Recover your Facebook account
Facebook recovery starts with the type of problem you can actually see. A forgotten password belongs in account lookup. An email address changed by someone else belongs in the hacked-account flow. A suspension notice needs the review route attached to that decision. Repeating password resets across all three situations usually adds confusion.
These routes are for your own Facebook account. If the mailbox receiving Facebook codes is the part you cannot open, recover it first; the Apple and Google account guide covers those providers. Keep a familiar phone or browser available, even if you also try another device to read instructions.
1. Locate the account with Facebook's own lookup
Open Facebook's Find Your Account page. The current page asks for the mobile number or email address associated with the account. Use a contact detail you actually attached to Facebook. An address used only to message a friend will not necessarily identify your profile.
Check the account shown before continuing. Similar names, old profiles, and shared household contact details can make this step easy to rush. If you do not recognize the profile, stop and reconsider the identifier rather than requesting a code for an account that is not yours.
Choose an available recovery destination when the flow offers one. Read the masked address or number closely. If you have lost that mailbox, the email provider's recovery process may be your next practical step. Do not ask the current holder of a reassigned number to forward a security code; choose another official option instead.
2. Use the compromised-account route for unwanted changes
Facebook's hacked-account page is the correct starting point when someone may have accessed your account. Facebook recommends using a device you have used to log in before. A familiar browser gives the service context that an entirely new device may lack.
Follow the questions that match what happened: a changed password, unfamiliar activity, or account details you no longer recognize. Keep your description factual. The exact options can depend on the account and the evidence Facebook has available, so a screenshot in a third-party tutorial is not a guarantee that you will receive the same button.
If you still have an active session, avoid signing out of every device before looking at the security options it offers. An open session is useful for checking account details, although it does not guarantee permission to make every sensitive change. Facebook can still require another identity check before accepting new contact information.
3. Read a disabled or suspended notice as a separate case
Sign in through Facebook itself and read the displayed decision. Follow an appeal or review option if one appears, including the deadline and evidence request shown for your account. The official account lookup helps you reach the right identity; it is not a promise that changing the password will reverse a policy decision.
There is no universal appeal outcome or single sequence that applies to every restriction. Do not send identity documents to someone who contacts you in comments claiming to work on appeals. If Facebook asks for proof within its own recovery experience, review that request there and supply only what the official process requires.
A public name, photograph, or friend list can identify an account without authorizing a reset. If Facebook offers no usable verification route and you cannot recover a linked contact method, access may remain unavailable. Paying a stranger does not change that boundary.
If a recovery message looks suspicious
For an email claiming that a new device signed in, login.com's new-device email assessment guide explains how to compare the alert with activity you check directly. A login alert describes a different event from a password-reset request.
Open Facebook directly instead of signing in through an unexpected message. Compare the account activity and prompts you see there with the claim in the message. A threat, an urgent countdown, or an offer to unlock the profile for a fee should not decide where you enter your password.
If you want help examining a link before opening it, login.com's link-safety checker provides an additional check. It cannot authenticate a sender or guarantee that a site is safe. Do not paste a private reset link containing a one-time token into a public message or share it with a supposed recovery agent.
After you regain access
Review the email addresses and phone numbers on the account, then check available security and session controls. Remove unfamiliar access through Facebook's own settings and secure the mailbox that can reset the account. If you reused the old password elsewhere, update those accounts separately.
Tell friends through a trusted channel if the account sent misleading messages while compromised. Save the new recovery information privately and set up a second method that you can reach without the same phone. A recovery route is most useful when you test and understand it before another lockout.
Instructions checked against vendor guidance on 24 September 2026.