My friend’s hacked Facebook ad account: it probably wasn’t their fault
A friend who manages communications for a large organization called me one Friday afternoon, a little panicked. An active ad for their organization, live for weeks, was no longer promoting what it was supposed to promote.
Nobody had clicked a suspicious link that day. The entire ad account had changed hands, and the existing ad had simply been redirected elsewhere.
As a reminder, a Facebook ad account in Meta Business Manager grants access to everything: active ads, budget, the linked credit card, and often customer lists uploaded for campaign targeting. Taking control of that account is worth far more than a stolen password alone.
What my friend saw
The ad kept running, but its content kept changing. First a generic product like the kind you find on Temu. Then cryptocurrency. Then something else again.
That’s not random. An attacker who controls an ad account rotates multiple offers, partly to maximize clicks before Meta blocks the ad, and partly because Meta’s review teams eventually detect and reject certain creatives. Rotation is a tactic, not a bug.
Was it really my friend’s mistake?
That’s the first question everyone asks. And the honest answer: probably not, at least not in the way people imagine.
I see three causes that come up most often in these cases, and none of them look like “they clicked an obvious link.”
The first is phishing that mimics a real Meta notification. A message arrives claiming a page violated copyright or an advertising policy. To fix the problem, you’re asked to grant access to Business Manager. The request looks exactly like a real Meta procedure because it copies the exact format. An administrator who responds to that isn’t making a gross judgment error. They’re reacting normally to what looks like a legitimate obligation.
The second is browser extensions. Security researchers documented in 2025 an extension called CL Suite, offered on the Chrome Web Store, that promised to make Meta Business Manager easier to manage. In reality, it exfiltrated two-factor authentication codes and contact lists to an external server. An extension installed by someone on the marketing team, to save time, can be enough.
The third, the most common in my experience: an administrator or partner access that was never revoked. A former advertising agency, an employee who left long ago, temporary access granted for a one-off project. These access rights sit dormant, often for months, and nobody checks them.
In all three cases, it’s not one person who acted badly. It’s an access governance process that didn’t exist.
What to do next
Once hijacking is confirmed, the order of actions matters. Here is the sequence I recommend, in this order:
- Immediately remove unknown administrator and partner access in Business Manager settings, before anything else. Revoking access too late lets the attacker regain control while you handle the rest.
- Change passwords for all administrator accounts and regenerate two-factor authentication codes, don’t just re-enable them. If token theft is involved, changing only the password fixes nothing.
- Pause the compromised ad and report the hijacked account directly to Meta through the process provided for that.
- Review transactions on the credit card linked to the ad account and dispute unauthorized charges.
- Assess whether personal information may have been exposed, such as a customer list uploaded for ad targeting. If so, Quebec’s Bill 25 requires assessing the risk of serious harm and, if the threshold is met, notifying the Commission d’accès à l’information and the individuals concerned.
- Document the incident. Not to blame anyone, but because this is exactly the kind of evidence an ISO 27001 auditor will look for: how the organization detected, contained, and corrected the incident.
What organizations should put in place
In practice, prevention here isn’t technically sophisticated. It’s access governance, plain and simple.
At a minimum, nobody should share an ad account password with an agency or colleague. Meta Business Manager lets you grant precise roles—administrator, advertiser, or analyst—without ever handing over the password itself. An external agency should have partner access tied to its own business identifier, revocable in one click.
Two-factor authentication should be mandatory for all administrators, not optional. And a review of active access (who is an administrator, who has partner access, whether those people or agencies still work with the organization) should happen at least quarterly. That’s not a suggestion; it’s a basic control, the same as reviewing access to a financial system.
I’d add a less obvious point: browser extensions on workstations that manage ad accounts should be limited or approved. That’s not excessive; it’s exactly the vector documented in the CL Suite case.
In short, my friend probably didn’t make an obvious mistake. They trusted mechanisms their organization never put in place to verify who has access to what. I don’t yet know which of the three causes explains their specific case, and honestly, it doesn’t change the answer much.
Does your organization know right now who has administrator access to its Facebook ad account?