Not Sure Where to Start?
Discover what works best for your body and lifestyle—whether you’re exploring for the first time or coming back for your favorites, we’ve got you covered.
By Sister Kate, Sisters of the Valley
On July 1, 2026, we discovered that something was wrong with our Meta Business Portfolio.
We were not investigating a cyber-attack. We were trying to understand an unexpected Instagram payout notification when we noticed that the administrative relationships inside our Meta Business Portfolio no longer looked the way they should.
At first, I assumed I had simply forgotten how something had been configured. Like many small business owners, I manage multiple platforms, pages, and software integrations. It never occurred to me that the administrative foundation of the business itself might have been altered months earlier without my knowledge.
Over the next four weeks, we attempted to determine what had happened, understand what had been lost, and restore the administrative control that had quietly disappeared. This article documents that investigation.
My hope is that it may help other small businesses recognize the signs of a compromised Meta Business Portfolio and understand that if it happens, there is no way to get that information to Meta.
We did easily and early in the process succeed in getting the information to the FBI and the FTC cyber-crime units, but Meta never received the report on the ‘Call Her Daddy’ impersonator hack. Concluding a month’s worth of effort, a long, tedious gathering of documents, the story ends with ‘Meta doesn’t even know’. Meta AI offered no path to receive the information and here is that story.
Discovery
As we examined the Business Portfolio, we discovered that my personal Facebook account no longer had the administrative relationship it had maintained with our business for nearly twelve years.
Further investigation revealed that Meta had suspended my personal account’s administrative privileges on April 17, 2026, for an alleged violation of Community Standards. Until July 1, I had never connected that event to our business because nothing visible had changed. Our Facebook page remained online, customers continued interacting with us, although our audience growth had been stalled.
The date stood out because my calendar showed an online meeting with individuals who had represented themselves as members of the technical team for the Call Her Daddy podcast. During that meeting, I was instructed to configure what appeared to be a Facebook Event collaboration. At the time, nothing about the request seemed unusual. Only after reconstructing the timeline did it become apparent that those instructions had likely provided the attackers with the opportunity to compromise our Business Portfolio and sever the administrative relationship between my personal account and the business assets.

One aspect of this incident deserves emphasis. The attackers did not destroy our public presence. They did not erase our audience or remove our content. The public-facing business continued operating almost normally. What changed was ownership behind the scenes. And that is exactly why reporting it as a hacked asset didn’t work.
Consequences
Because our public pages remained functional, the consequences of the compromise were not immediately obvious. Followers continued seeing our content. From the outside, the business appeared healthy. The damage was operational rather than public.
Although the business continues to function, we no longer have the ability to perform many of the administrative tasks required to manage and expand it. Among other things, we have lost the ability to assign or remove administrators, authorize new collaborators, connect third-party business services such as Meltwater, establish new business integrations, and manage portions of the Business Portfolio that require administrative authorization.
Ironically, the same administrative break that appears to have prevented me from regaining control also appears to have prevented the attackers from continuing to manipulate the account. We now exist in a peculiar form of digital limbo. The storefront remains open, but neither side appears able to exercise complete administrative control.
Attempted Resolution
The remainder of July was spent following every recovery procedure made available through Meta’s automated support system.
Viewed individually, each recommendation appeared reasonable. Viewed collectively, they all depended upon the same assumption: that Meta still recognized my personal account as an authorized administrator of the Business Portfolio.
That assumption was no longer true. The appeal process directed me to a page that reported “No Eligible Admin Pages.” Manual review links repeatedly returned “Page Isn’t Available.” Identity verification led back to the same administrative dead end. Different browsers, different devices, and private browsing sessions produced identical results.
Throughout the month, Meta’s AI assistant continued suggesting alternative recovery paths. Each recommendation ultimately returned to the same obstacle: every available procedure required administrative permissions that no longer existed.




Looking back, what is most striking is not that the recovery procedures failed. It is that they all failed for exactly the same underlying reason.
An Unexpected Source of Advice
In search of a white hat hacker, we instead found several cybersecurity professionals who generously shared their experience.
None of them claimed they could restore our Business Portfolio. Instead, they helped us better understand how Meta’s automated systems appear to classify and process recovery requests.
One suggestion proved particularly useful. Rather than describing the incident as a “hacked Facebook page,” they advised consistently using Meta’s own terminology: “compromised Business Portfolio.” Their experience suggested that AI-driven support systems often rely on specific vocabulary to determine how a case is routed.
That observation led to a broader realization. As artificial intelligence assumes a greater role in customer support, a new kind of professional expertise may emerge. Just as organizations once hired consultants to improve management practices or customer communication, businesses may increasingly rely on specialists who understand how to communicate effectively with AI systems, navigate automated decision trees, and recover from AI-mediated administrative failures. Whether that represents progress or simply another layer of bureaucracy remains an open question.
Humor as a Coping Mechanism
By the third week, it had become apparent that persistence alone was not going to produce a different result. Humor became another way of documenting the experience.
The collection of “Mettie” memes that follows was created during the investigation. They are not intended to diminish the seriousness of cybercrime or the challenges facing companies that must provide support at enormous scale. Rather, they record the increasingly surreal experience of interacting with an artificial intelligence that could express sympathy, apologize repeatedly, and acknowledge frustration, yet remain unable to depart from the same circular recovery paths.
Memes from Mettieville (Mettieville is the town the Metaphor Dolls live in)

What We Learned
Several observations emerged from this investigation that may prove useful to other small business owners.
- A compromised Meta Business Portfolio may not interrupt normal posting or audience growth.
- Administrative damage can remain undiscovered for months because the public-facing business continues to operate normally.
- Recovery procedures appear to assume that the administrative relationships inside the Business Portfolio remain intact.
- Terminology might matter when communicating with AI-assisted support systems, although it didn’t help us resolve our problem in the end. It did help us start at the right place, but we ended up without resolution.
- Maintaining detailed notes, screenshots, and a timeline throughout the recovery process is worthwhile, even if no immediate method exists for submitting that documentation.
Conclusion
I do not believe Meta intentionally designed its recovery systems to disadvantage victims of cybercrime. I do believe this experience illustrates a structural challenge faced by AI-mediated customer support. The attackers only had to succeed once.
Every recovery procedure we encountered assumed that the administrative relationships inside Meta’s systems remained intact. Once those relationships had been altered, every available recovery path depended upon permissions that no longer existed. Our evidence was never reviewed because we never reached a point where the system would accept it.
If this article helps another small business recognize a compromised Meta Business Portfolio sooner, or contributes in some small way to improving future recovery systems, then documenting this experience will have been worthwhile. And I hope that our Metties made you laugh. It is better to laugh then to cry, as they say, especially at a time when injustices pile up and give us much to cry about.





Not Sure Where to Start?
Discover what works best for your body and lifestyle—whether you’re exploring for the first time or coming back for your favorites, we’ve got you covered.


Comments are closed.