To recover a hacked Meta ad account, secure the personal Facebook profile the attacker used first, then remove unknown people and partners, turn off ads you did not create, check your payment activity and open a case with Meta support. Deleted ads cannot be restored, but you can find them with a filter in Ads Manager and duplicate them.
The steps below follow Meta's own Business Help Center articles, in the order that limits damage fastest. They work for Facebook and Instagram ads alike, because both run through the same ad account and business portfolio. For everything else about running campaigns, see our Meta Ads hub.
How Meta ad accounts get hacked
Most takeovers of a Meta ad account start with a personal Facebook profile, not with the ad account itself. Ad accounts have no password of their own: whoever controls a profile with access to the business portfolio or the ad account controls the ads.
Phishing is the most common way in. Meta warns that attackers send business portfolio partner requests that include phishing links, and that these notifications come from a legitimate Meta domain (facebookmail.com). Other routes Meta mentions are reused passwords, fake login pages that look like Facebook, and malicious software or browser add-ons on the computer of someone with access.
Signs your ad account was compromised
The clearest signs are campaigns you did not create, charges you do not recognize, and people or partners you did not add. Emails from Meta about new admins, changed payment methods or new ad accounts are another warning.
Before you assume a hack, rule out the ordinary explanations Meta lists in its article on unrecognized ad account activity:
- You reached your payment threshold or your monthly bill date, so you were charged more often than you expected.
- A campaign has a daily budget where you meant a lifetime budget, or the other way around.
- A colleague or agency with access to the ad account or payment method ran their own ads.
If none of these explain what you see, treat it as a takeover and act on the same day.
First steps for a hacked Meta ad account
The order matters: lock the attacker out before you clean up, or they can undo your work. These are the steps Meta recommends, combined into one checklist.
- Secure your personal profile. Go to facebook.com/hacked on a device you have used to log in before. If you can still log in, reset your password, remove logins and devices you do not recognize, and review your activity log.
- Report the account as compromised. Meta says you can do this even while you can still log in, if you think someone else also has access.
- Turn off ads you did not create. Use the toggle in Ads Manager instead of deleting them. You keep the evidence for support and for your bank, and the spend stops.
- Remove unknown people. In Meta Business Suite, go to Settings, People, select the person and click Remove. Removing someone revokes their access to every asset in the business portfolio.
- Remove unknown partners. In Settings, Partners, open Options and select Remove from business portfolio. Also check Ad account roles in the ad account's settings.
- Check payment activity. In Billing and payments, open Payment activity and click each transaction ID you do not recognize. Remove payment methods you did not add, and contact your bank if a card or account was charged without permission.
- Contact Meta support. Open a case through Business Support Home or the Business Help Center (select Get support). List the ad account IDs, the transactions and the date you first noticed the activity.
Meta may already have acted before you noticed anything. Its help center says that when it sees suspicious activity it can remove admins, pause ads or change payment methods to protect the account. Check your email and Business Support Home before you reverse any of those changes.
What to do when you lost access completely
If the attacker changed your password, email address or phone number, start at facebook.com/hacked and follow the recovery flow. Meta's help center has a separate path for people who can no longer receive codes on the email address or phone number linked to their account.
A second risk is the business portfolio itself. Only people with full control can remove others, change security settings or turn on required two-factor authentication. If nobody in your organization has full control any more, Meta lets you submit a request to get full control of the business portfolio. Keep proof that the business and its assets belong to you, such as invoices for ad spend and domain ownership.
Undo what the attacker changed
Most changes an attacker makes can be reversed, but deleted ads cannot. The table shows what you can undo and where.
| What the attacker changed | Can you undo it? | Where |
|---|---|---|
| Password, email or phone of a profile | Yes, through account recovery | facebook.com/hacked |
| New people added to the business portfolio | Yes, remove them | Business Suite, Settings, People |
| New partners or agencies added | Yes, remove them | Business Suite, Settings, Partners |
| New ads or campaigns created | Yes, turn them off | Ads Manager |
| Your ads deleted | No, but you can view and duplicate them | Ads Manager, Deleted and archived filter |
| Payment method added or charged | Remove it, then dispute through Meta support and your bank | Billing and payments |
Can you recover deleted Meta ads?
No. Meta states that you cannot restore deleted campaigns, ad sets or ads. You can still view them with search filters and duplicate them, which gives you new copies with the same settings and creative.
To find deleted ads in Ads Manager on a computer:
- Click the search bar at the top that says Search by name, ID or metrics.
- Click Delivery and choose Campaign delivery, Ad set delivery or Ad delivery.
- Select Is, then choose Deleted and archived in the Select values menu.
- Click Apply.
Then select the deleted items and click Duplicate. Meta lets you duplicate into the original campaign, an existing campaign or a new one. To keep social proof, tick Show existing reactions, comments and shares on new ads before you confirm. The duplicates go through ad review again before they run.
Two details from Meta's documentation are worth knowing. Reporting data for ads metrics is kept for a maximum of 37 months, so very old deleted ads show up without results. And if you see error #1487056 while editing an ad set, the ad set was probably deleted: duplicate it and edit the copy.
If the attacker also touched your Meta Pixel or Conversions API setup, check your events in Events Manager before you restart campaigns. Our analytics, tracking and privacy hub covers how to verify that conversion data still arrives correctly.
Common mistakes after a hack
- Deleting the attacker's campaigns straight away. Deleted ads cannot be restored, and you lose the evidence support and your bank may ask for. Turn them off first, document them, then clean up.
- Securing the business portfolio but not the profile. If the compromised profile still has an active session, the attacker can add themselves back. Reset the password and log out unknown devices first.
- Having only one person with full control. If that one profile is hacked, nobody can remove the attacker. Keep at least two trusted admins with full control.
- Ignoring the payment side. Unrecognized charges need a support case with transaction IDs, and a call to your bank when a card was charged without permission.
- Skipping two-factor authentication afterwards. Meta lets people with full control require it for admins only or for everyone. For most businesses, everyone is the right setting.
How to prevent the next takeover
Two-factor authentication for everyone with access is the single most effective protection. Meta already requires it for some business portfolios older than 90 days, and anyone with full control can require it in Meta Business Suite under Settings, Business portfolio info, Business options.
Beyond that, use a unique password for Facebook, review people and partners in the business portfolio at least every quarter, and remove access as soon as an agency or employee stops working on the account. The same access hygiene applies to your other ad platforms, such as Google Ads and TikTok and Snapchat ads.
