Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To make your Facebook account harder to take over, use a unique password, enable two-factor authentication, monitor login alerts and active sessions, watch for phishing, and prepare recovery options before you need them. These steps reduce common ways an attacker can get in, but no setting guarantees an account cannot be compromised.

1. Use a strong, unique password

Choose a password you do not use anywhere else. Reusing the same password for Facebook, email, banking, or another website means a password stolen from one service could put the others at risk.

If you have reused your Facebook password, replace it with a new one that is unique to Facebook. Keep it somewhere secure so you do not have to reuse an easier-to-remember password.

2. Enable two-factor authentication

Two-factor authentication (2FA) asks for another verification step in addition to your password when you log in. Facebook says it offers login alerts and 2FA as extra account protections; the exact options available can vary by account and device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Where supported, an authenticator app or a FIDO2/U2F security key is preferable to SMS because SMS is less resistant to phishing. If those options are unavailable or impractical, SMS can still add a layer beyond a password alone. Review the options Facebook presents in your security settings and choose one you can reliably access.

3. Turn on login alerts and review active sessions

Login alerts can notify you about logins Facebook considers unfamiliar. Enable them in the account’s security settings, then periodically check where you are logged in. In Facebook’s settings or Accounts Center, review the listed devices and locations and log out of sessions you do not recognize.

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A location or device description may not be exact—for example, network routing can affect a location estimate—so consider the context before deciding a session is unauthorized. If a login is unfamiliar, end that session and change your password to a unique one.

4. Treat unexpected messages and links as possible phishing

Phishing attempts try to trick you into giving away login details, often through a message that appears urgent or official. Malicious attachments or software can also expose account information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Do not enter your Facebook password after opening an unexpected link. Instead, open Facebook directly in your browser or app and check your account there.
  • Check the destination carefully before signing in; a familiar-looking message is not proof that a link leads to Facebook.
  • Avoid suspicious attachments and downloads, especially when a message pressures you to act immediately.

Facebook’s Account Security guidance includes information about protecting against phishing.

5. Prepare recovery options before an incident

Save Facebook’s one-time recovery codes

After you enable 2FA, Facebook can provide 10 recovery codes. Each code works once. Store them somewhere secure and separate from the device you normally use to log in; you can print or write them down. If the codes are lost or used up, Facebook says they can be regenerated.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Consider a compatible security key

Facebook requires you to obtain your own third-party Universal 2nd Factor (U2F) or FIDO2 security key to use that method. Key connections include USB, Lightning, Bluetooth, and NFC, but not every combination works with every browser or device. Check compatibility with your phone, computer, and browser before choosing a key.

Facebook’s pages explain how to set up login recovery codes and how to add a security key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If your Facebook account was hacked

Use Facebook’s recovery flow at facebook.com/hacked on a device you have used to log in to Facebook before. If Facebook imposes a 24-hour wait after a security check, it describes that delay as an extra precaution to protect the account and its information.

Once you regain access, set a unique password, review and end unfamiliar sessions, and check that your 2FA and recovery options are still under your control.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.