A new job, a trip, a wedding — posting it is now part of the event. For most people in Bangladesh, Facebook is also the phone book, the marketplace, the news and, for a growing number, the shop. That is exactly why it is attacked. The people who steal accounts here are not sophisticated; they rely on the fact that most users have never looked at a security setting. This is the list of what to look at.
What an attacker actually wants
Identity. Name, photo, phone number, employer, relatives — enough to open a fake account in your name, or to convince your contacts that a message asking for bKash money is from you. Leverage. A hacked account contains private messages and photos, and the extortion that follows — pay or they go public — is one of the commonest cybercrimes reported to police in Dhaka. Other people. Your account is a door to everyone in your friend list; the scam messages go out from it. Your work. Photographs, songs, writing and designs posted publicly are lifted and reposted as someone else’s, with no practical remedy.
The eight habits
- A different password for every account, long, with capitals, numbers and a symbol. The Facebook password must not be the Gmail password: the Gmail recovers the Facebook.
- Two-factor authentication on Facebook, Instagram, Gmail and WhatsApp. With it on, a stolen password is useless without the code on your phone. Use an authenticator app rather than SMS where offered; SMS codes are stolen by SIM swaps.
- Update the phone, the browser and the apps. Most break-ins use a hole that was fixed months earlier.
- Set the audience before posting. “Public” means strangers, and strangers include the people who screenshot. Personal photos go to Friends at most; check who can see your friend list and phone number under Settings → Privacy.
- Think before sharing. Never the address, the phone number, the NID, the boarding pass or the bank card — and not your child’s school.
- Do not tap the link. “You have won”, “your account will be closed”, “is this you in this video?” — every one is a phishing page that copies your password when you type it. Go to the site yourself instead.
- Audit third-party apps. Quizzes and games that “log in with Facebook” keep access for years. Settings → Apps and Websites; remove everything you do not recognise.
- Log out of shared computers and check Settings → Security → Where you’re logged in; end any session you do not recognise.
If it is already gone
Go to facebook.com/hacked from a device that was previously logged in, follow the recovery, then change the email password too. Tell your friends by another channel that messages from the account are not from you. And report the extortion, if it comes, to the police cyber unit — the threat is a crime whether or not you pay.




