
The login fails, and then the email arrives: the password on your account was changed, and you did not change it. Maybe a customer called first, asking why your business just messaged them about a giveaway. Maybe posts you never wrote are sitting at the top of your feed. When your business Instagram is hacked, or the Facebook Page goes with it, the lockout is only half the problem. The other half is years of followers you may not be able to reach, and customers who may be about to send money to someone using your name. There is an official way back in for each platform, and it costs nothing to start. The next hour matters more than the next week, so start with the steps below and keep this page open while you work.
Key Takeaways
Type instagram.com/hacked or facebook.com/hacked into your browser yourself. No phone line, fixer or paid service replaces Meta's own recovery process.
Whoever controls the email tied to the account can reset the password again, so lock that down before anything else.
Use your website, email list, Google Business Profile or storefront to say the account is compromised and that you will never ask for money, codes or passwords by message.
The FTC treats an unsolicited recovery offer that asks for a fee or personal details as a scam, and anyone asking for your two-factor code is not on your side.
Get Back In Through Meta's Official Recovery Pages
Meta runs a separate recovery route for Instagram and for Facebook, and a Facebook Page comes back through the person who manages it. The routes change what they ask depending on your situation, such as whether you still have the email or phone on file and whether you are using a device you have logged in from before. Meta's Help Center pages generally carry no publication date, and screens get relabeled, so the two recovery addresses below are safer to rely on than any list of menu taps. Type them into the browser yourself rather than clicking a link someone sent you.
Recover a hacked Instagram account at instagram.com/hacked
Go to instagram.com/hacked and choose the option that matches what happened, for example that your account was hacked or that someone changed your email. Depending on the account, Meta may offer a password reset, a login link, security checks or identity steps. This is the route to use if your Instagram was hacked and the email was changed, because you are not relying on the old email to prove who you are.
If your account includes photos of you, Instagram may ask for a video selfie. Meta says it uses this to confirm you are a real person, and the process asks you to turn your head for the camera. You will not have access to the account while the review runs. The selfie is offered for eligible cases, not for every business account, and a profile of only product photos may not qualify, so do not count on it being your only option.

Recover a hacked Facebook account at facebook.com/hacked
For Facebook, go to facebook.com/hacked, ideally on a phone or computer you have used to log in before. Meta's help page on how to recover a hacked account walks through the same route and the security steps that follow once you are back in. A device Facebook already recognizes gives you a better starting point than a new one.
Get a hacked Facebook Page back through the person who manages it
A Facebook Page does not have its own password. People reach a Page through their personal Facebook accounts or a business portfolio, so a Facebook business Page hacked in practice usually means a person's Facebook login was taken over first. Recovering the Page starts with recovering that person's Facebook account through facebook.com/hacked. It does not start with an unofficial support contact.
If someone else at the business still has full control of the Page, they can act right now. Meta's page on Facebook Page access explains that people with full control can change settings, manage who has access and remove others. That second admin should record the current access list, remove anyone who should not be there, secure their own login, and take screenshots before anything else changes.
Stop the Damage in the First Hour
Recovery requests can take time to review, but several things are fully in your hands while you wait. The order matters, because an attacker who still controls your email can undo each fix as fast as you make it. Do these on a phone or computer you trust.
Your first hour after the takeover
- 1
First 10 minutes
Secure the email account tied to Instagram or Facebook. Change its password, sign out other sessions and turn on two-factor authentication.
- 2
Next 10 minutes
Start recovery at instagram.com/hacked or facebook.com/hacked. If another admin still has access, have them remove unknown people now.
- 3
Next 15 minutes
Screenshot the unauthorized posts, messages, account URLs and times. Keep them before you report or delete anything.
- 4
Next 15 minutes
Post a warning on your website, email list, Google Business Profile and any social account you still control.
- 5
Last 10 minutes
Report any fake profile or Page pretending to be your business, and ask customers to report it too.
The email account comes first for a simple reason. The FTC's guide on how to recover a hacked email or social media account points out that control of your email can let someone reset passwords on your other accounts. The FTC's advice is to follow the provider's account recovery instructions, then change your password, sign out of all devices, turn on two-factor authentication and check your recovery information. Look inside the email account too, for forwarding rules or filters you did not set up.
Keep evidence before you clean up. Screenshots of the unauthorized posts, the messages sent to customers, the profile URL and the times you noticed each change help when you report the account and when you explain to customers what happened. Do not reply to the attacker, argue with them or pay them.
Keep Customers Safe While You Are Locked Out
Your customers are the people most exposed right now, and the compromised account cannot be trusted to warn them. Anything you post there could be deleted, and a message from that account looks exactly like the scam messages they may already be getting. Reach them through channels you still control.
- Your website: A short notice on the home page, where customers go to check whether something is real.
- Your email or text list: A direct note to the people most likely to receive a fake message.
- Your Google Business Profile: A post where searchers see it before they call.
- Your storefront or counter: A printed sign for walk-in customers.
- Other verified social accounts: If your Facebook Page is safe but Instagram is not, use the Page, and the other way around.
Keep the message short and plain. Say that your Instagram account (or Facebook Page) has been compromised, that you are working on getting it back, and that you will never ask for money, passwords, codes or payments through a direct message. Tell customers not to click links sent from that account, and name the one place they can reach you safely, such as your website's contact page or your shop phone. The FTC's guidance says to tell your contacts not to click unexpected links or respond to pleas for help or money.

Not every alarming message means your own account was taken. Sometimes the real account is fine and a copycat profile is messaging your followers. That needs a different first move, so work out which one you are facing.
| What you see | What it likely is | Your first move |
|---|---|---|
| Your password, email or phone number changed without you | Account takeover | Secure your email, then start recovery at the official link |
| Posts or messages you did not send, coming from your real account | Account takeover | Start recovery, then warn customers from other channels |
| You were removed as an admin of your Facebook Page | Account takeover of someone with full control | Recover the personal Facebook login, and have any remaining admin act now |
| A second profile with your name and photos is messaging customers | Impersonation | Report the fake account and warn customers; your real account still needs securing |
| A customer got a strange message but your account looks normal | Possible impersonation | Check for copycat profiles, change your password anyway and warn customers |
For a fake account, Meta lets you report a profile or Page that is impersonating you from the fake account itself, and there is a form if you have lost access to your own login. Customers can report it from the same place, and asking them to do so can help.
Spot an Instagram Recovery Scam on Sight
Once word gets out that your account was hacked, offers to help can arrive fast. They may come as a direct message, a comment under a post, a WhatsApp message, an email or a phone call, often from a profile that looks official or claims to work with Meta. Any unsolicited contact that promises to get your account back is not an official recovery route. The only safe routes are the addresses you type into your browser yourself, or the ones inside Meta's own apps and Help Center.
The FTC describes recovery scams as contacts that ask for an upfront fee or personal or financial information in exchange for helping you get something back. Watch for these signs:
- Payment in unusual forms: Cryptocurrency, gift cards, wire transfers or payment apps.
- A guarantee: A promise that recovery is guaranteed, or fast, for a price.
- A request for secrets: Your password, a two-factor code, backup codes, or remote access to your device.
- A lookalike address: A website or email that is close to Meta's but not quite right.
- Urgency: Pressure to act in the next few minutes before the account is "gone forever."
Meta's own account security guidance covers phishing, and Meta says Facebook will not ask for your password by email or message. Instagram has said the same kind of thing more bluntly: in its 2021 post on keeping Instagram safe and secure, it wrote that "Instagram will never send you a DM." If someone asks for your login code, they are trying to finish the takeover, not reverse it.

The same caution applies to anyone you might hire, including a marketing agency. No vendor can legitimately bypass Meta's recovery process, guarantee your account back, or safely take your password or codes. Start recovery yourself first, before you pay anyone for anything.
Secure Your Business Instagram So It Stays Yours
Getting back in is the start. The settings below are the ones Meta and U.S. government security agencies document, and they make the next takeover much harder. None of them guarantees an account can never be taken, but each one removes a common way in. Work through them on every account that can manage the business, not only the business profile.
Turn on two-factor authentication for every admin
Turn on two-factor authentication for each person's personal Facebook and Instagram login that can reach the business accounts. Meta supports several methods. An authenticator app or a security key is generally harder to steal than a text message, since a text code can be intercepted or moved to another SIM. CISA's small business guidance on multifactor authentication makes the same recommendation for business accounts in general. Save the backup codes somewhere safe that is not your phone.
Use a recovery email the business controls
The recovery email on each account should be an address the business owns, not a former employee's personal inbox or an old address nobody checks. Keep the recovery phone number current as well. When the recovery email belongs to someone who left, the business depends on that person to get its own account back.
Keep a second trusted admin, and only one or two
Have at least two trusted people with admin access to the Facebook Page and the business portfolio, so one lost login does not lock the whole business out. Limit full control to people you would trust with the whole account, because Meta says a person with full control can add or remove people, including the owner. Remove departed staff and former agencies once you have confirmed a second owner-controlled admin exists.
Watch for logins you do not recognize
Turn on login alerts and check the recent login activity on each account from time to time. An alert about a device or place you do not recognize gives you a chance to act before the password changes. CISA's social media account protection guide from August 2023 also recommends that organizations own their accounts, assign roles on purpose, use trusted devices and protect the email accounts linked to social profiles.

Stolen logins are a common way in across all kinds of breaches. Verizon's 2025 Data Breach Investigations Report found credential abuse in 22% of the breaches it analyzed. That figure covers every breach Verizon studied, not Meta business accounts in particular, and no public dataset ranks how small business Instagram and Facebook accounts get taken over. The practical order is still clear: phishing and stolen passwords first, then exposed recovery email, too many admins, missing two-factor, and old app or agency access.
Run the Ten-Minute Access Check Today
If you still control your accounts, or once you are back in, this check shows where you are exposed. It takes about ten minutes per account. Screenshot what you find and keep it with your business records.
- List who has access to each Facebook Page: Switch into the Page and open its access settings. Write down everyone with Facebook access, task access and, above all, full control.
- Check each high-access person's security: For every person with full control, confirm two-factor authentication is on, login alerts are on, and the recovery email and phone are current.
- Review recent login activity: Look for devices or places nobody recognizes on each admin's account.
- Check Instagram the same way: Confirm two-factor, recovery email and phone, and login activity for the Instagram account and any Facebook account linked to it.
- Remove people who no longer need access: Former staff and past agencies come off, but only after you confirm a second admin the business controls is in place.
If you do find gaps, the fixes are usually small. Setting up two-factor and updating recovery details takes about 15 to 30 minutes per admin. Cleaning up Page access usually takes 30 to 60 minutes. Checking connected apps, devices and old agency access can take one to several hours, and it is worth reviewing what each one does before you revoke it. A locked-out account is different: Meta's review depends on the case, and there is no reliable estimate for how long it will take.
Could you handle a hacked business account?
Pick an answer to begin.
1. Where should you start if your business Instagram is hacked?
2. What should you secure first in the first hour?
3. Someone offers to recover your account for a fee paid in gift cards. What is it?
Frequently Asked Questions About business instagram hacked
What is the official Instagram recovery page?
Go to instagram.com/hacked, typed into your browser yourself, and choose the option that matches what happened. It is free and it is Meta's own route.
How do I recover a Facebook business Page that was hacked?
A Page has no separate password, so you recover the personal Facebook account that had access through facebook.com/hacked, ideally on a device you have used before. If another admin still has full control, they can remove unauthorized people right away.
My Instagram was hacked and the email changed. Can I still get it back?
Yes, it may still be possible. Start at instagram.com/hacked and choose the option for a changed email. Meta may offer other ways to confirm it is you, including a video selfie for accounts with photos of you.
How long does Instagram's video selfie review take?
Meta does not promise a fixed time on the pages cited here, so keep checking the email address or phone number you gave and follow each step it sends. You will not have access to the account while it is under review.
Should I pay someone who offers Meta account recovery?
No. The FTC warns that unsolicited recovery offers asking for a fee or personal information are scams. Never share your password or a two-factor code with anyone.
How do I secure a business Instagram after getting it back?
Turn on two-factor authentication for every admin, use a recovery email the business controls, keep a second trusted admin, turn on login alerts, and remove former staff and agencies.
Final Thoughts
When a business Instagram or Facebook Page is hacked, the fastest safe route back runs through Meta's own recovery pages: instagram.com/hacked and facebook.com/hacked. Secure your email first, warn customers from channels you still control, keep your evidence, and report any copycat account. Anyone who contacts you offering recovery for a fee or asks for a code is part of the problem. Recovery can take time, and nothing you pay for will make Meta's review go faster.
Once you are back in, a few settings change the odds: two-factor on every admin, a recovery email the business owns, a second trusted admin and login alerts. With those in place and the ten-minute access check done, a stolen password becomes an inconvenience you can fix, and your customers hear from you first.
If you want a second set of eyes once recovery is underway, Web Leveling can help you sort out who has access to what. Our social media marketing work runs in accounts registered to your name, so the business keeps control of its own profiles. We work with small and medium businesses across the country and overseas. Tell us what happened to your account, and we will help you plan what comes next.
Terms
Account recovery words in this post
Tap a term to see what it means.
Account takeover. When someone else gets into your account and changes the password, email or phone so you cannot log in.
Impersonation. A separate, fake profile or Page that copies your business name and photos to fool customers.
Two-factor authentication. A second check at login, such as a code from an app or a security key, on top of your password.
Full control. The highest level of Facebook Page access, which lets a person manage settings, add or remove people and delete the Page.
Recovery email. The email address an account uses to confirm who you are and to reset your password.
Recovery scam. An offer to get back something you lost, such as an account, in exchange for a fee or personal details.
Video selfie. A short video Instagram may ask for to confirm a real person owns an account with photos of them.




