By Jackson Godwin. Cybersecurity Analyst & Penetration Testing

The First Thing I Checked Was My Password
The moment I confirmed that the login attempt had failed, I asked myself an uncomfortable question.
“When was the last time I changed my Facebook password?”
I honestly couldn’t remember.
That was a problem.
Many people create a password once and never think about it again.
Months turn into years.
Eventually, the same password is being used on:
- Gmail
- Netflix
- Shopping websites
- Banking apps
- Work accounts
It feels convenient.
But from a cybersecurity perspective, it’s one of the biggest mistakes anyone can make.
If just one of those websites suffers a data breach and you’ve reused the same password, cybercriminals may try that username and password combination on Facebook and other popular services.
This attack is known as credential stuffing, and it’s responsible for thousands of compromised accounts every year.
I wasn’t willing to take that risk.
I immediately changed my Facebook password to something completely new.
It wasn’t based on my birthday.
It wasn’t based on my name.
It wasn’t similar to any other password I used.
Instead, I created a long, unique password that would be difficult to guess.
That single decision significantly improved the security of my account.
The Next Thing I Enabled Changed Everything
After updating my password, I looked at another security setting.
One that many Facebook users ignore.
Multi-Factor Authentication (MFA).
As a cybersecurity consultant, I recommend MFA to businesses almost every day.
Yet I know many people who still don’t use it on their personal accounts.
That needs to change.
Imagine someone somehow discovers your Facebook password.
Without MFA, they may be able to log in immediately.
With MFA enabled, Facebook asks for an additional verification step before allowing access.
Depending on your settings, this could be a code from an authentication app or another approved verification method.
That extra layer of protection can make unauthorized access much more difficult.
Within minutes, I enabled MFA on my account.
It took less than five minutes.
The peace of mind was worth far more.
I Reviewed Every Device Logged Into My Account
Facebook keeps a record of where your account is currently signed in.
Most users never check it.
I opened Security and Login and carefully reviewed every active session.
I saw my laptop.
My Android phone.
My office computer.
Everything looked familiar.
If I had noticed a device I didn’t recognize, I would have immediately signed it out and changed my password again.
Checking your active sessions regularly is a simple habit that can help you detect suspicious activity early.
Then I Remembered Something Strange
As I continued reviewing my account, I remembered something that had happened a few days earlier.
I had received a Facebook friend request from someone who appeared to know several of my friends.
The profile picture looked professional.
The account had posts.
There were mutual friends.
Everything seemed normal.
But something didn’t feel right.
Instead of accepting the request immediately, I took a few minutes to look more closely.
The profile had only been active for a short time.
Most of the photos had been uploaded within days.
The comments looked repetitive.
Very few people interacted naturally with the posts.
I declined the request.
Later, I discovered that several people had reported similar fake profiles pretending to be professionals in different industries.
Fake accounts are often created to build trust before attempting scams, phishing attacks, or impersonation.
That’s why it’s always worth taking a closer look before accepting requests from people you don’t genuinely know.
Messenger Is Another Target
Many people think Facebook security ends with the login page.
Unfortunately, that’s not true.
Messenger has become a favourite tool for cybercriminals.
Imagine receiving a message from a close friend saying:
“Is this you in this video?”
Or:
“Congratulations! You won.”
Or:
“Please vote for me.”
The message includes a link.
Without thinking, many people click it because they trust the sender.
But what if your friend’s account has already been compromised?
In many cases, the attacker—not your friend—is sending the message.
That’s why unexpected links should always be treated with caution, even when they appear to come from someone you know.
…









