Account takeover is one of the few risks in Meta advertising that's entirely preventable with basic discipline, yet it remains one of the most common causes of sudden, catastrophic account loss. A hijacked admin account can add malicious partners, redirect spend, or lock out the legitimate team in minutes.
2FA is necessary but not sufficient
Every admin and advertiser-level user on your Business Portfolio should have two-factor authentication enabled, full stop — this should be enforced as policy, not left to individual preference. But SMS-based 2FA is the weakest form, vulnerable to SIM-swap attacks; an authenticator app (Google Authenticator, Authy) or a hardware security key is meaningfully more secure and worth standardizing on for anyone with meaningful account access.
2FA protects against unauthorized login, but it doesn't protect against a legitimate, already-logged-in session being compromised through malware or a phishing link that steals session cookies rather than credentials.
The phishing vector specific to ad accounts
Ad account credential phishing has its own recognizable pattern: fake 'policy violation' or 'account restricted' emails and messages directing you to click a link and log in to 'resolve' the issue. These messages often look identical to genuine Meta notifications and create urgency deliberately.
Train every team member to never click a login link from an email or message claiming to be from Meta — always navigate to Business Manager or Ads Manager directly through a bookmark or by typing the URL, and check any account restriction claim from within the platform itself, not from an emailed link.
- Enforce 2FA via authenticator app or hardware key for all admins and advertisers
- Never log in through a link from an email or message — navigate directly
- Treat urgent 'account restricted, click here' messages as phishing by default
- Review active sessions and connected apps periodically
Device and session hygiene
Periodically review active sessions on the Facebook accounts of anyone with admin access, and remove any device or location that isn't recognized. Also review connected third-party apps with access to the Facebook or Business account — over-permissioned apps from years ago are a common, forgotten attack surface.
For agencies managing many client relationships, standardize on password managers with strong, unique passwords per account rather than reused or weak passwords — credential reuse across services is still one of the most common root causes of account compromise industry-wide.
What to do if you suspect compromise
Act immediately: change the password, review and revoke unfamiliar active sessions, check the people and partner list on every Business Portfolio the compromised account had access to, and remove anything unrecognized. Check Account Quality and billing for unauthorized changes — new payment methods, new admins, altered spending limits.
Report the compromise to Meta through the platform's account security reporting flow as soon as it's identified, since faster reporting generally means faster recovery and less exposure.
Security as an agency responsibility
When you're operating agency-provisioned ad accounts, security hygiene on your side of the relationship still matters — a compromised admin account in your Business Portfolio can affect shared assets regardless of who provisioned them. Power Ads' support team can help identify and respond to suspicious activity on shared accounts quickly, but the first line of defense is always the security discipline of your own team.
Key takeaways
- Enforce authenticator-app or hardware-key 2FA for every admin and advertiser account
- Treat any emailed 'account restricted, click here' message as phishing by default
- Review active sessions and connected third-party apps periodically
- Have a clear, fast response plan for suspected compromise
FAQ
Is SMS-based 2FA good enough?
It's better than nothing, but authenticator apps or hardware keys are meaningfully more secure and worth standardizing on for anyone with real account access.
What's the first thing to do if an admin account is compromised?
Change the password immediately, revoke unfamiliar active sessions, and check every Business Portfolio that account had access to for unauthorized changes to people, partners, or billing.
