The short version: yes, Facebook Messenger can absolutely be hacked, and the most common way in isn’t a genius bit of code, it’s you clicking a link that looks like it’s from a friend. You can check right now by reviewing your login activity and connected sessions inside Facebook’s security settings, and if you see a location or device you don’t recognise, act within the hour, not the week.
Yes, it happens, and I’ve watched it happen to a client mid-launch
I had a client, a coaching business owner in Manchester, whose Messenger got taken over three days before a product launch in 2023. Her page started sending links to her warmest leads, the people who’d asked about her programme, with a message that said “sorry for the delay, here’s the link you asked for.” It wasn’t her. Fourteen people clicked it before she noticed the odd phrasing in her own “voice” and locked her account.
She hadn’t done anything careless in the way people imagine. No dodgy attachment, no obvious scam email. She’d clicked a Messenger message from someone in her own friends list, a person whose account had already been compromised, that said “is this you in this video?” That single click handed over her session, and from there the attacker didn’t need her password at all.
That’s the bit most people miss. Hacking Messenger rarely means someone cracked your password through brute force. It means someone tricked you, or tricked a friend of yours, into handing over access without a password ever being typed.
The three ways someone gets into your Messenger
There are really only three routes in, and knowing them changes how you check.
- Phishing links from a friend’s compromised account. This is the “is this you?” message, or a fake Messenger login page disguised as a video preview. You click, you’re asked to “log in again to view,” and you just handed your password to a stranger.
- Session or cookie theft through a malicious browser extension. Free Chrome extensions that claim to add emoji packs, download videos, or “boost engagement” on Facebook are a well known way to lift your active login session without ever needing your password. Facebook has removed extensions like this from the Chrome Web Store repeatedly, but new ones appear under new names within weeks.
- Old, reused passwords from other data breaches. If your email and password combo leaked from, say, a retailer breach in 2019, and you used the same password on Facebook, someone can just try it. This is called credential stuffing and it’s boring, low-effort, and it works constantly because people reuse passwords far more than they’ll admit to me in consulting calls.
Two factor authentication stops most of route three. It does very little against route one or two, because once someone has your live session cookie or you’ve handed over a fresh login on a fake page, the second factor has already been satisfied or bypassed. That’s the uncomfortable part nobody selling security courses wants to say out loud: 2FA is good, but it is not the shield people think it is once a session is already stolen rather than a password guessed.
How to check if your Messenger has been hacked, step by step
This takes about ten minutes. I’d rather you did it now than after a launch week disaster like my client’s.
- Open Facebook on desktop, not the app. Go to Settings and Privacy, then Settings, then Password and Security. The app hides some of this detail.
- Click “Where you’re logged in.” This lists every device and location currently signed into your account. Look for cities you haven’t visited, devices you don’t own, or logins timestamped while you were asleep.
- Check “Log in Alerts.” If this is off, turn it on. It emails or texts you the moment your account logs in from an unrecognised device, which is the single most useful setting most people never touch.
- Review your Messenger apps and integrations. Under Settings, look at “Apps and Websites.” Anything you don’t recognise, especially anything with permission to “manage your pages” or “send messages on your behalf,” remove it immediately.
- Scroll your sent messages for anything you didn’t write. Check the last 48 hours specifically. Hacked accounts almost always send in a burst, then go quiet, because the attacker is trying to get links out before you notice.
- Check for new admins on any business page tied to your account. If you run a page for your business, go to Page Roles. This is the step most business owners skip, and it’s the one that cost my client the most, because whoever got into her personal account also got temporary admin access to her page.
If any of that turns up something odd, change your password immediately, log out of all sessions using the “Log Out of All Sessions” button, and turn on two factor authentication using an app like Authy rather than SMS, since SIM swapping is its own separate, quietly common problem.
What Facebook’s own tools show, and what they don’t
Facebook’s security dashboard is decent for what it does, showing device type, browser, and rough location for every active session. What it won’t show you is intent. It can’t tell you whether that login from London was you on a train with patchy 4G showing up as a different mast location, or someone else entirely. That ambiguity is exactly why people ignore these alerts, because half the time they’re a false alarm from your own phone switching networks.
I tell every client I work with to treat this the way I’d treat any part of the business, the same way I’d tell them to run a full site audit on their website every quarter rather than waiting for something to break. A ten minute Messenger security check, once a month, on a calendar reminder, catches this stuff early. If you already use monday.com to organise your business tasks, put “check Messenger login activity” on there as a recurring monthly card. It sounds almost too small a thing to schedule, but so does flossing, and most of us don’t do that regularly either.
Why business Messenger accounts are a bigger target than personal ones
If you run any kind of business page, your Messenger is worth more to an attacker than a personal account, because it comes with an audience that already trusts you and, often, a live chat function connected to real leads. Facebook reported removing over 1.3 billion fake accounts in a single quarter of 2023 alone, a huge chunk of which exist purely to message business page followers pretending to be the page owner. If you’re using live chat to convert website visitors into leads, a hacked Messenger doesn’t just embarrass you, it can quietly redirect real paying customers to a scam link before you’ve noticed anything’s wrong.
This is also why the basics of running your Facebook marketing now has to include security hygiene as a line item, not an afterthought. I’ve started adding “who has admin access to this page, and when did we last check” as a standing question in client audits, the same way I’d ask about ad spend or content calendars.
The small habits that reduce your risk
None of this needs to be complicated or take over your week.
- Never click a “is this you?” or “look at this video” link inside Messenger, even from a close friend, without messaging them separately to confirm first.
- Remove browser extensions you don’t remember installing, especially anything promising free followers, free likes, or “Facebook boosters.”
- Use a password manager so your Facebook password isn’t reused anywhere else, and change it if you’ve ever reused it on a site that’s had a public breach.
- Turn on Log in Alerts today. It’s a thirty second setting change that would have flagged my client’s problem three days earlier than she caught it herself.
- If you manage a business page, check Page Roles monthly and remove anyone who no longer works with you.
Some of the guides floating around this topic will tell you to check your account “regularly” without saying what that means in practice. I’d rather give you an actual number: once a month, ten minutes, same day as you pay your bills or check your business bank statement, so it becomes a habit rather than a panic response. If security checks and everything else on your plate feel like too much on top of running a business, that’s a real problem worth solving rather than ignoring, and it’s part of why I’ve written before about how to find time for the things that matter without letting the important-but-not-urgent tasks like this one slide for months.
And if you want the wider, non-security version of getting more out of Facebook for your business, I’ve also put together a full set of Facebook tricks and tips that’s worth reading alongside this, because good marketing and good security on the same platform go hand in hand more than people assume.
Frequently asked questions
Can someone hack Messenger without hacking Facebook?
No, Messenger runs on your Facebook login, so anyone who gets into your Messenger has effectively gotten into your Facebook account, and vice versa. There isn’t a separate Messenger-only password to steal.
How do I know if my Messenger was hacked and not just glitching?
Check “Where you’re logged in” under Facebook’s Password and Security settings for unfamiliar devices or locations, and scroll your sent messages for anything you didn’t type, especially links sent in a short burst. A glitch doesn’t send messages to your contact list. A hack does.
Does two factor authentication fully protect Messenger?
It stops most password-guessing attacks but does far less against session theft from a phishing link or malicious browser extension, since those methods can bypass the second factor entirely by stealing an already-authenticated session rather than guessing your password.
What should I do first if I think I’ve been hacked?
Change your password immediately, log out of all active sessions from the security settings, turn on Log in Alerts, and check Page Roles if you run a business page, since attackers often grant themselves temporary admin access there too.
Primary sources
Related reading: How to Download Videos From Threads Onto Your Phone and What Facebook Ad Automation Tools Help Save Time on Campaigns.
For the Messenger-specific version of these checks, here is how to Messenger security guide.