Every Facebook account is worth something to somebody. Yours holds a decade of photos, your private messages, your friend list, the Pages you run, and — for a huge number of people in Bangladesh — the shop that pays the bills. That is why account takeover has become one of the most reported cybercrimes in the country: in a single six-month window, the CID Cyber Police Centre logged 282 Facebook account hacking complaints and 165 SIM cloning cases among 3,766 total victims who reached out.
Here is the frustrating part. Facebook's own security advice is genuinely good, but it is scattered across seven different Help Centre pages, none of which tells you what order to do things in, how long each step takes, or which settings actually stop an attacker versus which ones just feel safer. This guide fixes that. If you have been searching for how to secure your Facebook account without reading seven separate help pages, this is the whole answer in one place: a single, ordered 10-step checklist with the exact menu paths for the 2026 Accounts Centre layout, an honest breakdown of which two-factor method is worth using, and a five-minute test at the end so you can prove your account is actually locked down instead of hoping it is.
Total time: about 25 minutes. You will not need to do it again for three months.
KEY TAKEAWAYS
- Order matters more than effort: kick out unknown sessions first, then change your password. Doing it in reverse leaves an attacker logged in on their own device.
- Not all 2FA is equal: SMS codes are the weakest option and are directly defeated by SIM swap fraud — a documented and rising problem in Bangladesh. An authenticator app is free and far stronger.
- Recovery codes are the step everyone skips: save them offline the same day you turn on 2FA, or you risk locking yourself out permanently.
- Your email is the real front door: a hardened Facebook account with a weak Gmail password is still wide open. Secure the recovery email and phone number too.
- Profile Lock is available in Bangladesh (it is not available in the US, UK, or most of Europe) — a one-tap privacy upgrade most global guides skip entirely.
- If you run a Page or an F-commerce shop, your personal account is the weak link. Page loss almost always starts with a compromised personal profile.
What is in this guide
- How Facebook accounts actually get hacked
- Before you start: which settings screen are you on?
- The 10-step checklist to secure your Facebook account
- Extra steps if you run a Page or online shop
- Verify it worked: the 5-minute test
- Four things that do not secure your account
- What to do if you are already hacked
- Your quarterly maintenance schedule
- Frequently asked questions
How Facebook accounts actually get hacked
Before you start flipping switches, it helps to know what you are defending against. Almost every real-world Facebook takeover falls into one of five patterns — and each checklist step below maps to at least one of them.
| Attack method | How it works | What stops it |
|---|---|---|
| Credential stuffing | Your password leaked in some other site's breach. Bots try that same email and password on Facebook. | Steps 3, 4 |
| Phishing pages | A fake login page (often sent via Messenger from a friend's hacked account) captures your password as you type it. | Steps 4, 6, 7 |
| SIM swap | Someone re-issues your mobile number on a new SIM, then intercepts your SMS login codes and password resets. | Steps 4, 5, 9 |
| Session hijacking | You stayed logged in at a cyber café, on a shared phone, or on an old device you sold. That session never expired. | Steps 1, 2 |
| Malicious apps | A "free followers" or cracked APK tool you granted Facebook access to years ago is still connected and posting. | Step 8 |
Notice what is missing from that list: nobody "hacks" Facebook's servers to reach your account. Every single one of these attacks goes through you — your password, your phone number, your inbox, or a device you forgot about. That is good news, because it means the fixes are entirely in your hands.
Before you start: which settings screen are you on?
This trips up almost everyone. Meta has been migrating accounts to Meta Accounts, which means security settings moved out of Facebook's own settings page and into a shared hub called Accounts Centre. Depending on your account, you may see either layout — and older tutorials (including some still ranking on Google) point at menus that no longer exist.
Here is how to tell in five seconds:
- You see "Accounts Centre" near the top of Settings → you are on the current layout. Everything security-related lives under Accounts Centre → Password and security. This guide's paths will match exactly.
- You see "Security and login" in the left column instead → you are on the legacy layout. The same options exist, just one level shallower. Skip the "Accounts Centre" step in each path below.
One more thing worth knowing: Accounts Centre can control several profiles at once — your Facebook profile, an Instagram account, a second Facebook profile. When you open a security setting, Facebook will ask which account you want to change. Read that screen carefully. Turning on two-factor authentication for Instagram does nothing for your Facebook login.
How to secure your Facebook account: the 10-step checklist
Work through these in order. The sequence is deliberate — steps 1 and 2 assume the worst (that someone may already have access) and shut that down before you start changing credentials.
If you only have five minutes: do steps 1, 2, and 4. Those three cover the overwhelming majority of real-world takeovers. Come back for the rest tonight.
Step 1 — Run Security Checkup (2 minutes)
Why first: Security Checkup is Facebook's own triage tool. It scans your account and surfaces anything obviously wrong — an old password, 2FA switched off, unrecognised devices — in one screen. Doing it first tells you how much work you actually have ahead.
Path: Menu → Settings & privacy → Settings → Accounts Centre → Password and security → Security Checkup
Work through every item it flags. Do not dismiss warnings you plan to "handle later" — the checkup will not remind you again. Note that this tool is only available when you are logged in on a computer or on a recent version of the Facebook mobile app; the mobile browser version often hides it.
Step 2 — Log out every session you do not recognise (3 minutes)
Why this comes before the password change: if an attacker is already logged in on their own phone, changing your password alone may not evict them from that active session. Kill the sessions first, then rotate the password so they cannot get back in.
Path: Accounts Centre → Password and security → Where you're logged in
You will see a list of devices, browsers, and rough locations. Go through it honestly:
- Keep only devices you are holding right now or use every week.
- Log out of anything unfamiliar — old phones you sold or gave away, a browser at a cyber café or your office, a friend's laptop you borrowed once.
- Log out of everything if you see a location or device you genuinely cannot explain, then immediately continue to step 3.
Bangladesh note: location data here is approximate and often shows the nearest large city or your operator's gateway rather than your actual district. A session marked "Dhaka" when you are in Sylhet is usually normal. Judge by device type and last-active time, not by the city name.
Step 3 — Set a unique, strong password (4 minutes)
The single most common cause of a hacked Facebook account is not a clever hacker — it is a password you also used on a shopping site that got breached three years ago. If your Facebook password appears anywhere else, treat it as already compromised.
Path: Accounts Centre → Password and security → Change password → select your Facebook account
What a good Facebook password looks like in 2026:
- Long beats complicated. A four-word passphrase like correct-mango-rickshaw-42 is stronger and easier to remember than P@ssw0rd!
- Nothing guessable from your profile. No name, birth year, phone number, spouse's name, or your Page name.
- Used nowhere else. Not on your email, not on bKash, not on your hosting panel — nowhere.
Remembering a dozen unique passwords is unrealistic, which is exactly what a password manager solves. If you would rather not use one, at minimum give your email and Facebook two completely different passwords you have never typed anywhere else. Our guide to creating strong passwords you can actually remember covers the passphrase method in detail, and you can check whether your current password has already leaked in a known breach.
Step 4 — Turn on two-factor authentication — with the right method (5 minutes)
This is the highest-value step on the list. Two-factor authentication means that even if someone has your correct password, they still cannot log in without a second code from a device you control. It stops credential stuffing and most phishing outright.
Path: Accounts Centre → Password and security → Two-factor authentication → select your account → choose method
Facebook offers three methods, and this is where nearly every other guide stops being useful. They are not equivalent:
| Method | Strength | Cost | Honest verdict |
|---|---|---|---|
| Text message (SMS) | Weakest | Free | Far better than nothing, but defeated by SIM swap and delayed by network issues. Use only as a backup. |
| Authenticator app | Strong | Free | The right choice for almost everyone. Codes generate on your phone, work without network or SIM, and cannot be intercepted. |
| Security key | Strongest | Paid hardware | Phishing-proof, but you must carry the key and it is harder to source locally. Worth it for high-value accounts. |
Setting up an authenticator app takes about two minutes: install Google Authenticator, Authy, or Microsoft Authenticator from your app store. In Facebook's 2FA screen, choose Authentication app, scan the QR code with the app, then type the six-digit code back into Facebook to confirm. Done.
Why this matters more in Bangladesh than most places
SIM swap and SIM cloning are not theoretical here — they were the subject of 165 complaints to the CID Cyber Police Centre in a single six-month period. If an attacker convinces an operator to re-issue your number on a new SIM, every SMS code Facebook sends goes to them, and so does every password reset link tied to that number. An authenticator app is completely unaffected by this, because the codes are generated on your device rather than sent over the mobile network. If you keep SMS on as a backup method, treat it as the weak link it is. See our full breakdown of how SIM swap fraud works and how to prevent it.
Step 5 — Save your recovery codes offline (2 minutes)
This is the step almost everyone skips, and it is the reason people permanently lose accounts they had "secured." When you turn on 2FA, Facebook generates a set of one-time recovery codes you can use instead of an authenticator code — if you lose your phone, break it, or get your SIM swapped.
Path: Accounts Centre → Password and security → Two-factor authentication → select account → Recovery codes
Facebook typically issues ten codes, each usable once. Store them somewhere that survives losing your phone:
- Best: a secure note in your password manager, plus a printed copy in a drawer at home.
- Acceptable: written on paper and kept with your important documents.
- Do not: screenshot them to your phone gallery, save them in Messenger "Note to self," or email them to yourself. All three defeat the purpose — if your phone or email is compromised, so are your recovery codes.
Step 6 — Add a passkey (3 minutes)
Passkeys are the newer, better replacement for passwords. Instead of typing a secret that can be phished, you unlock your account with your phone's fingerprint, face, or screen lock. Because a passkey is cryptographically tied to the real facebook.com, a fake login page cannot capture or reuse it — which makes it the only method on this list that is genuinely phishing-proof without buying hardware.
Path: Accounts Centre → Password and security → Passkeys → Create a passkey
Adding a passkey does not remove your password or your 2FA — it just gives you a faster and safer way to log in on your own device. On a mid-range Android phone or any recent iPhone, setup takes under a minute. If you do not see the option yet, it has not reached your account; check again in a few weeks.
Step 7 — Turn on login alerts (1 minute)
Login alerts notify you by email and notification whenever someone signs in from a device or browser Facebook does not recognise. They do not prevent a breach — they shorten it. Catching an unauthorised login within minutes instead of days is often the difference between changing a password and losing an account permanently.
Path: Accounts Centre → Password and security → Login alerts → turn on for email and notifications
Switch on both channels. If an attacker gets in and immediately disables notifications, the email still lands in your inbox.
Step 8 — Audit connected apps and websites (3 minutes)
Every time you tapped "Continue with Facebook" on a game, a quiz, a photo editor, or a "check who viewed your profile" tool, you handed that service standing access to part of your account. Most people have accumulated dozens. Many of those services no longer exist, have been sold, or were malicious from the start.
Path: Settings & privacy → Settings → Apps and websites
Be aggressive here. Remove anything you do not actively use this month. Removing an app you still need costs you thirty seconds to reconnect; leaving a forgotten one connected can cost you the account. Pay special attention to anything promising free followers, likes, auto-posting, or profile analytics — that category is where most malicious integrations hide.
While you are in a cleanup mindset, it is worth running the same exercise on your phone. Our guide to auditing app permissions covers what your installed apps can quietly read.
Step 9 — Secure the recovery email and phone number (3 minutes)
This is the gap that undoes everything above. Your Facebook account can be reset through your email address. If your Gmail password is weak, reused, or has no 2FA of its own, an attacker does not need to break into Facebook at all — they break into your inbox and let Facebook's own password reset flow hand them the account.
Three things to do:
- Check which email and phone are actually on file. Go to Accounts Centre → Personal details → Contact info. Remove any old email address you no longer control — a work address from a previous job or a defunct provider is an open door.
- Turn on 2FA for that email account. An authenticator app, same as step 4. This is non-negotiable if you use one Gmail for everything.
- Add a second recovery email that is not your primary one, so a single inbox compromise does not cost you both.
If your recovery email is Gmail, work through the Google account security checkup next — it takes another ten minutes and closes the same category of hole.
Step 10 — Lock your profile and tighten who can find you (3 minutes)
The first nine steps stop people from getting into your account. This one reduces what an attacker can learn about you from the outside — which is the raw material for impersonation, cloned profiles, and social engineering aimed at your friends and family.
Lock Profile bundles about seven privacy settings into a single tap. Once locked, only friends can see your posts, photos, stories, and full-size profile picture; past public posts switch to friends-only; and profile and tag review turn on automatically.
Path: Your profile → three-dot menu (⋯) beside Edit profile → Lock Profile → confirm
Good news for Bangladeshi users: Lock Profile is region-gated, and Bangladesh is one of the countries where Meta rolled it out. Users in the US, UK, Canada, and most of Europe do not have this button at all — which is exactly why most English-language security guides ignore it. If you do not see the option, check that Professional Mode is switched off, since the two are incompatible.
If the button is missing, you can achieve most of the same result manually: set Posts, Stories, and Profile and tagging to Friends under Settings → Audience and visibility, and turn on both profile review and tag review. Also turn on Profile picture guard, which blocks downloading and sharing of your profile photo — the single most common ingredient in cloned-account scams.
Finally, under Audience and visibility → How people find and contact you, restrict who can look you up using your phone number and email address, and switch Who can send you friend requests to Friends of friends.
THE 10-STEP CHECKLIST AT A GLANCE
- 1. Run Security Checkup — 2 min
- 2. Log out unrecognised sessions — 3 min
- 3. Set a unique, strong password — 4 min
- 4. Turn on 2FA with an authenticator app — 5 min
- 5. Save recovery codes offline — 2 min
- 6. Add a passkey — 3 min
- 7. Turn on login alerts (email + notifications) — 1 min
- 8. Remove unused connected apps — 3 min
- 9. Secure your recovery email and phone — 3 min
- 10. Lock your profile and limit discoverability — 3 min
Extra steps if you run a Page or online shop
For F-commerce sellers, freelancers, and anyone managing a business presence, the stakes change completely. Your Page is not a separate fortress — it is attached to your personal profile. Nearly every Page hijacking starts with the admin's personal account being compromised, which is why steps 1 through 10 are the real business security plan.
On top of those, do three more things:
- Review who has admin access. Old freelancers, a cousin who "helped set it up," and former employees frequently still hold full control. Remove anyone who does not need access today, and understand what each role can actually do before you assign it.
- Keep at least two admins. If you are the sole admin and you lose your account, the Page can become unrecoverable. A second trusted admin is your insurance policy.
- Require 2FA for everyone in your business portfolio. Your security is capped by the least careful person with access.
Watch out for partner-request phishing. Meta has warned about attackers sending Business Manager partner requests containing phishing links. These arrive from a legitimate Meta domain (facebookmail.com), so the sender looks completely genuine. If you do not recognise the person or business named in a partner request, do not click anything inside it.
We cover asset-level protection in depth in how to secure your Facebook Page from hackers.
Verify it worked: the 5-minute test
Turning settings on is not the same as knowing they work. Almost no security guide includes this part, and it is where people discover their 2FA was never actually confirmed or their profile is still public. Run these four checks now.
| Test | How to run it | Pass looks like |
|---|---|---|
| 2FA actually fires | Open a private/incognito browser window and log in to facebook.com. | You are asked for a code before you get in. |
| Recovery codes exist | Find your saved codes without using your phone's gallery or email. | You can read them off paper or your password manager. |
| Profile is really locked | Log out entirely, then view your own profile URL in a private window. | Strangers see almost nothing — no post history, no full-size photos. |
| Sessions are clean | Reopen "Where you're logged in." | Every device listed is one you can physically point at. |
If the first test lets you straight in without a code, your 2FA setup was never completed — go back to step 4 and finish the confirmation screen.
Four things that do not secure your account
Plenty of widely shared advice does nothing at all. Skip these:
- Copy-pasting a "privacy declaration" status. Posting a legal-sounding paragraph about not consenting to Meta using your data has zero effect on anything. It is a chain letter, not a setting.
- Third-party "account protection" or "verification" services. Anyone offering to secure, verify, or recover your Facebook account for a fee — especially via Messenger or a Page inbox — is running a scam. Meta never charges for account recovery, and handing over your credentials is the actual attack.
- Deleting the Facebook app to "log out." Uninstalling an app does not end the session. Log out explicitly, or clear it from "Where you're logged in."
- Relying on SMS 2FA alone and calling it done. It is a real improvement over no 2FA, but as step 4 explains, it is the one method with a well-documented bypass. Treat it as a backup, not your primary.
Learning to recognise the bait itself is the other half of the job — our guides on spotting phishing emails and fake links and why you should never share an OTP cover the tactics that get past technically secure accounts.
What to do if you are already hacked
If you are reading this because something has already gone wrong — you cannot log in, your password stopped working, or friends are receiving strange messages from you — stop working through the checklist and act in this order instead:
- Go to facebook.com/hacked and follow Meta's guided recovery flow. Do this from a device you trust.
- Check your email inbox and spam folder for messages from Meta about changed contact details. These often contain a "secure my account" reverse link that works even after the attacker changed your email.
- Warn your contacts through another channel so nobody sends money to a scammer using your name.
- Report it officially if money, blackmail, or impersonation is involved. In Bangladesh this goes to the CID Cyber Police Centre or through the national cybercrime reporting channels.
Our step-by-step Facebook account recovery guide for Bangladesh walks through the full process including identity verification, and how to report cybercrime in Bangladesh covers the official complaint route.
Your quarterly maintenance schedule
Security is not a one-time project. Put a recurring reminder in your phone and spend ten minutes on this every three months.
| How often | What to do |
|---|---|
| Every month | Glance at "Where you're logged in" and remove anything unfamiliar. |
| Every 3 months | Run Security Checkup, review connected apps, confirm Page admin list. |
| Every 6 months | Check whether your email appears in any new data breach; confirm recovery codes are still where you left them. |
| Immediately | After losing a phone, changing SIM or operator, selling a device, or ending work with a freelancer who had access. |
Frequently asked questions
How do I secure my Facebook account in the fastest way possible?
Turn on two-factor authentication with an authenticator app, then log out of every session you do not recognise. Those two actions take about eight minutes and block the majority of real-world account takeovers. Everything else on this checklist is worth doing, but start there.
Is SMS two-factor authentication safe enough?
It is much better than no two-factor authentication at all, but it is the weakest of the three methods Facebook offers. SMS codes can be intercepted through SIM swap or cloning, which is a documented and common attack in Bangladesh. Use an authenticator app as your primary method and keep SMS only as a fallback.
What happens if I lose the phone with my authenticator app?
You use one of your saved recovery codes to log in, then set up the authenticator app again on your new phone. This is precisely why step 5 exists. If you lose both the phone and the codes, recovery becomes a slow identity-verification process with no guaranteed outcome.
Can I lock my Facebook profile in Bangladesh?
Yes. Bangladesh is one of the countries where Meta enabled the one-tap Lock Profile feature. Open your profile, tap the three-dot menu beside Edit profile, and select Lock Profile. If the option is missing, make sure Professional Mode is turned off and your app is up to date.
Does changing my password log everyone else out?
Not reliably, and not instantly. That is why this guide puts session logout before the password change. Do it in that order, then verify in "Where you're logged in" that only your own devices remain.
How can I tell if someone else is using my Facebook account?
The clearest signals are unfamiliar entries in "Where you're logged in," login alert emails you did not trigger, messages or posts you did not create, friend requests sent from your account, and changes to your name or contact details. Any one of these means you should run steps 1 through 3 immediately.
Are passkeys a replacement for two-factor authentication?
Not exactly. A passkey replaces the act of typing a password and is resistant to phishing, but you should keep two-factor authentication enabled as well. Together they cover different failure modes: the passkey protects your day-to-day logins, while 2FA protects the fallback paths.
Why does Facebook keep asking me for a code even on my own computer?
Facebook needs to store browser and device information to recognise you next time. If you use private browsing, clear cookies on exit, or run privacy extensions that block this, you will be treated as a new device every session. That is a settings side effect, not a security problem.
Should I pay someone to recover or protect my account?
No. Meta does not charge for account recovery, and every paid "Facebook recovery expert" advertising in comments or Messenger is a scam. At best they take your money; at worst they take the credentials you hand them.
The bottom line
Learning how to secure your Facebook account is not complicated — the process is just poorly organised by the platform itself. The platform gives you every tool you need, then scatters the instructions across a dozen help pages and never tells you which switch matters most. Now you know: sessions first, then a unique password, then app-based two-factor authentication with recovery codes stored somewhere your phone cannot lose them.
Give it twenty-five minutes today and ten minutes each quarter after that. Compared with the alternative — losing a decade of photos, your customer conversations, or a shop you spent years building — it is the cheapest insurance you will ever buy.