidence.
  • Assuming a bank dispute automatically reports the platform compromise or removes the attacker from Meta assets.
  • Running new campaigns before the administrator control plane is secure and any compromise-driven restriction has been documented.

Online account dispute escalation

When Meta recovery channels do not resolve the dispute

Hacked.com can help accepted clients organize the account history, preserve ownership and loss evidence, prepare a formal demand, and navigate California small claims escalation when appropriate.

Explore Small Claims Case Preparation

Hacked.com does not guarantee restoration, settlement, judgment, or payment. Legal representation and court fees are not included unless an accepted written offer expressly says otherwise.

Official recovery and review surfaces

Availability and labels can vary by asset, account state, device, and region. Use links from Meta-owned domains and preserve the exact message shown to the affected administrator.

Safety note: Meta does not publish one universal support phone number for every business. Treat phone numbers in ads, search results, messages, and unsolicited emails as untrusted.

What the engagement includes

  • One accepted Meta business incident for one business
  • One primary Business Portfolio, Business Manager, or Facebook Page
  • Up to two client-side administrators
  • Associated Pages, Instagram accounts, and ad accounts involved in the incident
  • Recovery support for an in-scope administrator's personal Facebook profile when it is required to regain control of the covered business assets
  • Containment, ownership-evidence preparation, official recovery and review guidance
  • A documented case log, live working sessions, and escalation support
  • Twelve months of follow-up for the covered incident and assets
  • Recovery-or-refund guarantee: amount paid minus documented work at $199 per hour if we cannot resolve the covered Meta business issue
  • Optional annual online account and security support for eligible clients at $899 per year. It starts when purchased and supports ongoing or new personal and business online-security matters, with no separate checkout for subscription-funded cases while active

What is not included

  • A guarantee of restoration, reversal, or a specific Meta response time
  • Advertising campaign management, creative strategy, or ongoing media buying
  • Legal representation, court fees, forensic imaging, or endpoint remediation
  • New incidents or assets outside the accepted scope

Hacked.com is an independent recovery service and is not affiliated with Meta. Meta controls platform decisions and response times.

Questions that change the recovery path

Should we contact the card issuer or Meta first?

Run both responses promptly. Ask the card issuer how to contain and document unauthorized charges, while preserving Meta billing and campaign evidence and securing business access. One process does not automatically complete the other.

Is pausing the fraudulent campaign enough?

No. Pausing limits delivery but does not remove the access route that created the campaign. Audit people, partners, system users, integrations, sessions, email, devices, and browser extensions before considering the incident contained.

Will Meta refund unauthorized ad spend?

Meta controls billing investigations and refunds, and outcomes cannot be guaranteed. Preserve transaction and campaign evidence, report the correct affected account, and coordinate with the payment provider without submitting contradictory claims.

What if the ad account was restricted because of the attacker's ads?

Treat containment and enforcement as linked workstreams. Secure the business, document which ads were unauthorized and when they ran, record the affected entity and restriction, and explain the corrective actions in the review path Meta provides.

Free qualification callback

Tell us what the business has lost

A specialist reviews the request before calling. The form does not create a paid case.

What do you need help with?

Related Meta business help

Detailed recovery guides