Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

Can Someone Hack Your Messenger? Here's Exactly How to Check

If you are skim reading
Straight answer: yes, Messenger can be hacked, and it happens through stolen passwords, cloned login pages, and stolen session cookies far more often than through anything clever.

Straight answer: yes, Messenger can be hacked, and it happens through stolen passwords, cloned login pages, and stolen session cookies far more often than through anything clever. You can check in under ten minutes by looking at your active sessions, your sent messages, and your connected apps, and I'll walk you through exactly where to click.

It happens more than people admit

I've been running social accounts professionally since before "influencer" was a job title, and I've had three clients in the last two years come to me white-faced because their Messenger inbox was sending things they didn't write. Not once was it a mysterious hacker in a hoodie in another country doing anything technically brilliant. Twice it was a fake Meta login page sent through a message that looked like it came from a friend. Once it was a browser extension the client had installed to "save time" that quietly harvested her login cookie.

Phishing kits that clone the Facebook and Messenger login screen sell for as little as $15 to $30 on the forums where this stuff gets traded, complete with the code needed to capture your password and hand it straight to whoever sent you the link. You don't need to be famous or wealthy to get targeted. You just need to be logged in, distracted, and click once.

My own scare, and the number that made it real

A few years ago, when I still had a much bigger public following, my Page inbox sent 340 near-identical messages in about forty minutes, all to people who'd messaged the Page in the previous six months, all asking them to click a link about a "limited investment opportunity." I hadn't sent a single one of them. What had happened wasn't a password guess. Someone had gained access through a Page role that had been added months earlier by a former assistant who'd since left the business, and the access was never removed.

That is the bit nobody tells you: the hack often isn't fresh. It's old access nobody bothered to clean up. If you've ever hired a virtual assistant, a social media manager, or an agency and given them Page or Business Manager access, and you never went back and removed them when the work ended, you have a door left open right now. I check this for every new consulting client in the first session, and I'd guess in eight out of ten cases we find at least one login or role that shouldn't still be there.

How Messenger gets hacked

Set aside the Hollywood version. The real methods are boring and repeat themselves constantly.

  • Phishing links disguised as messages from friends, saying something like "is this you in this video?" with a link that leads to a fake login page.
  • Reused passwords from a completely different site that got breached. If you used the same password on Facebook that you used on a shopping site that leaked, that password is on a list somewhere being tried automatically against thousands of accounts a minute.
  • Stolen session cookies grabbed by dodgy browser extensions or malware, which skip the password entirely and just impersonate your already-logged-in browser.
  • SIM swapping, where someone convinces your mobile provider to move your number to their SIM, then uses it to intercept the SMS code that resets your account.
  • Old admin or role access on a business Page, left over from a former employee, agency, or freelancer, exactly like my own story above.

Notice what's missing from that list: nobody "hacked" anything by being a genius. Every method above relies on you, or someone with access to your account, doing something ordinary and not noticing.

How to check if your Messenger has been hacked, step by step

This takes about ten minutes and you don't need to install anything.

  • Check where you're logged in. Go to Accounts Centre, then Password and security, then Where you're logged in. Look for devices or locations you don't recognise. If you see a login from a city you've never been to, that's your answer.
  • Check your sent messages folder. Scroll through recent chats for messages you didn't write, especially anything with a link, an urgent tone, or a request for money.
  • Check message requests you may have missed. Hackers sometimes reply to old message requests to spread a link quietly, banking on the fact you never check that folder.
  • Check connected apps and websites. In Settings, look under Apps and websites for anything you don't remember authorising. Old quiz apps and third-party schedulers are common culprits for leaked access.
  • If you run a business Page, check Page roles. Go to Page settings, then Page access, and look at every name listed. Remove anyone who no longer works with you, full stop, even if they were lovely and you trust them completely.
  • Check your login alerts. Turn these on if they aren't already, under Password and security, so you get a notification the next time a new device logs in.

If you find something wrong at step one or two, stop reading and go change your password right now, then come back.

Why two-factor authentication won't always save you

Everyone tells you to turn on two-factor authentication and treats it as the finished job. I use it, I recommend it, and it stops a huge number of attempts. But it doesn't stop the attack that's most common against ordinary people right now, which is someone calling or messaging you pretending to be "Facebook support" and simply asking for the six-digit code you just received, because you're panicking about a fake "your account will be deleted" warning they sent you first. Two-factor authentication protects you from a stranger guessing your password. It does nothing at all if you hand the code over yourself because someone sounded official and urgent. I've seen this trick work on sharp business owners, not gullible people, sharp people who were simply tired, distracted, and dealing with fifteen other things that day. If anyone ever asks you to read them a code, out loud, over any channel, the answer is no, always, no exceptions.

What to do if you've been hacked

  • Change your password immediately, and don't reuse anything close to your old one.
  • Log out of all sessions from the "Where you're logged in" screen, not just the suspicious one.
  • Remove any Page roles, connected apps, or linked accounts you don't recognise.
  • Turn on login alerts and two-factor authentication if they weren't already on.
  • Warn your contacts through a separate channel, like a text or an email, that any strange messages from you weren't from you.
  • Report the account through Meta's Help Centre using the "My account is compromised" flow, which is faster than the general contact form.

If it's a personal profile, most people get access back within a day or two once they've verified their identity. If it's a business Page tied to an ad account, the mess is bigger and slower, which is exactly why the role cleanup above matters so much before anything goes wrong, not after.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

If you run Messenger for a business

This isn't just a security issue, it's a customer trust issue. If your business Page sends a customer a phishing link because your account was compromised, that customer doesn't blame the hacker, they blame you, and they tell other people. I've written before about Messenger tricks that move sales for business pages, and every single one of those tactics depends on customers trusting that a message from your Page is from you. That trust is worth protecting with ten minutes of housekeeping a month.

If you're building out automated replies, quick sequences, or anything more involved in Messenger, it's worth understanding the mechanics before you hand access to a third party, which I cover in more depth in this piece on securing your Messenger chats. And if you're a smaller business trying to keep marketing tight without overspending, a locked-down inbox is one of those low-cost marketing basics that pays for itself the first time it stops a scam reaching a real customer.

The uncomfortable bit most people skip

Here's what I've learned doing this for a living: the person most likely to compromise your Messenger isn't a stranger, it's someone you gave access to and forgot about. Not maliciously, usually. An old freelancer. A friend who "just helped out" for a month. An app you authorised in 2022 for a competition you don't remember entering. Security advice loves to talk about hackers as outsiders, because that's less awkward than admitting most breaches trace back to access we handed out ourselves and never took back. Go and check your Page roles today. Not this weekend, today, while you're already thinking about it.

I keep every related walkthrough in the Facebook Help: 80 Guides to Pages, Groups, Ads, Stories and Fixes.

Frequently asked questions

Can someone hack your Messenger just by messaging you?

Not by the message alone, but if the message contains a link that leads to a fake login page and you enter your details there, that hands your password straight to the attacker. Never enter your Facebook password on a page you reached by clicking a link inside a message.

How do I know if my Messenger was hacked and not just glitching?

Check the "Where you're logged in" section under Password and security. Real hacks show up as an unrecognised device or location, unlike an app glitch which won't show a new session at all.

Will changing my password stop a hacker who's already inside?

Only if you also log out of all active sessions afterwards. Changing the password alone doesn't kick out someone who's already logged in on another device, which is why the "log out of all sessions" step matters just as much as the new password.

Can a hacker read old Messenger conversations even after I fix the account?

If they had access, they could have already seen or downloaded anything in your history before you locked them out, so once a breach is confirmed, treat any sensitive information shared in old chats as exposed and change any passwords or details you'd mentioned there.

Useful references

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.