Recover a Hacked Facebook Business Portfolio
Business Portfolio compromised? Contain ad spend first, lock payments, then audit People, Partners, and System Users for anything the attacker left behind.
A compromised Business Portfolio is a money problem and an access problem at once. The attacker may be spending on your ad accounts right now, and they may have planted ways back in — a new person, a partner, or a System User token that keeps working after you change your password. Contain the spend first, then methodically remove every foothold.
If your situation is actually …
- Your personal profile was hacked too → Recover a hacked Facebook profile →
- You just need the spend-and-audit checklist → Stop fraudulent ad spend after a hack →
Recover a hacked Business Portfolio
Contain the damage
- Pause every active and scheduled ad campaign across all ad accounts.Stops the bleeding while you investigate.Where: Meta Ads Manager
- Remove or lock payment methods, then contact your bank to flag or block further charges.A reset password does not stop a System User token from spending — cutting payment does.Where: Meta Business Suite → Billing & payments
- Secure the personal accounts behind the portfolio with new passwords and 2FA.Where: Facebook → Settings → Security and login
Find every foothold
- Audit People in Business settings for any user you did not add.Where: Meta Business Suite → Business settings → People
- Audit Partners for any partner business you do not recognise.Attackers add a partner business so they keep access even after individual users are removed.Where: Meta Business Suite → Business settings → Partners
- Audit System Users — these are non-human accounts with long-lived tokens that survive password changes.A rogue System User is the most common persistence trick and the easiest to miss.Where: Meta Business Suite → Business settings → System Users
Remove the attacker
- Remove every unrecognised person, partner, and System User you found.Where: Meta Business Suite → Business settings
- Reissue or revoke tokens for any System User you keep, so old tokens stop working.Where: Meta Business Suite → Business settings → System Users
- Confirm you still hold full control of the portfolio and that no ownership claims changed.Where: Meta Business Suite → Business settings → Business info
Close the gaps
- Require two-factor authentication for everyone with portfolio access.Where: Meta Business Suite → Business settings → Security Center
- Keep at least two trusted admins so one compromised account cannot lock everyone out.Single-admin setups are how a hack becomes permanent.
- Schedule a recurring access review so leftover partners and System Users surface before they become incidents.
Frequently asked questions
Delvia
Access issues are easier to prevent when roles, owners, and responsibilities are recorded clearly
Most access problems trace back to the same gap — no clear record of who has access, what role they hold, and what should happen when that changes. Delvia helps you keep that record so problems are visible before they become incidents.