A suspicious post can come from a compromised personal Facebook account, an overprivileged collaborator, a connected tool or a business-portfolio assignment. Deleting the post immediately may hide evidence while the same access remains active. Meta's Page access model provides several management paths; use it to find the path that made the post possible. If the personal account was hacked, Meta directs users to its hacked-account flow.
Before you start
Capture the post URL, text, attached link, publication time and any visible comments before removal. If it promotes a scam, warn followers through an established channel after confirming your own account is secure. Do not click its link to investigate on an administrator device. Coordinate with other authorized managers so nobody unknowingly reverses another person's containment step.Do it step by step
- Check whether a legitimate colleague scheduled the post or a cross-posting tool published it. Compare the time with scheduled content and campaign records. An unfamiliar post is an incident signal, not automatic proof that Meta itself was breached.
- Inspect Page access for unknown full-control, partial-control and task-access accounts. If your personal account shows unauthorized sign-ins, start facebook.com/hacked from a previously used device as Meta advises, change credentials and review sessions.
- Review business-portfolio people, partners and connected apps if the Page uses them. Remove or suspend only unauthorized access, preserving a trusted owner. Inspect linked Instagram and ad accounts because a compromised manager may have changed them too.
- After evidence is saved and access is contained, remove the fraudulent post and any malicious action button or Page link. Tell followers which message was unauthorized and where the genuine Page will provide updates.
- Review recent Page posts, inbox replies, comments, ads, billing and settings for other changes. A malicious actor may use the Page's credibility to send private scams without posting publicly.
- Strengthen all manager accounts with unique passwords and two-factor authentication, reduce unnecessary full-control roles and set a regular Page-access review. Record what happened and which accounts or tools were changed.