Securing your social media accounts
How to protect your Facebook, Instagram, LinkedIn, and other social media accounts from hackers and unauthorized access.
- Difficulty
- Intermediate
Social media accounts are a common target for attackers. A hacked Facebook page or Instagram account can damage your reputation, expose your customers to scams, and be difficult to recover — especially if the attacker changes your recovery information.
A few steps make your accounts significantly more secure.
Quick summary
Enable two-factor authentication on every social media account. Use a strong, unique password for each. Review who has admin access regularly. Never share your password — use admin roles instead. Set up a backup admin account so you're never locked out.
The biggest risks to social media accounts
- Weak or reused passwords — attackers try credentials stolen from other site breaches
- Phishing — fake "your account has been restricted" emails trick you into entering your password on a fake login page
- No 2FA — without it, a stolen password is all it takes
- Too many admins — old employees or contractors still having admin access
- A single admin — if that account is compromised, you lose access entirely
Turn on two-factor authentication
This is the most important step. Do it on every platform:
For your personal Facebook account (which controls your business page):
- Click your profile picture in the top right, then click Settings and privacy.
- Click Settings.
- Click Accounts Center, then Password and security.
- Click Two-factor authentication, then click the account you want to update.
- Choose the security method you want and follow the on-screen instructions. Facebook offers a security key, login codes from a third-party authentication app, or text message (SMS) codes — an app or a security key beats SMS.
Facebook will also give you 10 recovery login codes for when you can't use your phone. Save them.
Meta is moving people to Meta Accounts, so you may see either Accounts Center or Meta Account settings as the place to manage these settings.
If your Page belongs to a business portfolio: the portfolio's business settings are where you manage who has access. Ask us if you want two-factor authentication required for everyone who works on your assets — the options change as Meta reorganizes Business Suite.
Use unique passwords for each platform
Use a password manager to generate and store a strong, unique password for each social media account. Never use the same password across platforms.
Review who has admin access
People often have lingering admin access that should have been removed months or years ago. Take 10 minutes to review:
Facebook Page: switch into your Page — Facebook requires that before you can manage access — then open Page access. Meta splits this into three types — Facebook access (which can be full control), task access and Community Manager access — so check all three and remove anyone who no longer works with you. If the Page belongs to a business portfolio, manage access in the portfolio's business settings instead.
Instagram: If managed through Meta Business Suite, check business settings. Remove former team members.
LinkedIn Page: go to your Page's super admin view, click Settings in the left menu, and select Manage admins. You need to be a super admin to add or remove another admin.
Other platforms: Check the equivalent "Team," "Members," or "Users" settings on each platform you use.
See also Security steps when someone leaves.
Set up a backup admin
On Facebook and LinkedIn, at least two people should hold top-level access. On a Facebook Page that means two people with Facebook access with full control; on a LinkedIn Page it means two super admins, since only a super admin can add or remove another one. If the main account is locked out, hacked, or deactivated, the second person can maintain access.
That second person should be someone you genuinely trust — a business partner, or a long-standing member of your team.
Never share your password — use roles instead
All major platforms support multiple admin roles. Instead of sharing one login, invite team members with their own accounts and assign them the appropriate role (admin, editor, moderator, etc.).
This means:
- Everyone has their own login with their own 2FA
- You can remove one person's access without changing shared credentials
- You have an audit trail of who did what
Watch for phishing emails from "Meta" or "LinkedIn"
A very common attack: you receive an email claiming your account has been restricted, that you violated community standards, or that urgent action is required. The email links to a convincing fake login page.
Before clicking any such link, check the sender's actual email address and go directly to the platform by typing the URL yourself. See How to recognize phishing attempts.
Common questions
My Facebook Page admin access was stolen. What do I do?
Go to facebook.com/hacked to start the recovery process. Act as quickly as you can: the longer an attacker holds the account, the more likely your recovery details have been changed. Meta also has a specific process for recovering a hacked Page you manage. See What to do if an account is compromised.
Can I separate my personal Facebook from my business page?
Not entirely. A Facebook Page is managed from a personal Facebook profile — you switch into the Page from your profile to work on it — so the two stay connected. The best approach is to keep your personal account's security tight and add a trusted second person with full control of the Page. A business portfolio gives you a cleaner way to manage who on your team has access.
What if I'm the only admin and I get locked out?
Recovery is very difficult in this situation. This is why having a backup admin is so important — set one up before it's needed.
Should I use a social media management tool like Buffer or Hootsuite?
Social media management tools are fine to use, but they represent additional access points to your accounts. Ensure they are connected only through official OAuth (the "Connect with Facebook" style authorization), not by sharing your password. Review and revoke any tools you no longer use.
Related guides
- Two-factor authentication, explained
- How to set up two-factor authentication
- Security steps when someone leaves
- How to recognize phishing attempts
- What to do if an account is compromised
Need a hand?
Learn more
Last updated
Device & Wi-Fi security basics
Simple steps to keep the computers, phones, and networks your team uses every day secure against common threats.
Data privacy basics for your business
A plain-English introduction to data privacy — what data your business likely holds, your responsibilities, and how to handle it well.