By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Biggest Lesson Had Nothing to Do With Facebook
By the time I finished reviewing my account, changing my password, enabling Multi-Factor Authentication, and checking my login activity, I was finally able to relax.
My account was safe.
No one had successfully accessed it.
But something had changed.
I realized that what almost happened wasn’t really about Facebook.
It was about my digital identity.
Today, our social media accounts are connected to almost every part of our online lives.
Your Facebook account may be linked to:
- Messenger
- Facebook Marketplace
- Business Pages
- Meta Ads Manager
- Games and third-party apps
- Shopping websites
If someone gains access to your Facebook account, they may try to exploit those connected services as well.
That’s why protecting your social media accounts is no longer optional.
It’s essential.
The Social Media Security Checklist Everyone Should Follow
After completing my security review, I created a checklist that I now use every few months.
I encourage everyone to do the same.
✅ Use a Strong, Unique Password
Never reuse your Facebook password on another website.
Every important online account should have its own password.
✅ Enable Multi-Factor Authentication (MFA)
This adds an extra layer of protection if someone discovers your password.
✅ Review Login Activity Regularly
Check the devices currently signed into your account.
Remove anything you don’t recognize.
✅ Update Your Recovery Information
Make sure your email address and phone number are current.
Without them, recovering your account can become much more difficult.
✅ Be Careful With Friend Requests
Not every profile is genuine.
Take a few moments to review unfamiliar accounts before accepting requests.
✅ Think Before Clicking Links
Whether the message comes through Facebook, Messenger, WhatsApp, or email, unexpected links deserve extra attention.
When in doubt, verify before clicking.
✅ Keep Your Devices Updated
Install security updates for your phone, tablet, and computer.
Many updates fix vulnerabilities that attackers may try to exploit.
Why Social Engineering Is So Effective
One thing stood out during this entire experience.
The attacker didn’t need sophisticated hacking tools.
They relied on something much more powerful.
Human psychology.
Cybercriminals understand that people:
- Trust familiar brands.
- Trust messages from friends.
- React quickly when they think an account is at risk.
- Click first and think later.
That’s why cybersecurity awareness is one of the strongest defenses you can have.
Technology helps.
But informed decisions help even more.
What Should You Do If Your Facebook Account Is Compromised?
If you ever believe someone has accessed your Facebook account without your permission:
- Change your password immediately using Facebook’s official website or app.
- Sign out of unfamiliar devices.
- Enable Multi-Factor Authentication if it isn’t already enabled.
- Review recent posts and messages for suspicious activity.
- Update your recovery email and phone number if necessary.
- Let trusted friends know if you believe your account may have been used to send scam messages.
The faster you respond, the better your chances of limiting any damage.
Frequently Asked Questions
Can someone hack my Facebook account just by knowing my email address?
Knowing your email address alone is usually not enough to access your account.
However, attackers may use it in phishing attempts or combine it with passwords exposed in previous data breaches.
Is Multi-Factor Authentication really worth enabling?
Yes.
MFA is one of the most effective ways to reduce the risk of unauthorized access.
It adds another verification step beyond your password.
How often should I change my Facebook password?
There is no fixed schedule for everyone.
A good practice is to change it if you suspect it has been exposed, reused elsewhere, or if Facebook alerts you to suspicious activity.
Are fake Facebook friend requests common?
Yes.
Fake profiles are frequently used for impersonation, phishing, romance scams, and other forms of social engineering.
Always review unfamiliar requests carefully.
Final Thoughts
Looking back, I was fortunate.
The login attempt failed.
No personal information was stolen.
No one gained control of my account.
But the experience reminded me of something I often tell my clients.
Cybersecurity isn’t about believing you’ll never be targeted.
It’s about making sure you’re prepared when you are.
The strongest password in the world won’t help if you click a fake login page.
The best antivirus software won’t protect you from every social engineering attempt.
Your greatest defense is combining good security habits with informed decision-making.
So tonight, before you scroll through Facebook one more time, take just ten minutes to review your security settings.
It might be the most valuable ten minutes you spend online this year.
About the Author
Jackson Godwin is a Cybersecurity Consultant specializing in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
With years of experience helping organizations strengthen their cybersecurity posture, Jackson is passionate about translating complex security concepts into practical advice that everyday internet users can understand and apply.
Through JacksonTechnology.com.ng, he publishes cybersecurity tutorials, ethical hacking guides, cloud security insights, compliance resources, and real-world security awareness stories designed to help individuals and businesses stay protected against evolving cyber threats.
Whether you’re securing your first Facebook account or managing enterprise security, his mission remains the same:
To help people stay one step ahead of cybercriminals through education, awareness, and practical cybersecurity knowledge.







