Someone stole our client's Meta Business Manager account. What do we do in the first hour?
Contain first, recover second. In the first hour: pause every campaign to stop the spend, remove unfamiliar admins and end active sessions, treat the device that held the credentials as infected, and open Meta's documented compromised portfolio flow. A password reset from an infected machine achieves nothing, because the stealer captures the new one.
Why the clock matters more here than in a normal incident
Ad platform accounts are stolen for resale, not vandalism, which changes what the first hour is for. Mimecast logged 6.4 million detections of Meta Business Manager and Google Ads account theft across four years, roughly 1.86 million of them in the second half of 2025 alone, the highest volume of any period in its dataset (via Help Net Security, 29 July 2026).
The resale pricing explains the urgency. A stolen Meta Business Manager account sells for 15 to 340 dollars, a Google Ads account in a high-risk sector for 200 to 270, and aged accounts with real spend history carry a two to four times premium, because they clear platform filters a new account does not (same source).
So an agency is a target, not a bystander: it holds the asset that sells best, other people's aged, billing-enabled ad accounts. The asymmetry is the whole problem: an account with a 5,000 dollar monthly budget "can be drained in hours", while reclaiming ownership and rebuilding standing with the platform's review systems can take months (same source).
The first hour, in order
Order matters more than speed. Most teams start with the password, the one step that usually changes nothing.
- Name one person who owns the hour. Two people working the same incident in parallel revoke each other's sessions and lose the timeline.
- Stop the money before you chase the access. Pause every active campaign and, where you still can, the ad accounts themselves. Spend is the damage that accrues while you diagnose, and the only part you can halt in minutes.
- Remove the access you do not recognize, and end the sessions. Adding a new admin is how an attacker keeps the account after a password reset. Removing the unfamiliar user and ending active sessions is what closes the door.
- Treat the machine that held the credentials as infected. Mimecast attributes the bulk of this theft to four infostealer families: DuckTail, NodeStealer, VietCredCare and PXA Stealer (via Help Net Security, 29 July 2026). If a stealer is resident, a password changed on that device is captured as it is typed. Reset from a machine you know is clean.
- Recover the personal profile first, if that is what was taken. Business portfolio access hangs off individual profiles, so the portfolio cannot be fixed before the profile is. Meta's documented route is facebook.com/hacked, used from a device previously used to log in (Meta Help Center, consulted 22 September 2026).
- Open Meta's compromised business portfolio process. Meta documents a dedicated flow and tells affected businesses to contact Meta Support immediately (Meta Business Help Center, consulted 22 September 2026). File inside the hour: the queue starts when you file.
- Write the timeline as you go. What you saw, when, what you changed, on whose instruction. Nobody reconstructs this accurately later.
What Meta itself lists as signs of a compromised portfolio
Useful before you argue with a client about whether this is really a compromise. Meta documents four signals of a hacked or compromised business portfolio (Meta Business Help Center, consulted 22 September 2026):
- Unauthorized access changes. New users or admins added without approval, or unexpected permission changes.
- Unrecognized ad activity. New or reactivated ad accounts or campaigns that no authorized user created.
- Unexpected spend. Sudden or unexplained increases in ad spend, invoices or charges.
- Unrecognized organic content. Posts whose copy, creative or targeting is not typical of the business.
Notice what is not on that list: being locked out. Many compromises run quietly with the legitimate admins still logged in, because a spending account is worth more while it looks normal. The billing anomaly is often the first honest signal.
Three things not to do in that hour
Do not start the blame conversation. Whether it was a contractor's laptop, a shared login or a clicked phishing email is a question for day three. Inside the first hour it only slows down the people who need to act.
Do not delete the evidence. The instinct is to clear out the attacker's campaigns, posts and users. Screenshot first: user lists, permission changes, billing entries, the campaigns themselves. Once removed it disappears from your view, and it is what a platform appeal or an insurer will ask for.
Do not tell the client it is handled before you know the scope. Containment is not resolution. If the same credentials or infected device touched other clients, you have more than one incident. Say what is confirmed, what you are still checking, and when the next update lands.
Once access is back, the hardening Meta documents
Meta's own guidance starts with Security Checkup in the portfolio settings and the Security Center recommendations. The rest of its documented list (Meta Business Help Center, consulted 22 September 2026):
- Require two-factor authentication for every user in the portfolio, not only for admins.
- Review the email addresses of people with access and remove anyone whose address is not tied to the business.
- Close or remove ad accounts that have not run ads in the past year, to reduce the assets worth targeting.
- Review shared credit lines and remove any sharing you do not recognize.
- Scan and clean the personal devices of everyone who holds portfolio access.
For an agency the second and fifth bite hardest: agency work runs on freelancers using personal email addresses on personal laptops. Neither is a one-time cleanup, because the roster changes quarterly.
Why agencies keep ending up in this position
Verizon's Data Breach Investigations Report put third-party involvement in breaches at 30% in its 2025 edition and at 48% of all breaches in the 2026 edition (Verizon DBIR 2025, April 2025, and DBIR 2026, May 2026). The root causes it names: absent or misconfigured multi-factor authentication, and excessive permissions.
For an agency that is the arithmetic of the client roster: every client account you hold is a standing permission granted to people you do not employ full time, on devices you do not control, often left in place long after the work ended. That is not negligence, it is how the work is structured. The first hour goes very differently depending on whether an inventory of who holds what already exists.
Where this fits in the work
Want to know where your own environment stands? The first step is a free, read-only security assessment.
Get a free security assessment