Beware of scams on your business’s Facebook account
Fraudsters could hack into your business’s Facebook account and use your money to advertise their products online.


Running targeted ad campaigns on Facebook can be a great way to drive customers to your business. But while the social media giant’s enormous reach means it has become an important part of many business’s customer recruitment strategies, Facebook also attracts unsavoury users. A growing number of businesses have had their ad accounts hacked, and found themselves with a whacking bill run up by their attackers.
The story is depressingly familiar. Businesses that have set up legitimate advertising campaigns on Facebook – the cost of which depends on the number of views each advert gets – suddenly notice a jump in what they are being charged. Sometimes, the bill goes over the maximum spending limit they have set on their accounts; it may run into tens of thousands of pounds.
The explanation is that their account has been hacked. Fraudsters are using the business’s account to run ads of their own. They may also have access to the business’s settings, enabling them to change spending limits and other controls. This can also make it difficult to put a stop to the fraud, even after the business has spotted the problem.
Subscribe to MoneyWeek
Subscribe to MoneyWeek today and get your first six magazine issues absolutely FREE

Sign up to Money Morning
Don't miss the latest investment and personal finances news, market analysis, plus money-saving tips with our free twice-daily newsletter
Don't miss the latest investment and personal finances news, market analysis, plus money-saving tips with our free twice-daily newsletter
A costly problem
Facebook won’t say how frequently this happens, but the number of small businesses reporting problems appears to be growing. And while the social media giant doesn’t necessarily demand payment when ad spending is run up by fraudsters, it won’t guarantee all losses are refunded. Besides, the true cost of fraud for a business dependent on its Facebook advertising activities may go way beyond the bill run up by the fraudster. It may be impossible to continue running genuine campaigns while trying to fix the issue.
As with most online fraud, there is no single vulnerability that enables fraudsters to attack Facebook ad accounts. Your business could be targeted in many different ways. Certainly, phishing attempts remain rampant – where fraudsters send out emails purporting to be from Facebook in order to send you to a fake website aimed at stealing your login credentials. If you use the same login details for multiple sites, the problem may also lie with a breach of security elsewhere.
However fraudsters are also becoming more creative. One common scam sees fraudsters posing as customers so they can send over documents to make an order. The document includes malware that installs on your computer and compromises your security.
The more people in the business with access to the ad account, the greater the risk of a compromise. Each user with admin rights to the account becomes a potential target for fraudsters. It therefore makes sense only to grant such rights to those who genuinely need them – and to delete privileges as soon as they are no longer required.
Facebook says some basic cyber-hygiene will offer a good level of protection. It urges ad account users to set up two-factor authentication. This requires users to provide both a unique code and a password to log into the account, and sends out an alert each time someone tries to log in from an unrecognised device. Small business owners can also enable “login request”, asking them to approve or deny request for access following these alerts.
Facebook also advises businesses to keep the phone number and email address linked to their device updated. This can allow customers to recover their account more quickly. It is possible to report questionable content and accounts by tapping the three dots above posts, or by reporting an account directly from its profile.
In addition, Facebook says it never sends small businesses direct messages; instead, it uses email. Therefore businesses should never respond to a message sent by an account claiming to be Facebook – it is likely to be a scam.
Securing your Facebook account
However, despite taking careful precautions businesses do run into problems. One difficulty is that getting support from Facebook can be difficult. The company is heavily dependent on user guides and help pages on its websites, and so finding a way to speak to someone at Facebook either by email or on the phone is not straightforward.
Some simple steps will help. If you know which admin account is being used to compromise your business, you can remove its access privileges via your settings pages. You can also use these pages to secure your account, even if passwords have been changed. Facebook’s Help services also give you a means through which to report a problem and to request support. This may be necessary to avoid being stung for charges or to get a refund if you’ve already paid out for ads that weren’t yours.
Get the latest financial news, insights and expert analysis from our award-winning MoneyWeek team, to help you understand what really matters when it comes to your finances.

David Prosser is a regular MoneyWeek columnist, writing on small business and entrepreneurship, as well as pensions and other forms of tax-efficient savings and investments. David has been a financial journalist for almost 30 years, specialising initially in personal finance, and then in broader business coverage. He has worked for national newspaper groups including The Financial Times, The Guardian and Observer, Express Newspapers and, most recently, The Independent, where he served for more than three years as business editor.
-
Could the AI megacap bubble burst?
The business cycle could be moving into territory where megacaps have historically lagged. Could this prompt the bursting of the AI megacap bubble?
-
Top 10 areas with the biggest inheritance tax bills – is your town on the list?
People in some of the wealthiest parts of London pay the most inheritance tax – but there are a few areas outside the capital where big bills are paid when a loved one dies
-
UK wages grow at a record pace
The latest UK wages data will add pressure on the BoE to push interest rates even higher.
-
Trapped in a time of zombie government
It’s not just companies that are eking out an existence, says Max King. The state is in the twilight zone too.
-
America is in deep denial over debt
The downgrade in America’s credit rating was much criticised by the US government, says Alex Rankine. But was it a long time coming?
-
UK economy avoids stagnation with surprise growth
Gross domestic product increased by 0.2% in the second quarter and by 0.5% in June
-
Bank of England raises interest rates to 5.25%
The Bank has hiked rates from 5% to 5.25%, marking the 14th increase in a row. We explain what it means for savers and homeowners - and whether more rate rises are on the horizon
-
UK inflation remains at 8.7% ‒ what it means for your money
Inflation was unmoved at 8.7% in the 12 months to May. What does this ‘sticky’ rate of inflation mean for your money?
-
Would a food price cap actually work?
Analysis The government is discussing plans to cap the prices of essentials. But could this intervention do more harm than good?
-
Is my pay keeping up with inflation?
Analysis High inflation means take home pay is being eroded in real terms. An online calculator reveals the pay rise you need to match the rising cost of living - and how much worse off you are without it.