If someone takes over a Facebook account that can manage your business, the damage can extend to advertising, Pages and other connected assets. Two-factor authentication is still important, but recovery must also address the device, active sessions and business permissions that may have been compromised.
This guide reviews historical first-party malware research and provides a defensive response framework as of September 14, 2026. It does not diagnose an individual incident or describe a newly discovered attack. Use the official recovery routes available for the account, and preserve evidence while containing further misuse.
- 01Protect the session as well as the login.A successful authentication check does not establish that the device or an existing session remains trustworthy.
- 02Review connected business access.A personal account can be the entry point to Pages, advertising and business administration.
- 03Contain and verify before resuming spend.Regaining a password is not the same as confirming that unauthorised access and activity have stopped.
01 — Practical guidanceWhy another login factor is not the whole boundary
A login challenge checks a sign-in attempt. After authentication, a session lets a person continue working without repeating the whole process for every page. Malware or other account compromise can threaten that continuing access. This is why device health and session management matter alongside the password and second factor.
In its May 2023 business-malware report, Meta described campaigns targeting personal accounts connected to business assets, including malware capable of attempting to evade two-factor authentication. That is historical evidence of a mechanism, not a measurement of current attack frequency.
Google’s 2024 download-security discussion also described cookie-theft malware distributed through password-protected archives. The practical lesson is to treat unexpected downloads and extensions as part of the advertising account’s risk, even when they appear unrelated to the campaign.
02 — Practical guidanceSeparate containment from account recovery
When compromise is suspected, work from a device you have reason to trust. Use the platform’s official recovery route rather than a link supplied in an alarming message or by someone promising paid recovery. If the account is still accessible, record suspicious activity before removing the access responsible for it.
The table is a defensive sequence to adapt to the incident. It is not a promise that every control is available to every account. When the business lacks the expertise to investigate a suspected compromised device, involve its security or IT support rather than repeatedly signing back in from the same environment.
| Area | What to inspect | Evidence to preserve |
|---|---|---|
| Device | Unexpected software, extensions and recent downloads | Relevant timestamps and security findings. |
| Account | Recovery details, active sessions and authentication changes | Security notifications and account identifiers. |
| Business access | People, partners and applications with permissions | Unexpected additions, roles and change times. |
| Advertising | Unrecognised campaigns, destinations and spending | Campaign IDs, dates and billing records. |
| Recovery | Official case status and remaining unexplained access | Case identifiers and verification notes. |
03 — Practical guidanceRegaining access is only one recovery milestone
Changing a password addresses one credential. It does not by itself demonstrate that malware is gone, that sessions have been revoked or that a business role added by an intruder has been removed. Treat these as separate checks with separate evidence.
Meta’s historical report specifically warned about re-compromise when malware remains on the device. A repeated takeover should therefore trigger investigation of the endpoint and connected access, not just another password reset. Retain the distinction between the account being accessible and the environment being trusted.
After restoring access through official channels, inspect the assets the account can manage. Review administrator and partner access, connected applications, recovery details and unexpected campaign changes. Do not remove legitimate colleagues indiscriminately: identify each role and record the reason for a change.
04 — Practical guidanceControl spending and preserve the incident record
If unauthorised ads are running and you have legitimate access to stop them, contain that activity while documenting the affected campaign and account IDs. Check whether destinations or creative were changed, rather than assuming a familiar campaign name means the campaign is safe.
Preserve relevant billing and transaction records for the provider’s dispute or support process. Where a payment method may be compromised, contact its issuer through a known official channel. This guide does not promise reimbursement or establish which party is financially responsible for a particular incident.
A useful incident record distinguishes observed facts from hypotheses: an unrecognised administrator is a finding; the theory that a specific download caused the theft needs additional evidence. The Google Ads security guide covers related controls for another advertising environment.
05 — Practical guidanceReduce the opportunities for another compromise
Keep multi-factor authentication enabled and use stronger authentication options where the platform supports them. Limit privileged business access to people who need it, review integrations and remove obsolete permissions. Authentication, authorisation and device controls work together; none should be presented as a substitute for the others.
Create a clear process for unexpected software requests. A marketer should not need to install a browser extension from an unsolicited message to inspect an invoice, campaign warning or creative brief. Verify requests using a separate trusted route, especially when they create urgency around account suspension.
For paid-media operations, agree who can pause campaigns, contact support and investigate account changes. A response plan written before an incident reduces the need to improvise while money is being spent. Resume activity when the relevant checks support it, rather than when the login screen finally works.
Download the reference table (CSV). The download contains the rows shown above, with their scope and review date. It does not contain campaign results or a completed assessment of your business.
For connected automation, the agent access checklist and agent identity guide help distinguish human access from delegated tool permissions.
Evidence and scope
- As-of date
- September 14, 2026. Sources reviewed for this article; the editorial allocation is September 13, 2026.
- Method
- Historical Meta and Google security research used to explain the threat mechanism. Five original defensive inspection rows; no incident investigation or live account changes.
- Limits
- Recovery options vary. Historical campaigns are not presented as current incidents. No guarantee of malware removal, account recovery or reimbursement.
06 — Next stepVerify the whole access path
Verify the whole access path
Keep 2FA, but investigate beyond it. A sound recovery checks the device, sessions, business permissions and advertising activity, with evidence for each step. Treat restored login access as a milestone and confirm the remaining boundaries before returning to normal operations.