Hacked FB account despite 2FA and Authenticator
Ckezadri
Posted messages
6
Registration date
Status
Member
Last intervention
-
fabul Posted messages 42305 Registration date Status Moderator Last intervention -
fabul Posted messages 42305 Registration date Status Moderator Last intervention -
Hello everyone,
I’m seeking your opinions because I’m facing a very persistent hacking issue on my personal Facebook account and on my business pages.
1. The problem: Crypto scam messages and posts (promising fake USDT bonuses via a fake casino site with a link) are being sent automatically from my profile and my pages. The bot immediately deletes/archives conversations in Messenger after sending.
2. Measures already applied (which have NOT stopped the sends):
- Password: Reset multiple times.
- Two-factor authentication (2FA): Enabled and functional.
- Sessions: Forced global logout of all devices performed.
- Apps & Websites: No third-party access or active applications.
- Meta Business Suite: I am the only profile listed under People, no suspect Partner or third-party company attached.
- Meta Account Center: No external account linked.
3. Clue from recent connections:
Examining the active sessions, a suspect line appears:
- Device: Unknown device type (Macintosh / Chrome)
- IP: Orange France range (2a01:cb19:...)
- Identifier: Active Cookie Token (-1dS...)
My questions:
1) How can the attacker continue to publish when the password is reset, 2FA is active, and sessions are cut?
2) Do you favor the theory of an Infostealer (real-time session cookie theft on the machine) or a persistent API access token (Page Access Token / system user) hidden in Meta?
3) What audit tools do you recommend to definitively cut off this access?
Thanks for your feedback!
I’m seeking your opinions because I’m facing a very persistent hacking issue on my personal Facebook account and on my business pages.
1. The problem: Crypto scam messages and posts (promising fake USDT bonuses via a fake casino site with a link) are being sent automatically from my profile and my pages. The bot immediately deletes/archives conversations in Messenger after sending.
2. Measures already applied (which have NOT stopped the sends):
- Password: Reset multiple times.
- Two-factor authentication (2FA): Enabled and functional.
- Sessions: Forced global logout of all devices performed.
- Apps & Websites: No third-party access or active applications.
- Meta Business Suite: I am the only profile listed under People, no suspect Partner or third-party company attached.
- Meta Account Center: No external account linked.
3. Clue from recent connections:
Examining the active sessions, a suspect line appears:
- Device: Unknown device type (Macintosh / Chrome)
- IP: Orange France range (2a01:cb19:...)
- Identifier: Active Cookie Token (-1dS...)
My questions:
1) How can the attacker continue to publish when the password is reset, 2FA is active, and sessions are cut?
2) Do you favor the theory of an Infostealer (real-time session cookie theft on the machine) or a persistent API access token (Page Access Token / system user) hidden in Meta?
3) What audit tools do you recommend to definitively cut off this access?
Thanks for your feedback!