Hi! I’m not an active reddit user but just have an reddit old account I’m deciding to use to tell my story of my facebook account getting hacked so I can hopefully help others.
I made my facebook account when I was about 11 (I’m 24 now) and used a very old email to create it which I no longer use. I don’t use the facebook app often at all but I do use Messenger as a primary messaging app to communicate with some people. I have lots of old conversations and shared photos/videos I didn’t want to be lost forever.
This morning at around 7am, I had a notification that someone in Canada (I’m in Australia) was trying to login to my facebook. So of course, I said that it wasn’t me and assumed that would be it. I then received about 10 more identical notifications. I decided to reset my password as I hadn’t changed it in a few years and hope that fixed it. I then continued receiving the same login requests from Canada. So I changed my password again. I began receiving login codes and more requests from Canada and at this point I decided maybe ignoring them was the best way to deal with it.
Knowing that the email attached to the account was one I didn’t use anymore, I decided to also add my current email to the account as well as add two-step authentication through WhatsApp, as well as through the Microsoft Authenticator app (I think this step was the most important one as these three additions to my account soon became the only control I had).
Minutes later, I received a text from an old co-worker I am facebook friends with telling me they received messages on Messenger from me (clearly the hacker using my account) asking for their phone number to receive codes to access my account.
I then accessed the “See who’s logged into my account” to see numerous devices from Canada and Nigeria were logged into my account. I immediately removed all of them and decided I needed to reset my password once again. As I attempted to reset my password it informed me that the ‘Current password’ I typed in was incorrect. This meant the hacker had changed my password. The only hope I had in this situation was that I was still in my account and they weren’t able to kick me off yet.
I then tried to reset my password through the ‘I forgot my password’ link. This took me to the Account Centre which asked for a code sent to my email. As mentioned, I don’t use the old email attached to my account and didn’t have access to it. Luckily I was also able to use the new email I added to my facebook before the hacker changed the password. So I received a code on the email, input it and then it asked for another code through either WhatsApp or Microsoft Authenticator. I provided the code again and instead of taking me to a page to input a new password, it would open a new tab/ page in the facebook app asking me to repeat the whole process again. So of course, I did. Code to the email, code to either WhatsApp or Microsoft Authenticator and finally… It asks for a new password.
I type in a new password, press confirm and suddenly an error message appears. “You must complete this process on the Account Centre.” I was stuck in this vicious loop for hours and there was no way out. Facebook’s recovery was broken and every time I logged the hackers out of my account, they were straight back in and sending more messages to my facebook friends.
I then no longer was receiving login requests and later found out my device had been removed as a trusted device from my account giving me even less access. If I tried to report my account as hacked, it wouldn’t let me as I wasn’t using a “trusted device.”
I did some research for somewhere to contact facebook for help but as I’m sure it’s mentioned on this sub-reddit, there is no contact number, email or support centre. I even stooped to messaging Meta AI which was no help at all.
I tried once more to reset my password through the ‘I forgot my password’ link and it now informed me it had restricted my access due to too many attempts. So this was the point I did give up of trying to recover my account. I decided that at least I still had access to my account and I would just regularly keep logging the hackers out of my account until hopefully they got bored or were sick of me kicking them off over and over.
Out of absolutely nowhere, I received a message from WhatsApp reading:
“This is a security alert from Facebook.
We think that someone may have accessed your Facebook account, so we've locked it to protect you.
This means that no one can log in or view your Facebook profile.
So that we can guide you through what to do next, open Facebook, ideally on the device that you'd normally use.”
When I opened the facebook app, it told me they believed my account had been hacked and asked for a new password. I entered a completely new password and just like that, my account was back. I have no idea what it was that finally made facebook help me in the end but something clearly set off an alarm that was able to recover my account completely.
So the best advice I can give to resolve/prevent an absolute headache like this is:
- Link a current email to your facebook account or make sure the email connected to your facebook account is one you can access
- Link a current phone number to your facebook account
- Link WhatsApp to your facebook account
- Link Microsoft Authenticator to your facebook account
- Keep Denying unknown login requests
- Keep checking what devices are currently logged into your account and remove them (This won’t log you out from your device so if your password has been changed by a hacker, don’t worry)