Field Notes / Access Control
Who has admin access to your Facebook Page right now? Are you sure?
Open Meta Business Suite in the next tab and read the list of people who can post as your business. If you cannot name every one, you already have the finding we see in 9 of 10 Filipino SMBs. Here is the 15-minute fix.
01 The 15-minute audit
ou walk away from this chapter with a clean access list and two-factor turned on for every admin who should be there. That is the whole outcome. Total time is between 8 and 25 minutes, depending on how many admins you start with. The method sits underneath, five steps, no tooling, no ticket.
A Facebook Page carries three things an attacker wants in one place. It holds your brand voice, so anything posted from it looks like you. It runs your customer conversations through Messenger. It owns the ad account, which means it controls budget that can be redirected. For a Filipino SMB whose sales run through Facebook, the Page is the single most concentrated piece of digital trust the business owns. Guarding it starts with knowing who holds a key Meta Page Roles .
- Log in to Business Manager at business.facebook.com with the account you use to run the business. On a legacy Page, open the Page and click Settings, then Page Roles.
- Pull the access list. Settings, then People and Assets, then People shows everyone with Business Manager access. Open Pages and click each Page name to see its specific roles.
- Read every name out loud. For each one, answer two questions. Does this person still work here? Do they need this level of access for their job today? If either answer is no, remove them now.
- Turn on two-factor authentication for every admin who stays. Use an authenticator app, not SMS. Settings, then Security and Login, then Two-factor authentication.
- Write down who has access, at what level, and put a recurring 15-minute calendar event every quarter. Pages drift back into sprawl when the review never recurs.
That is the audit. Do it before you finish this article, and the 15-minute version of this problem solves itself today. Leave it, and you inherit one of the versions below.
02 The admins you forgot
A 65-person logistics firm in Quezon City retained us for a red team in mid-2024. During reconnaissance we pulled the Page admins that Meta exposes through its transparency report, then cross-referenced the names against LinkedIn. We found 23 people listed as admins. 11 of them had moved to other employers, several years earlier in some cases. One had joined a direct competitor.
We do not know whether anyone used that access. We do know the structural risk had been open for 14 months, and the only reason it surfaced was our engagement. The owner removed the 11 ex-employees during the call. It took 11 minutes. The cleanup took less time than his explanation of why it had never been done, and that was the part that bothered him.
The second case cost nothing to fix and a lot to ignore. A 22-person agency in Cebu gave a freelancer admin access during a campaign in late 2023. The contract ended. Nobody removed her. Eight months later, after a payment dispute the agency thought was settled, she logged in and posted a long public message criticising how the agency treated contractors. It sat in front of 12,000 followers for nearly 6 hours before anyone in management noticed. Screenshots were already circulating in industry groups. The reputational repair took 4 months.
03 The hijacked Page
A small bakery owner in Makati contacted us in early 2025 after her Page was hijacked. The attacker had transferred it out of her Business Manager, renamed it to a crypto-trading scam, and was running ads against her audience of 38,000 followers. The forensic timeline was simple. She had used the same password for her personal Facebook as she had used for an online clothing retailer that was breached in 2022. Her credentials had sat in a public dump for over two years Have I Been Pwned .
Eventually a credential-stuffing tool tried that email and password against Facebook, succeeded, and the attacker noticed she was an admin of a profitable Page. Recovery took 4 weeks of back and forth with Meta support. She lost an estimated PHP 280,000 in revenue while the Page was gone, and a measurable share of audience trust afterwards. The lesson, in her words, was that her personal Facebook password had been a business asset all along, and she had been treating it like a personal one.
04 Why it is a red team finding
You might wonder why a CREST-accredited offensive team writes about Facebook Page hygiene. It looks like an IT chore. The reason is that when we map a Philippine SMB's attack surface, the Page ranks alongside the email tenant and the accounting system, and often ahead of both. The consequences of a takeover are more visible to your customers and slower to recover.
So we test it the way an attacker would. We enumerate admins from public signals, check reused passwords against credential dumps, measure two-factor coverage across every admin account, review recovery email security, and probe whether we can social-engineer access through Meta support. The result is a finding every time. Sometimes small. Often large. The 15-minute audit in Chapter 1 closes most of it, and turning on two-factor closes most of what remains Meta 2FA .
05 Run the audit, then close the tab
The honest question is whether you will actually open Meta Business Suite now and run the five steps. For most readers the answer is no. They bookmark the page, screenshot the steps, or tell themselves Monday. The 11-month version is what brought the logistics firm to us. The 4-week recovery is what happened to the bakery. Pick which version you want, then act on it in the next 15 minutes.
If you want a second pair of eyes, hand us your Page URL and we will tell you what we see from the outside that you cannot see from the inside. Same operator who would run your engagement, no slide deck. Enterprise-grade cybersecurity, within reach.
- Every ex-employee and expired contractor removed from People and Page Roles
- Two-factor authentication turned on for every remaining admin, via an authenticator app
- Page moved into a Business Manager so it no longer depends on one personal account
- Login alerts enabled and a recurring quarterly access review booked in the calendar
References
Sources
- Meta Business Help Centre. Page Admin Roles. Meta Platforms, 2024. facebook.com
- Meta Business Help Centre. Two-Factor Authentication for Business. Meta Platforms, 2024. facebook.com
- Have I Been Pwned. Credential Breach Database. Troy Hunt, 2024. haveibeenpwned.com
- National Privacy Commission. Data Privacy Act of 2012 Guidance. Republic of the Philippines. privacy.gov.ph