What do I do if someone hacked my Facebook and changed the email and phone number?
My Facebook account has been hacked, and the person changed both my email address and phone number. What steps can I take to recover my account and secure it again? I have tried logging in with my usual details, but I can no longer access the account or receive verification codes. I also want to know how I can check for any changes the hacker made to my account after I regain access.
Priya Gupta
Here is the order of steps that actually works, based on how Facebook's recovery system is built.
Start with Facebook's own hacked account flow, not the regular login page
Go to facebook.com/hacked directly. This is a different flow from the normal login screen. It asks whether you can still access the email or phone number on the account, and if you say no, it moves you into an identity verification path instead of a password reset path. Trying to force your way in through the regular "forgot password" screen usually just loops you back to the email or phone the hacker already changed, which won't help you.
Use the "my account is compromised" option, not "I don't remember my password"
These are two different flows inside Facebook and people often pick the wrong one. The compromised account option tells Facebook's system to expect that the account details have been tampered with, and it will start asking for other ways to prove the account is yours: old passwords you remember, previous email addresses or phone numbers linked to the account, or photos if you're a Facebook user who's had the account long enough to have that option offered.
Have your ID ready
If Facebook can't verify you through account history alone, it may ask for a government ID upload that matches the name on the account. This step trips a lot of people up because they created the account years ago under a slightly different name or spelling. If your ID doesn't match exactly, the review can take longer, so it helps to submit it once, correctly, rather than resubmitting repeatedly, which can reset you to the back of the review queue in some cases.
Check your email for Facebook's security alerts, even old ones
Search your email inbox for anything from Facebook around the time you think the account was compromised. Sometimes Facebook sends a notification when the email or phone number is changed, and it includes a "secure your account" link that's still valid even after the change. This link can sometimes let you reverse the change directly instead of going through the full identity verification process. Check your spam folder too, since these alerts sometimes land there.
If the account is tied to a business, check what else the hacker can touch
This is the part people often miss. If your personal Facebook profile is an admin on a Business Manager, ad account, or Page, the hacker doesn't just have your profile, they potentially have access to your ad spend, your Page, and any apps connected through Facebook Login. While you're going through recovery, also check (from another device or account if you have one) whether your Business Manager shows unfamiliar admins added, whether ad campaigns have been created that you didn't set up, and whether your Page's payment method has changed. If you catch unauthorized ad spend, report that separately through Meta Business Help Center, since ad account fraud has its own support path and its own urgency, because money can be lost quickly there.
Watch out for "guaranteed recovery" services
Once people know your account was hacked, whether through a mutual friend or because you've posted about it publicly, you may get messages from people or pages offering to recover your account for a fee, sometimes claiming to have contacts inside Facebook. This is almost always a scam. Facebook doesn't have a paid fast-track recovery service, and legitimate recovery only happens through the official flow. Don't send anyone your login details, ID, or payment for this.
After you get back in
Once you regain access, do these three things immediately, in this order. First, change your password to something you haven't used anywhere else. Second, remove any unfamiliar devices or sessions from Settings, under "Where you're logged in," since the hacker's session may still be active even after you change the password. Third, turn on two factor authentication using an authenticator app rather than SMS if you can, since SIM swapping is one of the ways phone numbers get hijacked in the first place.
If your Facebook password was reused on other accounts, email, banking apps, or other social platforms, change those too, since a hacked Facebook account is often just one part of a wider credential leak.
One more thing worth checking: if the phone number the hacker added is one you also use for other accounts, or if you suspect a SIM swap happened rather than just a password guess, it's worth contacting your mobile carrier directly to confirm your SIM hasn't been ported without your knowledge. That's a separate problem from the Facebook side and needs its own fix.
Most important thing you may be missing:
If this account has any role in a Business Manager or ad account, the financial exposure while it's locked out matters more than the account recovery itself. Check your linked bank or card statements for unauthorized ad charges now, not after recovery finishes, since Meta's dispute window for unauthorized charges is time sensitive and recovery can take days.