TL;DR:
- Instagram and Facebook business account hijackings have surged across the UK — attackers use phishing, compromised admin personal accounts, and fake Meta copyright notices to take over pages
- Recovery is notoriously slow and unreliable through Meta’s official channels — prevention is the only reliable strategy
- Two-factor authentication on every admin’s personal Meta account is the single most important protection, because losing a personal account means losing access to any business pages it manages
Losing your business’s social media accounts is a significant operational event. Your followers, message history, advertising campaigns, and built-up reputation can disappear overnight — and unlike a hacked website, recovering a compromised Meta or TikTok account is genuinely difficult and sometimes impossible.
The number of UK small businesses reporting social media hijackings has risen significantly in 2025–2026, and the attack patterns have become more sophisticated. Here’s what you’re actually up against and what actually works.
How Attackers Are Getting In
Method 1: Phishing the business owner or page admin
The most common vector. Attackers send messages via email or Instagram DMs impersonating Meta, TikTok, or a third-party tool you use. The message claims your account is violating community guidelines, your page is being reviewed for suspension, or there’s a trademark dispute filed against you. You’re directed to a convincing fake Meta login page and asked to verify your identity.
Once you enter your credentials, the attacker has your login. If you don’t have two-factor authentication, they’re in immediately. If you do, they sometimes run a real-time relay — capturing your 2FA code and replaying it within seconds before it expires.
Method 2: Compromising a personal account linked to the business page
Business pages on Meta are managed by people through their personal Facebook accounts. If any admin’s personal account is compromised — through a phishing attack, credential stuffing from a leaked database, or malware — the attacker gets access to every business page that person manages.
This is why securing personal Meta accounts is just as important as securing your business page. Many business owners don’t realise the link.
Method 3: Fake copyright and impersonation reports
Meta and Instagram both allow users to file copyright or impersonation complaints. Attackers file fraudulent complaints against business accounts, claiming the account is impersonating someone or using their content. Meta sometimes acts on these reports by disabling accounts before the business has a chance to respond. The attacker then “helpfully” contacts the business offering to resolve the complaint — for a fee.
Method 4: Purchased compromised credentials
Credential stuffing using leaked database dumps. If your business email or the personal email associated with your Meta account appears in a data breach, attackers try that email and password combination automatically across Meta, Instagram, TikTok, and other platforms. If you reuse passwords, a breach of one site unlocks everything.
Why Recovery Is So Hard
Meta’s recovery systems are designed for individual consumers, not businesses. The official recovery path — submitting an identity document via the Help Centre — often results in automated rejections or no response. The “trusted contact” recovery option only works if you set it up before losing access.
TikTok’s recovery is similarly unreliable for small business accounts.
The brutal reality: if you lose access to your account and the attacker has changed the recovery email and phone number, the official recovery rate for small businesses is low. Multiple UK small business owners have reported spending months going through Meta’s channels without resolution.
This makes prevention not just preferable, but necessary.
Prevention: What Actually Works
1. Enable two-factor authentication on every admin’s personal Meta account — not just the business page
Go to your personal Facebook account settings → Security and Login → Two-Factor Authentication → Enable with an authenticator app (not SMS — SIM swapping is a real threat, covered in our SIM swapping guide).
Do this for every person who has admin access to your business page, not just yourself.
2. Audit your business page admins right now
Open your Facebook Business Suite or Meta Business Manager → Business Settings → Users → People. Remove anyone who no longer needs access. Former employees, freelancers, and agencies that finished contracts should be removed — their accounts may be less protected than yours.
Check the list quarterly.
3. Create a Meta Business Manager account if you haven’t
If your business page is managed directly through your personal Facebook account (the original setup), moving to Meta Business Manager gives you better control. In Business Manager, you can separate business asset access from personal accounts, add multiple admins without giving them personal account access to your business assets, and set up system users for API access without attaching them to a personal account.
4. Set up trusted contacts and recovery email before anything goes wrong
On your personal Facebook account: Settings → Security and Login → Trusted Contacts. Add 3–5 trusted friends or colleagues. If your account is locked, these people can give you recovery codes.
Also ensure your recovery email and phone number are up to date and secure. Your recovery email should use a strong, unique password and have its own 2FA.
5. Use a dedicated email address for your social media accounts
Don’t use your main business email (the one on your website) as the login for your social accounts. A separate email address that isn’t publicly listed is harder to target in credential stuffing attacks.
6. Instagram specifically: review third-party app access
Go to Instagram → Settings → Security → Apps and Websites. Review every third-party app with access to your account. Scheduling tools, analytics dashboards, and marketing tools you no longer use should be revoked. Each connected app is a potential attack surface.
If You’re Already Locked Out
If you’ve lost access to your account:
- Go directly to facebook.com/hacked or instagram.com/hacked — these are the official starting points, not Google results
- Use the “Get More Help” option if the automated flows fail — this routes to a human review queue (slowly)
- Report to Action Fraud (UK) — actionfraud.police.uk — even if they can’t directly help recover the account, a reference number can sometimes help in Meta escalations
- Check whether a linked ad account is affected — if you run paid ads, contact Meta Business Support directly through your ad account; paid advertiser support is significantly more responsive than organic page support
- Document everything — screenshot any communications from the attacker, preserve evidence of your ownership (historic posts from before your public email, payment records for promoted posts, original profile setup emails)
The most important thing: act immediately. Every hour that passes after a compromise gives the attacker more time to lock down recovery options and extract value from your account.
A 20-Minute Audit You Can Do Right Now
- 2FA enabled on your personal Facebook account (authenticator app, not SMS)
- 2FA enabled on your Instagram account
- 2FA enabled on your business email account
- Business page admin list reviewed and pruned
- Trusted contacts set up on Facebook
- Recovery email and phone number verified
- Third-party app access reviewed on Instagram
- Business email not publicly listed as the social login email
None of these take long. A compromise takes minutes; recovery takes months. The investment is worth it.