Instagram and Meta Security Checklist
Secure your Instagram and Meta Business Manager accounts with this step-by-step checklist covering passwords, 2FA, connected apps, and team access.
Overview
If you have any concern about unauthorized activity on your Instagram or Meta Business accounts, or you simply want to harden your security posture, work through this checklist in order. The first section is the most time-sensitive.
This checklist applies to all customers using ChatMaxima with Instagram and Meta Business integrations.
Priority 1: Immediate Actions (within 24 hours)
These steps mitigate any active or recent compromise. Complete them first, in the order shown.
1.1 Reset your Instagram password
- Path: Instagram > Settings and Privacy > Accounts Center > Password and Security > Change Password
- Choose a long, unique password of 16 or more characters that is not reused on any other service.
- Use a password manager (1Password, Bitwarden, Dashlane, or similar) to generate and store it.
1.2 Reset your Meta Business Manager password
- Path: business.facebook.com > Account > Personal Account > Password and Security > Change Password
- Apply the same password discipline as above.
- If your Meta Business Manager is linked to a personal Facebook account, secure that account too. The personal account credentials are often the actual entry point in compromise scenarios.
1.3 Enable two-factor authentication (2FA) on every account
- Instagram: Settings > Account Center > Password and Security > Two-Factor Authentication
- Facebook (the personal account linked to your Business Manager): Settings > Security and Login > Two-Factor Authentication
- Use an authenticator app (Google Authenticator, Authy, 1Password) rather than SMS. SIM swapping is a common attack vector and SMS-based 2FA can be bypassed.
1.4 Review and terminate active login sessions
- Instagram: Settings > Account Center > Password and Security > Where You're Logged In
- Facebook: Settings > Security and Login > Where You're Logged In
- Log out of every session you do not recognize. Log out of every device you no longer use.
1.5 Review recent login activity
- Instagram: Settings > Account Activity > Logins
- Look for logins from unfamiliar locations, devices, or IP addresses in the past 30 days.
- Document any suspicious entries with screenshots before they age out of the visible history.
1.6 Audit and remove connected apps
Note: This is the most overlooked step and the most important one.
- Instagram connected apps: Settings > Account Center > Apps and Websites > Active. Revoke any app you do not actively use or do not recognize.
- Facebook connected apps: Settings > Apps and Websites > Active. Same review.
- Meta Business Manager integrations: Business Settings > Integrations > Connected Apps. Revoke any unused or unrecognized ones.
- After revoking, regenerate tokens for apps you intend to keep, including ChatMaxima, by reconnecting from within the platform.
1.7 Review Meta Business Manager users and admins
- Business Settings > Users > People
- Verify that every person listed should have access. Remove anyone who has left, was temporary, or is unrecognized.
- For each remaining user, review their role and apply the principle of least privilege: grant only the access each person actually needs.
- Pay particular attention to Business Admin assignments. These are the highest-privilege roles.
Priority 2: Hardening (within 7 days)
These steps reduce the likelihood of future compromise.
2.1 Secure the email account linked to Meta and Instagram
The email account used for your Meta and Instagram logins is the master key. If it is compromised, every account that uses it is compromised.
- Set a unique, strong password.
- Enable 2FA (authenticator app).
- Review email forwarding rules. Attackers commonly set up silent forwarding to intercept password reset emails. Remove any forwarding rules you did not set up yourself.
- Review email filters and rules. Remove any that auto-archive, delete, or mark password reset emails as read.
- Review the recovery phone number and backup email on the account.
2.2 Enable login alerts
- Facebook: Settings > Security and Login > Get alerts about unrecognized logins
- Configure alerts to be sent to your email and a non-SMS channel where possible.
2.3 Set up trusted contacts on Facebook
- Settings > Security and Login > Choose 3 to 5 trusted contacts who can help you regain access if you get locked out.
2.4 Run anti-malware scans on devices used to access Meta and Instagram
- Use a reputable scanner (Malwarebytes, Microsoft Defender, Bitdefender).
- Pay particular attention to browser extensions. Review and remove any extensions you do not actively use, especially recently installed ones.
2.5 Verify Meta Business Asset ownership
- Business Settings > Accounts > Pages, Instagram Accounts, Ad Accounts
- Confirm every asset listed is one you own and intend to manage. Remove unfamiliar assets.
Priority 3: Operational Security (ongoing)
These practices reduce risk over the long term.
- Use a password manager for all team members. Shared passwords stored in spreadsheets, notes, or messaging apps are a major risk.
- Train your team on phishing. The most common compromise vector is a team member entering credentials on a fake Meta login page. Teach team members to verify URLs before logging in (the correct domains are facebook.com, instagram.com, and business.facebook.com).
- Be cautious about OAuth grants. When any new app requests access to your Instagram or Meta account, review the permissions requested carefully. Only grant access to apps you trust and need.
- Avoid shared logins. Each team member should have their own Meta Business Manager user account with appropriate permissions, rather than sharing one set of credentials.
- Watch for SIM swap attacks. If you use SMS 2FA anywhere, contact your mobile carrier and add a port-out PIN or password to prevent unauthorized SIM transfers. Better yet, replace SMS 2FA with authenticator app 2FA wherever possible.
- Review users and connected apps quarterly. Set a recurring calendar reminder to repeat steps 1.6 and 1.7.
Reporting Suspected Compromise to Meta
If you believe your Instagram or Meta Business account has been compromised, report it directly to Meta as soon as possible.
- Path: Meta Business Help Center > Report an Issue > Compromised Account or Suspicious Activity
- URL: business.facebook.com/business/help
- Submit the report from the account owner's logged-in session, which speeds up verification.
- Include: the names of affected accounts, approximate dates and times of suspicious activity, screenshots of any unauthorized messages or content, and any recent changes you noticed (passwords, recovery email, connected apps, admin users).
Meta will conduct its own review and produce activity records for your accounts. This is the authoritative documentation of any unauthorized activity on your Instagram and Meta accounts.
What ChatMaxima Covers and What It Does Not
It is important to understand the boundary between what we can and cannot help with.
ChatMaxima is responsible for:
- The security of our platform infrastructure.
- The encryption and handling of OAuth tokens we hold on your behalf.
- The integrity of campaigns and messages sent through our API.
- Detecting and preventing abuse on our platform.
- Maintaining audit logs of API activity for your account.
ChatMaxima cannot directly secure:
- Your Instagram and Meta Business account passwords.
- Your team members' credentials and security practices.
- Activity that occurs on Instagram's native interface (mobile app or web).
- Other third-party apps you connect to your Meta accounts.
- Your team members' devices, browsers, or email accounts.
For anything in the second list, the steps in this checklist are how you protect those layers. We are happy to provide guidance, but the actions must be performed by the account owner with their own credentials.
Need Help?
If you have specific questions while working through this checklist, contact ChatMaxima Support. We can clarify any step and confirm whether a specific app or integration is associated with your ChatMaxima account.
For urgent compromise, prioritize the Meta abuse report above all else. Meta is the only party with full visibility into Instagram-side activity and the authority to lock and recover compromised accounts.