Blog / Article
Article

Loading article…

Found this useful? Share it.

Keep reading

More on this.

Rather we just did it for you?

Let's get your business seen.

Social media, websites, SEO and ads from a team you can actually meet.

The best way to keep your social media secure is to protect the logins behind your business accounts: turn on two factor authentication or passkeys for every person with access, give people access through the platform’s business tools rather than sharing a password, and never act on a message claiming your page is about to be deleted. Those three habits stop most account takeovers we hear about.

This guide covers social media security for business in practical steps, from password managers to who should have admin rights, how to spot fake support messages, and the official recovery routes for Facebook, Instagram, LinkedIn, TikTok and X if the worst happens.

Your business pages are only as safe as the people behind them

On most platforms, a business page is not a separate login. It is controlled through the personal accounts of the people who manage it. If one of those personal accounts is taken over, the attacker can often reach your page, your ad account and the card saved against it.

That is why social media security starts with a quick audit:

  • List every platform your business uses, including old accounts you no longer post on.
  • Note who has access to each one and at what level.
  • Check which email address and phone number each account is registered to. Use a business address you control, not a former employee’s personal email.
  • Remove anyone who no longer needs access, such as past staff, freelancers or a previous agency.

Turn on two factor authentication and passkeys

Two factor authentication (2FA) means that logging in needs something extra as well as your password, usually a code from an app on your phone. Even if your password leaks, an attacker cannot get in without that second step.

The options, from strongest to weakest:

  1. Passkeys or security keys. A passkey lets you sign in with your fingerprint, face or phone PIN instead of a password. It is tied to your device and the real website, so it cannot be phished. Facebook, Messenger and Instagram now support passkeys, as do Google accounts and many other services.
  2. Authenticator apps. Apps such as Google Authenticator, Microsoft Authenticator or the one built into your password manager generate a fresh code every 30 seconds.
  3. Text message codes. Better than nothing, but vulnerable to SIM swap fraud, where criminals move your number to their own SIM. On X, text message 2FA is now only available to Premium subscribers, so use an authenticator app or security key there.

Save the backup or recovery codes each platform gives you when you turn on 2FA, and store them somewhere safe, such as your password manager. They are often the fastest way back in if you lose your phone.

Related reading: Why Social Media Needs Secure Connection Practices

Use a password manager, not a shared spreadsheet

A password manager creates and stores a long, unique password for every account, so one leaked password cannot open everything else. Business plans let you share specific logins with specific people and remove access instantly when someone leaves.

  • Use a different password for every social account and the email address behind it.
  • Protect the password manager itself with a strong master password and 2FA.
  • Secure the email accounts linked to your social profiles just as carefully. Whoever controls the email can usually reset the social account.
  • Stop sharing logins over WhatsApp, email or a document on the shared drive.

Give access through business tools and the right roles

Every major platform has a way to give people access to a business account without handing over a password. Use it, and give each person the lowest level of access they need.

Meta (Facebook and Instagram)

Manage your Facebook Page, Instagram account and ad accounts through a business portfolio in Meta Business Suite. In its settings you can give people full control or partial access to specific assets, and you can require everyone in the portfolio to use two factor authentication. Keep at least two trusted people with full control, so you are not locked out if one account is compromised.

LinkedIn

LinkedIn Pages have admin roles such as super admin, content admin and analyst, plus separate roles for running ads. Keep super admin to a small number of senior people.

TikTok

Use TikTok Business Center to manage business accounts and ad accounts, and add team members with an appropriate role rather than sharing the app login.

YouTube and Google

Add people to your channel through YouTube Studio’s permissions settings rather than giving them the Google account password, and choose the most limited role that lets them do their job.

Review all of these every quarter. When we manage clients’ social media, we always ask for partner or role based access rather than passwords, and we recommend you hold the same standard with anyone else who works on your accounts.

Spot phishing and fake support messages

Most business account takeovers start with a convincing message rather than a clever hack. Common versions include:

  • A message or email saying your page has broken copyright or community rules and will be deleted within 24 hours unless you “appeal” through a link.
  • Fake offers of a verified badge or a brand partnership that ask you to log in.
  • Messages from pages with names like “Meta Support” or “Page Policy Team” and an official looking logo.
  • Requests for a 2FA code, often from what looks like a friend’s account that has already been hacked.

Simple rules for your team:

  • Never log in through a link in a message. Open the app or type the website address yourself.
  • Check any warning in the platform itself. On Facebook and Instagram, real notices appear in the app’s account status and support areas, not only in a direct message.
  • Never share a login code with anyone, for any reason. No real platform will ask for it.
  • Be wary of urgency. Pressure to act within hours is a classic sign of a scam.

What to do if your account is hacked

Act quickly, and use only the official routes below. Be wary of anyone on social media offering to recover your account for a fee, as many of these offers are scams themselves.

First steps

  1. Try to log in and change the password straight away, then sign out of all other sessions and turn on 2FA if it was off.
  2. Check the email address and phone number on the account have not been changed. Many platforms email the original address with a link to reverse the change.
  3. Secure the email account linked to the social account.
  4. Check your ad accounts for unexpected campaigns and contact your bank if a card is saved.
  5. Remove unknown people from page roles and business portfolios, and revoke third party apps you do not recognise.

Official recovery routes

  • Facebook: go to facebook.com/hacked, or use the support options in the Facebook app. Meta has added a central support hub in the Facebook and Instagram apps, with options such as a video selfie to confirm your identity.
  • Instagram: go to instagram.com/hacked, or follow the help steps from the login screen in the app.
  • LinkedIn: use the “Report a compromised account” route in the LinkedIn Help Center.
  • TikTok: follow the hacked account steps in TikTok Support, or use Report a problem in the app.
  • X: if a password reset does not work, submit the hacked or compromised account form in the X Help Center.

Tell your customers through your other channels that the account was compromised, so they ignore any odd messages or offers. If money was taken or you were defrauded, report it. In England, Wales and Northern Ireland, Report Fraud replaced Action Fraud in December 2025, at reportfraud.police.uk. In Scotland, report it to Police Scotland on 101.

Frequently asked questions

What is the most important social media security step?

Turning on two factor authentication, ideally with passkeys or an authenticator app, for every person who can access your business accounts.

Should I share my social media password with my agency?

No. Give your agency access through the platform’s business tools, such as a Meta business portfolio or LinkedIn Page admin roles. You keep control and can remove access at any time.

How do I know if a message from Meta is real?

Check inside the Facebook or Instagram app for account status warnings. If the notice is not there, treat the message as a scam and do not click any links.

Can a hacked business page be recovered?

Often, yes, especially if you act fast and another admin still has access. Having two trusted admins with 2FA makes recovery far easier.

Get help keeping your accounts safe

Our team manages social media for businesses across the UK, with secure, role based access and sensible admin set up as standard. See our social media management service, or get in touch if you would like us to review who has access to your accounts.