A Facebook account is worth more to attackers than most people assume. It's not just your photos and messages - It's a trusted identity that can message your friends with scam links, run ads on a stolen payment method, and log in to third-party apps via "Continue with Facebook." That's why a weak, reused, or possibly-leaked Facebook password is worth replacing today, and why Meta has been nudging everyone's security settings into its centralized Accounts Center. The move confused a lot of muscle memory - The password setting is no longer where it lived for a decade - So here's the current path on web, mobile, and the recovery flow if you're locked out.
Change Your Facebook Password on the Web
On a desktop browser:
- Log in at facebook.com and click your profile picture in the top-right corner.
- Choose Settings & privacy → Settings.
- At the top of the settings menu, open Accounts Center (Meta groups password, security, and personal details there).
- Select Password and security, then Change password.
- If your Facebook and Instagram accounts are linked in Accounts Center, pick the Facebook account you're updating.
- Enter your current password, then the new one twice, and save.
Facebook only demands 6 characters, one of the weakest minimums of any major platform - Meeting it is nowhere near enough. Generate a 16-character random string with a password generator, or if you insist on something typeable, a multi-word passphrase from a passphrase generator resists the dictionary-based guessing that mows down short human-made passwords.
Change It in the Mobile App
The app mirrors the web layout:
- Open the Facebook app and tap the Menu button (your profile picture or the three-line icon, depending on platform).
- Tap Settings & privacy → Settings.
- Tap Accounts Center at the top, then Password and security.
- Tap Change password, choose the account if you have several linked, and enter the old and new passwords.
Because Accounts Center is shared Meta infrastructure, these steps are essentially identical on iPhone and Android, and very close to the flow you'd use for Instagram.
If You've Forgotten Your Password
From any Facebook login screen, tap Forgot password? (on the web you can also go directly to facebook.com/login/identify). Then:
- Enter the email address or phone number on the account to find it.
- Choose where to receive a reset code or link - Email or SMS, depending on what's on file.
- Enter the code, set a new password, and choose whether to stay logged in on other devices or log them all out. If there's any chance someone else has access, log them all out.
If you no longer control the email or phone on the account, look for the option that says you can't access those channels - Facebook will route you through additional identity checks, which work best from a device you've previously used to log in. Be wary of "Facebook recovery services" advertised online: legitimate recovery only happens through facebook.com, and anyone else asking for payment or your ID is running a scam of their own. That instinct - Verifying you're on the real domain before typing a password - Is the core skill in our phishing protection guide, because fake Facebook login pages remain one of the most common credential traps on the internet.
If a "friend" messages you a login link, treat it as hostile until proven otherwise. Compromised accounts phish their own contact lists first - That's what makes them valuable.
After You Change It
| Cleanup task | Where in settings | Why |
|---|---|---|
| Log out other sessions | Password and security → Where you're logged in | Evicts anyone still holding an old session |
| Turn on two-factor authentication | Password and security → Two-factor authentication | Blocks logins even with a stolen password |
| Review connected apps | Settings → Apps and websites | Old third-party apps can retain account access |
| Check login alerts | Password and security → Login alerts | Get notified of future unrecognized logins |
| Update your password manager | Your vault | Prevents a failed autofill and a lazy re-reset |
Start with Where you're logged in: changing your password does not necessarily terminate every existing session, so scan the device list and remove anything unfamiliar - An Android phone in a city you've never visited is the classic tell. Then enable two-factor authentication; an authenticator app is the strongest everyday option (see TOTP vs SMS 2FA for why app codes beat text messages, and try our TOTP generator to see the codes in action).
Finally, if you changed the password because it leaked, remember that attackers immediately try leaked credentials on other big sites - The attack known as credential stuffing. Any account sharing the old password needs a new, unique one too. If keeping dozens of unique passwords in your head sounds impossible, that's because it is; our guide on how to remember strong passwords explains the realistic options, starting with a manager.
FAQ
Does changing my Facebook password also change Instagram?
Not automatically - They're separate passwords even when the accounts are linked in Accounts Center. The linking mainly affects logins and profile syncing. When you change one, Accounts Center asks which account you're updating, so make sure you repeat the process for Instagram if that password also needs replacing.
Does changing my password log hackers out of my Facebook?
Not reliably on its own. Facebook's reset flow offers to log out other devices, and you should also manually review Password and security → Where you're logged in, then remove every session you don't recognize. Skipping that step can leave an intruder's session alive with the old cookie.
How do I recover a hacked Facebook account?
If you can still log in, change the password and sweep sessions immediately. If you're locked out entirely, use the Forgot password flow, and if the attacker changed your email or phone, follow the on-screen path for compromised accounts, which adds identity verification. Acting within hours matters - Attackers monetize hijacked accounts fast.
What's the minimum safe length for a Facebook password?
Ignore Facebook's 6-character minimum; that's crackable almost instantly. Aim for 16+ random characters or a four-word passphrase, unique to Facebook, stored in a password manager, and backed by two-factor authentication. Length plus uniqueness does more than any symbol requirement.