Part One
In February 2021, someone took over my Facebook account.
At first, I thought it was just another attempted password reset. Within a few hours, I had lost access to an account I had owned since 2004.
The attacker removed every recovery option except one: an email address connected to a domain I no longer owned.
What followed was a bizarre chain of events involving an expired domain, a targeted account takeover, Facebook advertising fraud, and a very lucky friendship with someone who worked at Facebook.
This is the story of how it happened—and what I learned from it.
It Couldn't Have Happened at a Worse Time
My wife and our newborn daughter had come home from the hospital just a week earlier. We were spending the weekend with her parents in South Bohemia, and after an exhausting week of learning how to be parents on the fly, I was looking forward to having some extra help.
On a Sunday afternoon in early February, I briefly checked my iPhone notifications between feeding, changing nappies, and trying to keep up with everything that comes with a newborn.
One notification caught my attention: a Facebook friend request.
When I opened the app, I saw it was from a complete stranger. I declined it and didn't think much of it. Random friend requests aren't exactly unusual on social media.
A few hours later, around 10 PM, while cleaning baby bottles, I opened Facebook again.
The first thing I saw was a notification informing me that my account had been temporarily restricted from tagging people.
That was strange.
The only option available was to submit an appeal, which I did immediately. In the message, I explained that I had no idea why my account had been restricted in the first place.
Then I noticed a few new emails.
And that's when I knew something was wrong.
One email, sent to my iCloud address, informed me that someone had requested a password reset for my Facebook account.
Someone Is Trying to Reset My Password
Fuck.
The next email confirmed that the password had already been changed.
Attached was an activity log showing a login from a Windows PC in Manchester, UK.
I immediately opened Facebook again, only to discover that I had already been logged out.
I tried to recover my account.
Normally, Facebook offered several recovery options. This time there was only one:
Send a recovery link to alanisko@alanisko.net
And that's where things got interesting.
The Forgotten Domain
Many years ago, before switching to alanisko.co.uk, I owned the domain alanisko.net.
Back then, I used the email address alanisko@alanisko.net and most likely used it when I registered my Facebook account in June 2004.
Seventeen years earlier.
Over the years, I changed email addresses several times and always updated my Facebook account with my current contact details and phone number.
What I didn't realise was that the old alanisko.net email address was still sitting there as one of my recovery options.
Maybe I left it there for nostalgic reasons.
Maybe I simply forgot about it.
Either way, it turned out to be a very expensive mistake.
By the time I attempted to recover my account, every modern recovery option had disappeared.
My phone number was gone.
My current email addresses were gone.
The only remaining option was an email address connected to a domain I no longer owned.
Facebook's alternative suggestion?
Create a new account.
No support chat.
No support email.
No way to speak to an actual human being.
Just a polite message suggesting that after seventeen years of posting photos, building connections, and helping generate content for their platform, I should simply start over.
So That Was It...
Or so I thought.
Since I couldn't regain access, I started asking myself a simple question:
Why?
Why would anyone want my Facebook account?
I wasn't a celebrity.
I had around 800 friends.
Nothing about it seemed particularly valuable.
Then another possibility crossed my mind.
Maybe Facebook wasn't the real target.
Maybe Instagram was.
At the time, my Instagram account had around 72,000 followers, which sounded considerably more attractive from a hacker's perspective.
I immediately logged into Instagram and changed my password.
Fortunately, I had already enabled two-factor authentication there.
I then went back to Facebook and attempted to lock the account completely, hoping that neither I nor the attacker would be able to access it.
Another concern was the fact that I had been using Facebook Login across countless websites and services for years.
Probably hundreds of them.
The thought of someone gaining access to those accounts worried me far more than losing Facebook itself.
How Did They Do It?
At this point, I knew someone had changed my password and removed every recovery option except the one linked to a domain I no longer controlled.
What I couldn't understand was how they had done it.
I was absolutely certain I hadn't clicked on any suspicious links, opened strange attachments, or responded to phishing messages.
The whole thing felt bizarre.
What made it even stranger was that the attacker hadn't replaced the alanisko.net recovery email with their own address, which is what usually happens in account takeovers.
Instead, they had left it there.
That detail kept bothering me.
So I decided to investigate.
I went to Whois.com and looked up the registration details for alanisko.net.
The moment I saw the registration date, I knew I had found the answer.
The domain had been registered that very day.
Through GoDaddy.
This wasn't a random attack.
Someone had specifically targeted my account.
I had used GoDaddy for years and still managed several domains through them, so I contacted their support team and explained the situation.
The support representative was helpful and seemed to understand that the domain had likely been purchased specifically to gain access to my Facebook recovery email.
Unfortunately, there wasn't much she could do immediately.
I was instructed to send an email outlining the situation and wait up to 72 hours for a response.
So I did.
And then I waited.
One Last Option
At that point, I felt completely stuck.
But there was one last possibility.
A good friend of mine, Craig, worked at Facebook in Dublin.
I sent him a message on Instagram explaining everything that had happened and asking if there was any chance he could point me in the right direction.
Then I went to bed.
The following afternoon, Craig replied.
He said he would try to submit an internal support ticket and see what happened.
A few hours later, he messaged me again.
This time, he asked for a completely new email address that had never been used with Facebook.
A few minutes later, I received a password reset link.
For the first time in two days, I felt a huge sense of relief.
I was back in.
Recovering the Account
Facebook's recovery process required me to verify recent activity, including posts, photos, and recently added friends.
Fortunately, I had successfully locked the account shortly after the attack.
The attacker hadn't had time to do much damage.
The only suspicious activity I found was two strangers who had somehow been added to my friends list.
I removed them immediately and sent their details to Craig.
As far as I know, Facebook later removed those accounts.
I thanked Craig repeatedly.
Without his help, I suspect I would still be locked out today.
When I asked him whether attacks like this were common, he told me Facebook was dealing with large numbers of compromised accounts, both large and small.
I also asked what the best protection was.
His answer was simple:
Enable two-factor authentication.
But not SMS-based authentication.
SIM swapping attacks have become increasingly common, and phone numbers can be compromised.
Instead, he recommended using an authenticator app that generates time-based security codes.
Lessons Learned
At that point, I thought the story was over.
I had my account back.
The attacker was locked out.
Everything seemed under control.
Or so I thought.
A few important lessons had already become clear.
Never rely on an email address connected to a domain you may not own forever.
Enable two-factor authentication wherever possible, preferably using an authenticator app rather than SMS.
Take privacy seriously.
Around that time, I started using an app called Jumbo, which had been recommended by a friend. Besides helping manage privacy settings, it also worked as an authenticator.
I already knew apps tracked a huge amount of user behaviour.
What surprised me was seeing just how many trackers were running in the background across the apps I used every day.
And while I was relieved to have recovered my account, I had no idea that the story wasn't over yet.
Two weeks later, things got much worse.
Part Two
Two weeks later, once again on a Sunday morning, I woke up just after 8:30 AM.
As soon as I reached for my phone, I knew something was wrong.
There were several notifications from my banking app informing me about outgoing payments.
Shit.
That wasn't good.
There were eight transactions in total, each for around $50. Some had been declined, but several had gone through successfully.
I immediately opened the banking app to investigate.
Unfortunately, the notifications were real.
The transactions were listed as PayPal-authorised payments for Facebook advertising.
I called my bank straight away, blocked the card linked to my PayPal account, and ordered a replacement.
A quick side note: credit where credit is due. Both my bank and Apple handled the situation brilliantly. I was able to start using my new card through Apple Pay before the physical replacement even arrived.
Following the Money
I never use my primary bank card for online purchases.
Whenever possible, I use either PayPal or a virtual card with limited funds.
In this case, PayPal was the payment method connected to my Facebook advertising account.
Because the charges appeared to be legitimate Facebook advertising expenses, PayPal processed them without raising any red flags.
The strange thing was that I hadn't run a Facebook or Instagram advertising campaign in months.
The last one had been sometime during the previous summer.
So I opened Facebook Ads Manager.
And there it was.
A campaign was actively running through my advertising account.
For a Vietnamese Facebook page.
One that I had absolutely nothing to do with.
The campaign was targeting women aged 22–50 in Vietnam and the Czech Republic and had a budget of approximately $1,000.
Even worse, it was performing extremely well.
People were clicking.
A lot.
My money was literally being spent in real time while I watched the statistics update.
Not Quite Finished
At that moment, it became clear that recovering my Facebook account hadn't completely solved the problem.
Somehow, the attackers still had access to parts of my advertising account.
I took screenshots of everything and contacted Craig again.
Once more, he submitted an internal support ticket.
This time the process took several days, but eventually Facebook restored full access to the advertising account and refunded the unauthorised charges.
The situation could have been far worse.
If I hadn't known someone inside Facebook, I honestly don't know how I would have resolved it.
Without access to support, I could easily have lost both the account and a substantial amount of money.
Thanks again, mate.
I owe you one.
What Were They Advertising?
At one point, curiosity got the better of me.
I asked a Vietnamese employee at my local grocery shop to take a look at the page and translate the content.
According to him, it was advertising women's clothing.
Nothing particularly sophisticated.
No cryptocurrency scam.
No fake investment scheme.
Just clothes.
Which somehow made the whole thing even stranger.
Coincidence or Something More?
Maybe I'm paranoid.
Maybe it was simply bad luck.
Maybe someone noticed that an old domain had expired and happened to find a Facebook account still connected to it.
That's entirely possible.
But the more I thought about it, the less convinced I became.
Less than two years earlier, I had spent several weeks travelling around Vietnam.
I bought a local SIM card on arrival and used it throughout most of the trip.
Like most travellers, I occasionally connected to hotel Wi-Fi networks, Airbnb connections, trains, and public internet access points.
I also used location-based apps such as Swarm and Foursquare, regularly checking in to places and leaving recommendations for other travellers.
Looking back, I had created a fairly detailed digital footprint of my journey across the country.
Could someone have connected those dots?
I honestly don't know.
But the fact that the fraudulent advertising campaign was running for a Vietnamese page certainly made me wonder.
Maybe it was coincidence.
Maybe it wasn't.
I'll probably never know.
What Changed Afterwards
The whole experience forced me to rethink my online security.
Not because I considered myself important.
Quite the opposite.
Most people assume hackers only target celebrities, influencers, or wealthy individuals.
The reality is much simpler.
If money can be made from your account, someone will eventually try.
Since then, I've enabled two-factor authentication on every important account I own.
Wherever possible, I use authenticator apps instead of SMS verification.
I removed Facebook Login from hundreds of websites and services and switched to Sign in with Apple whenever available.
I no longer use my primary credit card for PayPal payments. Instead, I use virtual cards that can be topped up only when needed.
Most importantly, I've become far more aware of the digital trail we all leave behind.
Every old email address.
Every forgotten account.
Every expired domain.
Every service you've signed up for and haven't thought about in years.
They're all potential entry points.
Final Thoughts
Looking back, the most surprising part wasn't that someone hacked my Facebook account.
It was how vulnerable a digital identity can become because of a forgotten decision made nearly two decades earlier.
An old domain name.
An abandoned email address.
A recovery option I had completely forgotten about.
That was all it took.
The attack itself wasn't particularly sophisticated.
What made it successful was that I had unknowingly left a door unlocked.
And after seventeen years, someone finally found it.
It's a crazy world we live in.
You don't have to be famous to become a target.
You don't need thousands of followers.
You don't need to be wealthy.
You just need to leave the wrong door open long enough for someone to notice.
And trust me—there are people out there checking every door.
