How to keep your account from getting hacked
open allWhat for: So you don’t get hacked.
If you use a short and simple password for your Facebook account, cybercriminals can guess it and hijack your account. A long and complex password is more secure. Use a strong password that:
- Is at least 8 characters long;
- Contains lowercase and uppercase letters, numbers, and special characters ($, @, etc.);
- Is not an actual word or easy-to-guess phrase;
- Is not the same as your passwords for any other accounts, including your Google password;
- Does not consist of information that strangers could easily find out (your name, date of birth, pet's name, and so forth — or those of your friends or relatives).
To change your password:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Select Settings;
- Go to the Password and Security section;
- Tap Change password;
- Enter your current Facebook password;
- Enter a new strong password twice;
- Tap Update password.
What for: So you definitely don’t get hacked.
Facebook can be configured to request a one-time code when you log in to your account. That way, even if cybercriminals learn your username and password, they will not be able to use them. The code is sent by SMS to your specified phone number or generated by an app (for example, Google Authenticator).
To enable two-factor authentication:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Password and Security section;
- Tap Use two-factor authentication;
- Select a one-time code retrieval method:
- Authentication App;
- Text Message (SMS);
- Security Key.
Remember that a text message with the code can be intercepted by malware, which is why using a two-factor authentication app is a safer option. Facebook can also use the phone number you linked to your profile for targeted advertising.
With two-factor authentication, you can log in to your account even if you lose your phone. For that, you need the recovery codes. To get them:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Password and Security section;
- Tap Use two-factor authentication;
- Select Recovery codes;
- Tap Recovery codes.
Each of the ten codes can be used only once. Write them down or take a screenshot of them, and keep the information in a safe place.
What for: So nobody can log in to your account on your old phone.
By default, Facebook trusts any devices from which you previously logged in to the social network. When signing in on them, a one-time code is not requested. If your old phone ends up in the hands of strangers, they will be able to log in to your account bypassing two-factor authentication. To avoid this, include only devices that you currently use in the trusted list:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Password and Security section;
- Tap Authorized Logins;
- Remove the ones you don’t use from the list of trusted devices.
If necessary, you can still log in to Facebook from any device using two-factor authentication.
What for: To change your password promptly if you get hacked.
Facebook can notify you every time your username and password are entered in a new browser or on a new device. If someone else signs into your account, you will be notified immediately by e-mail or alert on a trusted device. In this way you can react promptly and change the password.
To enable suspicious activity alerts:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Password and Security section;
- Tap Get alerts about unrecognized logins;
- Specify how you prefer to receive suspicious activity alerts selecting one of the options:
- Notifications;
- Messenger;
- E-mail.
- Tap Save.
We recommend activating all three to receive alerts even if one of the channels is unavailable; for example, if you lose your phone or your e-mail is hacked.
How to protect yourself against malicious websites
open allWhen you tap a link in a post, the Web page opens in a browser integrated into the Facebook app. This page can be malicious or use an insecure connection. Enable the safe browsing feature to get a warning from the app before you open suspicious pages.
To enable safe browsing:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Password and Security section;
- Tap Safe Browsing to activate the feature.
How to keep corporations out of your business
open allWhat for: So Facebook does not know more than it needs to.
The Facebook app requests the contact list of your phone to help you locate the people you know on the social network. However, the information about your contacts is also used to create targeted ads and generate news feeds. Moreover, your information is shared with third parties, which increases the risk of a leak.
To prevent Facebook from using your contact list:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Upload Contacts section;
- Disable the Continuous Contacts Upload feature.
Downside: The social network will not prompt you to add your new acquaintances whose numbers you store as your new friends.
If such apps as Instagram, Messenger or WhatsApp, which are owned by Facebook, have access to the contact list, this information can still be used by the social network.
Keep in mind that you have to disable access to contacts on all your devices with contact lists.
You can check which contacts are already uploaded to your accounts and remove any unwanted information here:
What for: So Facebook does not know where you go.
The Facebook app can access information about your location. This information is used to geotag your posts and stories and configure targeted advertising suggestions. If you do not want to share your location with strangers and the social network, you can disable access to location data.
To disable geodata transfer:
- Open your phone’s Settings menu;
- Go to the Apps & Notifications section;
- Select App Permissions;
- Tap Location;
- Find Facebook in the list of apps;
- Tap Deny.
Bear in mind that the Facebook geodata log stores your locations harvested before access is disabled. You can turn off this feature and delete the collected data:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Access Your Information section;
- Tap Logged Information;
- Tap Location History. If necessary, enter your password.
- Tap the three-dot button in the upper right corner of the screen, and go to Location Settings;
- Disable Location History;
- Tap See Location History;
- Tap the three-dot button in the upper right corner of the screen.
- Select Delete all location history and confirm.
Downside: Facebook will not be able to alert your friends when you are nearby or show you nearby events. You won’t see location-based advertising, either.
If such apps as Instagram, Messenger, and WhatsApp, which are owned by Facebook, have access to location data, it can still be used by the social network.
What for: To stop Facebook from looking for you in every photo.
Facebook can locate you in photos and videos by using face recognition. To this end, the social network analyzes your photos and creates a search template.
When one of your Facebook friends uploads a photo of you, the social network may suggest tagging you. If the photo of you is uploaded without a tag, Facebook will prompt you to check and confirm whether you are in the photo. You will also get a notification if somebody pretends to be you and uses your photo as a profile image.
According to Facebook, its face recognition technology is intended for convenience and safety https://www.facebook.com/help/122175507864081 and cannot be abused. However, not all people like the idea of being watched.
To disable face recognition:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Face Recognition section;
- Tap Do you want Facebook to be able to recognize you in photo and videos?
- Check the box next to No.
Downside: Disabling the face recognition function does not mean that you will no longer be tagged in photos. It’s just that now, anyone wanting to tag you will have to do so manually. If you disable face recognition, Facebook will remove the template with your biometric data, and your friends will not receive notifications prompting them to tag you in photos. You will also stop receiving notifications whenever somebody posts your photo without tagging you, which means you will not be alerted right away if strangers use your photos as their own.
You can view the list of photos in which you are already tagged in the activity log.
What for: To prevent potential data leaks.
Many apps and websites allow users sign in with their Facebook account. That gives the owners of such third-party services access to your publicly available information and profile-linked e-mail address. Developers that have passed a review can request permission to create posts on your behalf or send you advertising messages.
In general, logging in through Facebook can be convenient: It eliminates the need to create and memorize logins and passwords for each service. However, after logging in to a website through Facebook, we may forget we did so. As a result, the account becomes linked over time to a long list of third-party resources.
Remember that services connected to your account can become a source of data leaks or post advertising messages on your behalf. Although Facebook clears the access list automatically, we recommend manually removing any unwanted services from this list from time to time.
To see which sites and apps have access to your profile and to revoke permissions:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Apps and Websites section;
- Select apps or websites that you do not trust and tap Remove;
- To remove all content that the app or website published on your page, select Delete all posts, videos or events posted on your timeline;
- Tap Done.
If you prefer not to log in through Facebook at all, you can disable this feature entirely:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Apps and Websites section;
- Tap Turn Off in the Apps, Websites and Games section and confirm.
What for: To keep Facebook from personalizing ads based on your actions on other websites and in other applications.
The social network’s partners share information about your actions on their websites and in their mobile applications with Facebook. In particular, if you purchase something through a service that you logged in to with your social network account or that has the social network’s analytics tools built into it, Facebook will learn that and will use information about your purchase for personalizing ads. For instance, if you have looked for a hotel in another town using a lodging search application, Facebook will show you ads for airlines that sell flights to that town. It is not just on the device that you used to search for a hotel but every other place where you are logged in.
The social network lets you find out which of your activities it follows and restrict the use of that information for ad personalization. This is a highly useful feature: it shows just how much the company knows about your online activity. Besides, you may want to keep your visits to some of the services that share information with Facebook private, e. g. from friends who can see your Timeline.
To prevent Facebook from using information about your online activity for personalizing ads and clear the activity log:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to Off-Facebook Activity;
- If you want to clear your activity log, tap Clear History and confirm;
- Tap the three dots in the upper right corner of the screen;
- Select Manage Future Activity;
- Tap Manage Future Activity;
- Toggle off the Future Off-Facebook Activity option and confirm.
Here, too, you can view and download your account data.
The new settings will take effect within two days. The amount of ads will remain unchanged, but they will no longer consider your activity outside of Facebook.
Bear in mind that although Facebook will stop using that information in selecting ads, the social network will continue to receive it from partners.
Downside: You will no longer be able to log in to websites and applications with your Facebook account.
If you have logged in to third-party service with your social network account before, you may be kicked out of your account with the service. You will lose access to the data in the service including accumulated discounts, game achievements, etc.
How to defeat spammers and trolls
open allWhat for: To remove irrelevant comments.
By default, all Facebook users can leave comments under your posts, an ability that spammers and trolls often abuse.
To make sure that only your friends can comment on your posts:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to Followers and Public Content;
- Under Public Post Comments, check the box next to Friends.
You can also block the app from showing comments containing certain keywords or hashtags on your timeline. In this way you can hide offensive comments or other unwanted content. This feature can be configured only in the settings of the Facebook Web version.
What for: To avoid unpleasant people.
If you want to stop a specific user from commenting on your posts, you can block that user. Blocked users will not be able to view your profile, leave comments under your posts, or send you private messages. In this case, the user will not know that you blocked them.
To block a user:
- Tap the menu icon in the lower right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Blocking section;
- Tap Add to blocked list;
- Type a name of user you want to block;
- Tap Block and confirm.
What for: Peace of mind.
Other Facebook users can tag you in their posts. By default, such posts appear in your timeline, and your friends get notified about them. But what if somebody tags you in an offensive or fraudulent post — or if
your friends tag other people in your posts? The point is, tagging isn’t always welcome.
You can limit other users’ ability to tag you in their posts as well as configure the app to request your confirmation every time you get tagged:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Profile and Tagging section;
- Tap Who can see posts you're tagged in on your profile? and select one of the options:
- Friends of friends;
- Friends;
- Friends except...;
- Specific friends;
- Only me.
- Tap Review tags people add to your posts before the tags appear on Facebook? and turn on the toggle switch;
- Tap Review posts you're tagged in before the post appears on your profile? and turn on the toggle switch.
- To completely stop other users from viewing tagged posts, tap Who can see posts you're tagged in? and select Only me.
Remember that posts in which you have been tagged will still be available in search results and other Facebook sections. To delete such a tag in somebody's post:
- Tap the menu icon in the upper right corner of the app;
- Select View your profile;
- Tap the button with three dots under your profile image;
- Select Activity Log;
- Tap Activity You’re Tagged In and select Posts and comments you’re tagged in;
- Tap the post you want to untag;
- Tap the three-dot button to the right of the post author's name;
- Tap Report/Remove Tag and select any reason for the report;
- Go back to Activity Log and select Photos you’re tagged in;
- Tap the post you want to untag;
- Tap the three-dot button to the right of the post;
- Tap Report/Remove Tag and select any reason for the report.
What for: To fend off bothersome users.
By default, all Facebook users can send you friend requests. Spammers and fraudsters sometimes abuse this feature. Having lots of requests from unknown people is bound to get on your nerves.
To limit the list of users who can send you friend requests:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the How People Find and Contact You section;
- Tap Who can send you friend requests? and select Friends of friends.
Downside: Your acquaintances will have a hard time locating your Facebook profile unless they are friends of your friends.
How to hide posts from unwanted people
open allWhat for: So your posts will be seen only by those for whom they are intended.
When you create a new post, you can choose who will see it on Facebook. By default, they are visible to all of your friends. That can be inconvenient if you would prefer not to share your private life with some of them.
You may already have changed this setting and made your posts publicly available. Remember that information from your posts can be used against you. For example, information about your personal life can help telephone fraudsters to make up a convincing story in order to steal money from your bank accounts.
You can choose the following access settings for your posts:
- Public — posts are visible to all Facebook users and visitors to your page who are not registered on the social network;
- Friends — posts are visible to friends only.
- Friends except… — posts are visible to all friends except those listed.
- Specific friends — posts are visible to friends on the list only.
- Only me — posts are visible to no one but you.
- Custom — posts are visible to Facebook users located in a specific place, for example, in your city. Facebook itself generates these lists and suggests them to you depending on your place of work or geolocation.
To configure the default visibility of your posts:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Privacy Settings section;
- Tap Check a few important settings;
- Select Who can see what you share;
- Specify which group of users shall see your posts by default.
Remember that you can still override the general settings and change the visibility of each post when publishing it or later.
A. To restrict the visibility of your post when you create it:
- Tap the button under your name;
- Choose the user group you want to see your post.
B. To configure the visibility of an existing post:
- Tap the three-dot button to the right of the post title;
- Select Edit Privacy;
- Choose the user group you want to see your post.
Earlier versions of the Facebook apps for some types of devices did not include a function for restricting the visibility of posts, but you can still customize their visibility.
To set the visibility of posts created in older versions of the app:
- Tap the menu icon in the lower right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Posts section;
- Tap Limit past posts and confirm.
Note that people you mention or tag in a post will see it even if you set the Only me option.
What for: So your stories are visible only to those for whom they are intended.
Other Facebook users can see your stories and share them with their friends, so your personal information might become available to outsiders, and details from stories could be exploited.
You can set the following levels of story visibility in Facebook:
- Public — any Facebook or Messenger user can view your stories;
- Friends — only your Facebook friends can view your stories;
- Custom — stories are visible to a custom list of Facebook users that may include both friends and users who do not follow you;
- Custom list — your stories are visible only to Facebook users on this list;
- Hide story from — your story is visible to all users except those listed.
To limit access to stories:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Stories section;
- Tap Story Privacy;
- Select a group of users who will be able to view your story.
- Tap Change;
- Go back to the Story Settings section and select Sharing Options;
- Tap Allow others to share your public stories to their own story? and select the check mark next to No.
- Tap Allow people to share your stories if you mention them? and select the check mark next to Don’t allow.
You can also configure visibility of specific stories.
To limit the visibility of a story when you post it:
- After choosing a photo or video for your story, tap Privacy in the lower left corner of the screen;
- Select a group of users who will be able to view your story.
To limit the visibility of a story already posted:
- Select your story at the top of your news feed;
- Select Edit Story Privacy;
- Tap Story Privacy;
- Select a group of users who will be able to view your story.
What for: To keep your posts from being shared beyond the intended audience.
Other Facebook users can add your posts to their stories. That means people other than your friends can see your posts. You can prevent other users from sharing your posts.
To prevent your posts being shared in stories:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Profile and Tagging section;
- Tap Allow others to share your posts to their stories? and check the box next to No.
Keep in mind that Facebook offers other ways to share your posts. For example, users can repost them or send your post in a direct message.
How to prevent your personal data from being exposed
open allWhat for: To protect yourself from spammers and other shady people.
Cybercriminals can use information from your profile to do all kinds of unpleasant things. For example, they can bombard your phone with spam calls or text messages. Also, contacts from your social network profile in combination with certain publicly available information about your life can be a treasure trove for bad actors who can try to defraud you financially. Detailed information about your job or interests helps them contrive persuasive stories.
By default, your phone number is visible to all of your friends. Friends of your friends can see your date of birth. Meanwhile, information about your city, place of study, and work is public.
To hide this information:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Profile information section;
- Set the visibility of each personal information item to Only me.
After configuration, you can see how your profile looks to other users:
- Tap the menu icon in the upper right corner of the app;
- Select See your profile;
- Tap the three dots button under your profile image;
- Tap the View As button.
Downside: Your friends may have trouble locating your Facebook profile or contacting you by phone.
By default, people, pages, and lists that you follow are visible to all users. Fraudsters can use information about your hobbies and interests to concoct more believable stories. And your employer probably doesn’t need to know that you are subscribed to ten job search groups.
You can make your subscriptions visible to all or some friends, or hide them from everyone but you:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Followers and Public Content section;
- Tap Who can see the people, pages and lists you follow? and select one of the options:
- Friends;
- Friends except...;
- Specific friends;
- Only me.
What for: To stop showing everybody when you are online.
Facebook shows your friends when you are, or last were, online. Your ex-partners or other interested people could monitor your status and spam you with their messages when you are online.
Also, if you friend people you don’t know personally, this information could be used by an intruder to choose the best time to hack your account. By observing your status over a period of several days, they will see when you are likely to be offline and unable to respond promptly to an attack.
To stop Facebook from showing your status:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Active Status section;
- Disable the Show when you're active feature;
- Select Turn off in the dialog that opens.
Downside: You will also be unable to see the status of your friends.
How to get rid of unwanted notifications
open allWhat for: To avoid distractions.
By default, Facebook shows you notifications about all social network activities, including game and app alerts and information about nearby hangouts. If some notifications distract you, disable or mute them.
To manage the notifications:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Notifications section;
- Select the listed notifications that you do not wish to receive and disable the Allow notifications on Facebook feature.
- Some types of notifications don’t have a single switch; turn off Push, Email, and SMS switches separately.
What for: To avoid distractions.
Other users can send you invitations from games, as well as other notifications from internal Facebook apps. If such messages annoy you, turn them off.
To disable notifications from games and apps:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Apps and Websites section;
- In the Games and app notifications section, select Turn Off and confirm.
How to clean up your traces
open allWhat for: Not to lose money.
Facebook users can make in-app purchases, order ads on the social network, donate money to charity, or buy products, for example, on Facebook Marketplace. To this end, the social network requests and stores details of a bank card or PayPal as a payment method.
That’s convenient, but in the event of a leak or hack, your financial information could fall into the hands of cybercriminals. To avoid that, delete the information from the social network’s database.
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Go to the Payments section;
- Select Facebook Pay and Ads payments; At the top of the screen, you will see a list of bank cards and PayPal accounts associated with the app.
- Go through them, tapping Remove Card for each.
- If you use a bank card or PayPal to pay for advertising, close your advertising account in the social network before removing it.
Downside: You need a saved payment method to order ads or make purchases on Facebook. After deleting cards and accounts, you will not be able to use these options.
You can still buy goods on Facebook store pages if they process payments on their own sites.
What for: To view what data Facebook has on you, remove the data you don’t need, and back up the data you want.
You can view and download all of the information Facebook stores about you. Information about posts, comments, likes, and other actions is kept in the activity log.
To view and download the log:
- Tap the menu icon in the upper right corner of the app;
- Select Settings & Privacy;
- Open Settings;
- Scroll down to the Access Your Information section;
- Tap the Download your information link. You can select individual data types, as well as set the time interval and file format (using the options at the bottom of the screen).
- Tap Create file to download an archive with your Facebook information.
The only option Facebook offers to delete the information it harvested is to delete the relevant account.
However, if you are a citizen of the European Union, you can demand that Facebook remove your data pursuant to Article 17 of the General Data Protection Regulation (GDPR). The company is obligated to take steps to remove that information even if the data has been transferred to third parties and is stored by them. Within a month, the social network will send you a progress report or the reason why your request has been denied (the list of possible reasons appears in Part 3 of Article 17 of the GDPR).