What to Do When a Brand Account Is Hacked.
The first hour decides whether you get the account back. The recovery routes that actually exist, and the setup that makes recovery possible at all.
The password stops working, the recovery email points somewhere nobody in the business controls, and something you did not write is live on the account.
The short version: go to the platform’s own recovery route from a device you have logged in on before, secure the email account sitting behind it, and change nothing you cannot undo. Then prove the business owns the account.
That last part is where most brands stop. Account recovery is not really a security problem, it is social operations: every route back in depends on decisions taken months earlier, about who holds admin, where the recovery contacts point and whether anyone can show the page belongs to the company.
Most brands find out they cannot at the worst possible moment.
The first hour, in order
- Open the platform’s own recovery route, on a device you have logged into that account from before. Facebook publishes facebook.com/hacked, Instagram publishes instagram.com/hacked. Device history is one of the signals used to decide whether you are you.
- Check the old recovery inbox. When the email on a Facebook account is changed, a message goes to the previous address with a link that reverses it. That is the quickest way back in, and useless if nobody reads that inbox.
- Secure the email account itself. Change its password, then check its filters and forwarding rules, where an attacker keeps a copy of every reset code you request.
- If you still have any access, end every other session and revoke connected apps.
- Screenshot everything before it changes: the posts, the messages sent, the login activity, the account and page IDs.
- Tell the people who need to know, including the client if you are the agency.
What not to do
- Do not delete the page, the account or the attacker’s posts. Deletion is the one action you may not be able to reverse, and it destroys the evidence a support review asks for.
- Do not keep trying passwords. It does not help, and it buries the login history you need to read.
- Do not pay anyone who arrives in your DMs offering to get the account back. That offer is the second attack.
- Do not launch a replacement account on day one. A new handle announced in a panic teaches your audience to follow an unverified account, which is what the next impersonator counts on.
When the recovery contacts have already been changed
This is the fork almost every brand hits. The attacker changes the email, changes the phone and adds their own second factor, so every automated route now runs through contact details they hold.
Two questions decide what is left. Can anyone still read the old inbox, and can the business prove ownership another way.
If that old address belonged to a freelancer or someone who has left, the fast route is closed. Facebook documents a separate path for people who cannot reach their email or phone. LinkedIn’s forgotten password flow offers “Can’t access this email?” and then “Don’t have access to any of these?”, which ends with you supplying a new address and verifying your identity.
Both end in the same place: proving who you are to a review process rather than to a colleague.
Proving who you are, and proving the business owns the page
These are two different proofs, and brands routinely bring only the first.
For identity, Meta accepts one government issued ID showing your name with either your date of birth or your photo, or two non-government documents such as a student card or an employment confirmation. In some markets, including the UK and the EU, Meta also offers a video selfie matched against the profile photos on the account. Availability is uneven, so treat it as a route you may be offered, not one to plan around.
LinkedIn verifies identity through Persona, its verification provider: a valid government issued ID, sometimes with a photo of your face to match it. In the UK, the EU and Canada a notarised affidavit is accepted instead.
Ownership is the harder proof, and the one almost nobody has ready.
Why a business portfolio changes the odds
Meta publishes a recovery route for a compromised business portfolio that sits apart from the consumer hacked account flow. A page held inside a portfolio is an asset the business owns, with named people holding roles against it.
A page held only inside a personal admin’s login has one route, the same consumer form as everybody else.
Meta’s rule on page access is also unforgiving: only someone with full control can grant, change or remove access. If the attacker holds full control and everyone else was removed, there is nobody left inside the business who can put you back.
For a hacked page you still manage, the route is a recovery form. Meta aims to respond within a day, says some reviews take longer, and can only act once it confirms the page really was hacked. That last clause is why the screenshots matter.
What the other platforms give you
LinkedIn’s route is the Report Unauthorized Account Access or Changes form, whether or not you can still log in. If you can, do four things at once: change the password, turn on two-step verification, sign out of every session you do not recognise, and read the full list of email addresses and phone numbers on the account, not just check that yours is still there.
TikTok and X both route through their own in-product support forms, and those paths move more often than brand documentation gets updated. What is stable is the shape: you start from the platform’s help centre while logged out, and the form asks you to prove control of a contact method you may no longer control.
So write the help centre into the runbook, not a saved deep link that will 404 on the day you need it.
Who makes the call, and who talks to the audience
Two roles, agreed before anything happens.
One incident owner runs recovery and is the only person filing support requests. Three colleagues opening three cases makes the request harder to read, not faster to resolve.
One communications lead speaks to the audience on the channels you still hold. The holding message is short and factual: the account is compromised, you are working on it, and you will never ask anyone for money, codes or payment details. Promise no timeline.
Post it where people will see it: your other social channels, your site and your email list. Not the compromised channel, and not buried in a comment argument.
Own the account, do not borrow it from a person
A brand account that lives inside one person’s login is a single point of failure with a notice period attached.
Put the page in a business portfolio, with the business as owner and individuals granted roles against it. When someone leaves you remove a role, rather than negotiating with a former employee for a password.
Hold full control in at least two pairs of hands. Not because two people need it daily, but because one can leave, lose a phone or get compromised, and the second is the only reason the first is recoverable.
Then write it down. A one page record of every account, everyone with access and the role they hold belongs in the same review as the rest of your operating detail, which is what a social media audit checklist is for.
Recovery contacts and second factors
- The recovery email should be a monitored company address on a domain the business owns, read by more than one person. A personal address belonging to whoever set the page up is the first thing to change.
- The recovery phone should not be a handset that walks out of the building with an employee.
- Use an genuineator app or a security key rather than SMS. The UK’s National Cyber Security Centre ranks message-based codes last among the methods it recommends, and key-based credentials such as passkeys first. Any second step still beats none.
- Store the backup codes properly. Facebook issues ten one-time recovery codes, and they belong in the company password manager, not a screenshot on somebody’s phone.
- Turn on Meta’s Advanced Protection where it is offered. It checks the account for weaknesses and requires a stronger login, and Meta already treats page admins and portfolio members as higher risk.
The access review is a scheduled job, not a reaction
Put it in the calendar with a named owner, quarterly at minimum. It is a short job.
- Every account, every person with access, every role they hold.
- Anyone who has left, removed the day they leave rather than the week after.
- Recovery email and phone on each account, confirmed to point at the company.
- Second factor confirmed as an app or a key.
- At least two people holding full control.
An access review that happens when someone remembers is an access review that happens after the incident.
What good looks like
The brand that gets hacked and is back the same day is not lucky. It is the brand where the page sits in a business portfolio, two people hold full control, the recovery inbox is a company address somebody reads, the second factor is an app, the codes are in a password manager, and there is a written record of who holds what.
Recovery then becomes a form, filed by a named person, with evidence attached, from a device with login history. That is a case a reviewer can approve. The alternative is a stranger asking a platform to hand over an audience.
Some accounts are never recovered. That is the honest reason the preparation matters more than the recovery, and it is the same discipline that makes everything else run like a system.
How NBK thinks about account security
NBK treats account access as part of the operating system, not an IT chore somebody will get to. Ownership, admin roles and recovery contacts sit on the audit list next to cadence, approvals and reporting, because an account the business cannot prove it owns is a risk behind every post it publishes.
Teams that come through an incident well are not the ones with better luck. They are the ones whose workflow had already answered who decides, who speaks and who holds the keys.
Next step
If nobody in your business can say today who holds full control of every social account, that is the gap to close first. If you want social to run with more clarity and accountability, NBK can map ownership, access and recovery contacts as part of an audit.
The NBK Social briefing
Our Facebook coverage, and everything else we publish, by email.