How was my Meta ad account or admin profile hacked?

A hack of an ad account is a major blow to any company or business, as it can seriously compromise its operations. One of the first steps to counteract these types of attacks is to scan our computers or devices with antivirus software to detect any malware or viruses. However, the question always arises: How was my ad account, computer, or admin profile hacked? How did the hacking begin? In this article, I will try to answer these questions and mention the main attack methods and mistakes that companies make in this regard:

Importance of a genuine and reputable antivirus

The first thing to keep in mind is that if the user does not have a genuine antivirus program on their computer or device, they will have no protection against these types of attacks or infections. When an antivirus program detects a virus or malware, the first thing it does is inform the user about the situation, then disinfect, remove, or isolate the threat. It’s important to note that for an antivirus program to function correctly and protect your computer, it must meet the following requirements:

– It must be genuine.

– It must be from a reputable company.

– It must be up-to-date.

– All security features must be enabled.

Malware or Virus Infection of a Computer or Device

Hackers typically gain access to advertising accounts by connecting from the same computer or device as their victims. To remotely control these devices, hackers usually use malware or a virus (Trojan) to infect and control the computer. This way, the social media platform won’t be able to detect the hack because the session is initiated from the user’s own computer. Below are some of the different infection methods:

Downloading a File and Opening It with a Password-Protected File

The primary source of infection is downloading a file and entering a password. This is generally the standard method of infection. How this attack is carried out depends on the attacker. For example, in my personal experience, when my computer was infected in 2023, someone contacted me through a well-known freelance platform to request a quote. After I submitted my proposal, the person agreed to the terms and then sent me a file to review, claiming it contained their business materials. They told me to check the information and indicated that the file was password-protected. I downloaded the file, entered the password, and viewed the materials. Then, about five days later, the hack occurred.

It’s important to note that after the hack, the person used my personal profile to contact others using the same method (claiming interest in hiring a specific service and then sending an attachment with a password).

Phishing via email or text message

The next method is phishing, which can be carried out through any online channel, although attackers generally use email or instant messaging app chats. The most common techniques in these cases involve impersonating a recognized provider or company. For example, in emails, they might claim to be from a specific online service and instruct the recipient to log in via an attached link to resolve a particular problem. This also occurs in some chats, where attackers impersonate the platform itself. For instance, a private message on Facebook, Instagram, or WhatsApp might claim to be from Meta, stating that the account has been sanctioned or something similar.

Downloading or using pirated games, applications, or programs

Another way to infect a computer is through pirated content. For example, many pirated games, applications, programs, courses, audio, and videos download malware that infects the user’s computer. This is the second most common technique used to infect computers globally.

Websites infected with malware or viruses

Another way to get infected is through an “infected” web hosting service or when browsing websites infected with malware. As with pirated programs and applications, an infected website can download malicious software that infects the user’s computer or device.

It’s important to note that our website or web hosting service can be infected with malware due to a vulnerability in our own website. For example, some of the main vulnerabilities that a WordPress website can have include:

– Weak password.

– Outdated or abandoned plugins or templates.

– Lack of updates to the core, PHP, or server.

– Not having an active security plugin or program (for example, Wordfence).

How was my Meta ad account or admin profile hacked?

Email Associated with an Administrator Account

The next method for hacking accounts involves capturing the account’s email. For example, there are cases where the account has a strong password and two-step verification. Still, the email associated with that account is vulnerable, either because it has a weak password or because it lacks two-step verification.

While it is essential to have a strong password and enable two-step verification, another factor to consider is the company behind your email service. For example, with Google (Google Workspace), you can expect a certain level of quality and security. In contrast, with other services (such as cPanel webmail on your server), the level of quality and security will be lower.

Another point to consider is the email’s visibility. If the email controls an important account, it is best to keep it hidden or not publicly visible (many companies make the mistake of displaying their administrator email addresses on their websites or official social media accounts). Another tip is to avoid using the same email for multiple accounts, because if someone gains access to that email, they can then control more of our organization’s assets.

External Programs or Tools for Publishing Content

Another form of infection occurs through the use of external tools, especially those capable of performing mass actions across multiple social media accounts and online platforms. We must keep in mind that if someone hacks such an external tool, the attack will also directly affect us, since our digital assets depend on it. Among the main examples are tools that allow us to publish on multiple social networks or manage multiple advertising accounts.

It is important to note that, in the event of a penalty, we cannot “blame” the external tool, as we are responsible for what happens on our digital channels. Therefore, it is recommended to only use official tools. For example, if we have a Facebook page or an Instagram account, it is best to schedule our posts on the Meta platform itself: Meta Business Suite.

Regarding the use of an external tool, two variables can further aggravate the problem:

– Publishing large volumes of content.

-If we use this tool to control multiple social media platforms (the hacker will be able to control even more platforms).

Poor Administrator Management

Another factor contributing to account hacking is poor administrator management of a digital asset. Below are some of the most common errors in this regard:

Failing to Remove Former Employees

A common mistake is failing to revoke administrator access for former employees or workers who will no longer be using a specific account. If such a profile is hacked, hackers can use it to control the organization’s digital resources.

Granting High-Level Permissions to Administrators

Another common mistake is granting high-level permissions to an administrator. We must keep in mind that there are several permission levels, and in many cases, a “basic” or “intermediate” level permission will be sufficient. We must also consider that the higher the administrator’s level, the greater the negative impact will be in the event of a hack. Therefore, it is recommended to assign the appropriate access level when appointing a new administrator, and to appoint “general” (or top-level) administrators only to highly trusted individuals or when strictly necessary.

Failing to verify that people are using protected devices

All employees or collaborators of the company must connect from properly protected computers or devices. As mentioned previously, for a computer to be protected, it must have genuine antivirus software (from a reputable company) installed, the antivirus software must be up to date, and all security features must be enabled.

Using the same account or personal profile for multiple employees

Another mistake many companies and businesses make is using the same account (with username and password) for multiple employees. For example, some companies make the mistake of having only one personal administrator profile, and employees access the account using this personal profile (sharing passwords), instead of using administrator accounts (where each person accesses from their own personal profile).

Not requiring administrators to have two-step verification enabled

Another common mistake is failing to require all administrators to have two-step verification enabled. While some platforms require this, others make it optional. It’s important to keep in mind that two-step verification isn’t foolproof, but it adds an extra layer of security to each account or personal profile, making hacking more difficult.

Bad practices that contribute to account hacking

In addition to administrator management, there are some bad practices at the user and business levels that can cause problems. Below are the most common mistakes in this regard:

Not logging out after work

A fairly common mistake is not logging out after work. For example, some advertisers or content creators leave their personal profiles open all day after work, which can cause problems if they are hacked, since with the session open, a hacker won’t need to log in or go through other security steps. Therefore, it is recommended to log out after work, and if using the profile for personal use, it is best to log in and out each time you use the device. Another way to avoid these types of problems is to use one profile for work and another for personal matters.

Sharing passwords via text messages or unsecured channels

A fairly common mistake, at both the user and company levels, is sharing passwords over unsecured channels. For example, instead of using a password-sharing program (like LastPass), employees share passwords via email or WhatsApp messages, which is very risky from a cybersecurity perspective.

Sharing the device with a partner or other family members

Another frequent mistake at the personal level is sharing the work device with a partner or other family members. We must keep in mind that the more users who use a device, the greater its vulnerability. Therefore, it is recommended not to share the work device with others or to use a separate device for personal matters.

Using pirated products and services

Unfortunately, piracy is not just a concept; for many people, it’s a way of life. We must keep in mind that a person who frequently uses pirated products or services is more likely to be hacked, since many of these products or services contain viruses or malware.

Connecting from unsecured wireless networks

Another problem on a personal level is the use of “unsecured” or “public” wireless networks to connect to the internet. Many public networks are often infected or compromised, as they can extract personal data from their users. Therefore, it is recommended to connect only from personal or 100% trusted networks.

Using weak passwords

A common mistake is using “weak” passwords or simply failing to change them frequently. We must remember that a weak password is very vulnerable to brute-force attacks and other hacking methods.

Using the same password or email for multiple accounts

A serious security error is using the same password (or email) for multiple accounts. The problem with this vulnerability is that if a hacker compromises one account, they can access the rest of the company’s accounts using the same credentials. Therefore, it is recommended to use a unique password for each account and a different email (or username) to log in to each platform.

Lack of employee onboarding processes

A fairly common mistake is not having employee onboarding or offboarding processes. For example, if an employee is no longer working for the company, their credentials should be removed, and they should be asked to hand over any outstanding information. Furthermore, there should be protocols in place to ensure a smooth departure. Unfortunately, many companies end an employment relationship by sending a simple text message or making a phone call, without processes or personnel responsible for verifying that the company’s digital assets have not been compromised. Security problems typically arise when former employees’ access is not removed and when the employment relationship ends acrimoniously.

Using fake names on administrator accounts

Another common company mistake is using a fake name on an administrator profile. The problem with a fake name is that, in the event of a problem or a hack, we won’t be able to perform the identity verification process to recover the account (by submitting an ID document), since that name simply doesn’t exist.

Not having a cybersecurity specialist

The company needs to have a cybersecurity specialist. Just as there are administrative, sales, marketing, and accounting staff, it’s essential to have cybersecurity specialists, especially if the business has a strong online presence. We must keep in mind that as time goes on, hackers are becoming increasingly aggressive and efficient because, just as digital tools evolve, so do online attacks. Many online security problems at the corporate level stem from an undervaluation of the role of the cybersecurity specialist. Among the various functions and actions a cybersecurity specialist can perform are the following:

– Evaluating the security level of the company’s digital assets.

– Creating online security protocols and procedures for the company.

– Implementing updates on various online platforms to reduce vulnerabilities.

– Training and supervising staff on cybersecurity matters.

What are your thoughts on this topic? Have you experienced any security issues with your advertising account or administrator profile?

If you need assistance with this, you can contact me by visiting the following link.

Image by Markus Spiske via Unsplash.com under a Creative Commons license.

Leave a Comment