Facebook logged in from an unknown device: What should you do to protect your account?
Facebook is showing a login from an unknown device, a session you do not recognize, or repeated login alerts even after you changed your password? Do not just change your password and assume the problem is solved.
A safer response is to review active sessions, change your password from a trusted device, secure your recovery email, enable stronger authentication, and inspect the computer or phone you are using.
In particular, if you have already changed your password, logged out other devices, and enabled 2FA but the issue returns a few days later, consider the possibility that your credentials or authenticated session data are still being stolen from the browser, an extension, or a malware-infected device.
Does a Facebook login from an unknown device mean your account has been hacked?
Not every unknown-device alert means that a hacker has successfully taken over your Facebook account.
If Facebook shows a message such as “Someone tried to log in, but we stopped them,” the platform may have detected and blocked a suspicious login attempt. However, the fact that someone may be trying your credentials is still a reason to review your account immediately.

The situation is more serious if you notice one or more of the following signs:
An active session from a device you do not recognize.
Your recovery email or phone number has been changed.
Posts, comments, or messages were sent without your knowledge.
An unknown administrator appears on your Facebook Page, ad account, or Business Account.
Your password was changed without your authorization.
Your linked Instagram account or email also shows suspicious activity.
You changed your password, but unknown devices continue to appear a few days later.
In the real-world user reviews shared for this article, one recurring scenario was that users had changed their password, logged out devices, and even enabled 2FA, but suspicious login alerts returned after one or several days.
Some users suspected stolen cookies, browser extensions, software installed on the device, or persistent sessions elsewhere. These are user experiences and assumptions, so they should not be treated as proof of the root cause in every case. However, cookie and session-token theft are real attack techniques that Meta has previously analyzed in technical reports.
7 steps to take when Facebook is logged in from an unknown device
1. Do not click links in warning emails or messages
One of the most dangerous mistakes is seeing a message such as “Your Facebook account will be disabled” and immediately clicking the attached link.
Instead, open the Facebook app directly or type Facebook’s address into your browser yourself and check notifications from inside your account.
Attackers often create a sense of urgency using messages such as:
Your account has violated copyright rules.
Your Page is about to be disabled.
Your verified badge will be removed.
You must verify your account within a few hours.
Someone attempted to log in and you must confirm immediately.
If you are unsure whether an email is legitimate, review the signs of phishing emails and common phishing risks before entering your password or authentication code on any website.
This risk is especially relevant to business accounts. IPSIP previously analyzed the AccountDumpling campaign targeting more than 30,000 Facebook accounts, in which attackers abused Google AppSheet, fake Facebook support pages, and multiple verification scenarios to collect login credentials. Some fake pages also requested 2FA codes.
This means that an email coming from a familiar service or a professionally designed website is not enough to prove that the message is legitimate.
2. Review logged-in devices and revoke suspicious sessions
Next, open Facebook or Meta’s security settings and review the list of devices, browsers, and active sessions.
If you find a device that you are certain is not yours, log that session out.
If there are signs that the account has actually been compromised, consider signing out of other unused sessions instead of removing only one suspicious device.
The goal is to prevent an old authenticated session from remaining active while you are changing your password.

3. Change your password from a trusted device
If you suspect that your current computer may be compromised, do not keep changing your Facebook password on that same device.
Instead, use another phone or computer that you trust to:
Change your Facebook password.
Create a completely new password.
Avoid reusing an old password.
Do not use the same password for Facebook, Gmail, Outlook, or other services.
If your old Facebook password is also used for email, social media, or other important accounts, change it on those services as well.
This point is critical. If an attacker controls the email account used to recover your Facebook account, changing only the Facebook password may not be enough.
4. Secure your email, phone number and linked Meta accounts
After Facebook, the next thing to check is your recovery email.
Review:
The email address linked to Facebook.
Recovery phone numbers.
Devices currently logged in to your email account.
Automatic email forwarding rules.
Newly added recovery methods.
Instagram or other linked Meta accounts.
In April 2026, Meta announced a transition from Accounts Center to Meta Account, allowing users to manage settings such as passwords, email addresses, two-factor authentication, and connected Meta apps in one place. The transition is being rolled out gradually, so menu names and locations may vary between accounts.
If Facebook and Instagram are connected within the same ecosystem, do not review Facebook alone.
5. Enable 2FA and consider using a Passkey
If two-factor authentication is not already enabled, activate it once you regain control of the account.
2FA adds another layer of protection if your password is exposed.
Meta has also introduced passkeys on Facebook. Passkeys allow users to authenticate with fingerprints, facial recognition, or a device unlock code instead of relying entirely on a traditional password. Meta states that passkeys are more resistant to phishing and password-spraying attacks than conventional passwords or SMS-based one-time codes.
You can also learn more about what passkeys are and why they are gradually replacing traditional passwords.
However, one important point should be clear: enabling 2FA does not mean your account is completely safe if your device is infected with malware.
6. Check browser extensions, software and the device itself
This step is especially important if you belong to the group of users who say, “I already changed my password, but the problem came back a few days later.”
Check for:
Browser extensions from unknown sources.
Extensions installed shortly before the incident started.
Cracked or pirated software.
Installers downloaded from unofficial websites.
Suspicious EXE, ZIP, PDF, or tool files received through chat.
Unknown remote-access software.
Outdated browsers or operating systems.
Then update your operating system and browser and run a reputable security tool.
If you are unfamiliar with how malware can infect and persist on a device, see IPSIP’s guide to malware types and ways to prevent malicious software.
If Facebook, Gmail, Instagram, and several other accounts all show suspicious logins on the same computer, the likelihood of a device-level compromise should be taken more seriously.
7. If you lose access, use Meta’s official recovery process
If an attacker has changed your password or email address and you can no longer sign in, use Facebook’s official account recovery process.
Meta said it improved its account recovery processes during 2025–2026, including better recognition of trusted devices, adaptive verification flows, and, in some cases, identity verification using video selfies. Meta also recommends tools such as Security Checkup, 2FA, and passkeys to strengthen account protection.
Avoid third-party “Facebook account recovery” services that ask for:
Your password.
OTP codes.
2FA codes.
Browser cookies.
Session data.
Recovery codes.
Sharing this information can turn a minor incident into a complete account takeover.
Why is Facebook still being accessed after you change the Password and enable 2FA?
This is one of the most important questions raised in the user reviews.
Many users said they had changed their password, enabled two-step verification, and logged out devices, only to see suspicious activity return a few days later.
At least three scenarios should be considered.
Scenario 1: The attacker is still trying the Password, but 2FA is blocking them
If someone has your password but does not have the second authentication factor, Facebook may block the login attempt and send you an alert.
In this situation, receiving another warning does not necessarily mean the attacker successfully entered your account.
However, your password should still be changed because it may already be exposed.
Scenario 2: You entered the new Password on a device that is still infected
This is one reason changing your password repeatedly may not solve the problem.
Meta previously analyzed NodeStealer, a malware family targeting Windows browsers. NodeStealer can steal data from Chromium-based browsers, including session cookies and saved credentials for Facebook, Gmail, and Outlook. Meta noted that malware campaigns of this type may collect session tokens in an attempt to bypass two-factor authentication requirements.
In other words, if you create a very strong new password but then enter it on a device that is still compromised, the new credentials may also be stolen.
Scenario 3: Your authenticated session was stolen
A password and a session are not the same thing.
After a user signs in successfully, websites normally use session data to keep the user authenticated. If that session data is stolen in certain attack scenarios, an attacker may try to reuse the authenticated session instead of going through the full login flow again.
This is why users should not assume:
“I enabled 2FA, so my account can never be hijacked.”
2FA significantly reduces risk, but account security still depends on protecting your browser, device, and email.
Should you reinstall Windows if Facebook keeps showing unknown logins?
You do not need to reinstall Windows immediately after seeing one suspicious login alert.
First:
Change your password from a clean device.
Revoke suspicious sessions.
Secure your email account.
Enable 2FA or a passkey.
Remove suspicious browser extensions.
Scan for malware.
Update Windows and your browser.
Reinstalling the operating system becomes more reasonable if the issue continues after these steps or if additional signs appear, such as:
Multiple accounts being compromised.
Unknown software appearing on the device.
Browser extensions reinstalling themselves.
Security tools repeatedly detecting malware.
Remote-control software appearing that you did not install.
Newly changed passwords continuing to leak.
You cannot identify or remove the root cause from the device.
If you reinstall the system, be careful when restoring data. Installing a fresh copy of Windows and then reinstalling the same cracked software, suspicious extension, or infected file can bring the problem back.
Why should a compromised Facebook account be treated quickly?
A stolen Facebook account does not only result in lost access.
It can be used to:
Impersonate the account owner.
Ask friends or family for money.
Run unauthorized ads.
Scam a company’s customers.
Take over Facebook Pages.
Spread more phishing links.
Be sold on underground account markets.
A recent case in Vietnam shows that this risk is not theoretical.
On July 16, 2026, Vietnam’s Ministry of Public Security reported that Bắc Ninh Provincial Police had dismantled a group involved in stealing Facebook accounts for resale. Authorities said that between July 4 and July 10, 2026 alone, the group had taken control of 64 Facebook accounts.
Earlier, on January 29, 2026, Bắc Ninh Provincial Police announced another case involving a group that took over Facebook and Zalo accounts and then impersonated the owners to ask their friends and relatives for money. Authorities estimated the stolen amount at approximately VND 50 billion.
These cases show how a compromised social media account can become one part of a broader fraud operation.
How should businesses respond if a Facebook Business Account is accessed from an unknown device?

If the affected account is only a personal profile, the response can focus primarily on Facebook, email, and the user’s device.
However, if the account has administrative access to:
A Facebook Page.
A business Instagram account.
Meta Business.
Ad accounts.
Payment methods.
Customer-support channels.
the incident should be treated as a potential business security issue.
In addition to changing passwords, businesses should review:
Who currently has Page administrator access.
Whether any permissions were recently added or changed.
Whether unauthorized advertising campaigns have appeared.
Whether new payment methods have been added.
Whether the corporate email account was accessed.
Whether the administrator’s computer shows signs of compromise.
Whether other business accounts reuse the same password.
If the incident extends beyond Facebook and shows signs of affecting endpoints, corporate email, privileged accounts, or multiple systems, the company should move to a formal cybersecurity incident response process to isolate affected devices, determine the scope of compromise, and identify the root cause.
Quick checklist when Facebook shows an unknown device
If you need to respond immediately, follow this order:
Do not click links in suspicious emails or messages.
Open Facebook directly to verify the alert.
Review the list of logged-in devices.
Sign out sessions you do not recognize.
Change your password from a trusted device.
Review and secure your recovery email.
Remove unknown email addresses or phone numbers from the account.
Enable 2FA and consider using a passkey.
Check browser extensions and recently installed software.
Scan for malware and update your device.
Review linked Instagram, Page, and ad accounts.
If you lose access, use only Meta’s official recovery process.
Conclusion
When Facebook is logged in from an unknown device, changing the password is necessary, but it is not the entire solution.
A proper response should cover active sessions, passwords, recovery email, 2FA or passkeys, the browser, and the device itself.
Most importantly, if you change the password and sign out other devices but suspicious logins return after one or several days, do not simply repeat the password reset. Ask a more important question:
Where are the new credentials or authenticated sessions continuing to leak from?
If several accounts are affected at the same time, or if the Facebook account has administrative access to business systems, Pages, or ad accounts, the incident should be handled as a broader device and cybersecurity incident rather than only a Facebook account issue.
------------------
References
Meta Engineering – The malware threat landscape: NodeStealer, DuckTail, and more: Meta Engineering
Meta – Meta Account: The Simpler Way to Access Your Apps and Devices: Meta Newsroom
Meta – Making it Easier to Access Account Support on Facebook and Instagram: Meta Newsroom
Meta – Introducing Passkeys on Facebook for an Easier Sign-In: Meta Newsroom
Bộ Công an – Triệt phá ổ nhóm chiếm đoạt tài khoản Facebook để bán thu lợi: Cổng thông tin Bộ Công an
Bộ Công an – Bắc Ninh: Khởi tố nhóm chiếm đoạt quyền sử dụng tài khoản mạng xã hội để lừa đảo khoảng 50 tỷ đồng: Cổng thông tin Bộ Công an











Comments