• What is Facebook cloning?
  • How to tell if your Facebook account has been cloned
  • What to do if your Facebook account is cloned
  • How to prevent Facebook cloning
  • Additional security tips for protecting your Facebook account
  • FAQ: Common questions about Facebook cloning
  • What is Facebook cloning?
  • How to tell if your Facebook account has been cloned
  • What to do if your Facebook account is cloned
  • How to prevent Facebook cloning
  • Additional security tips for protecting your Facebook account
  • FAQ: Common questions about Facebook cloning

Is your Facebook account cloned? How to detect it and protect yourself

Featured 29.11.2025 8 mins
Raven Wu
Written by Raven Wu
Ana Jovanovic
Reviewed by Ana Jovanovic
Penka Hristovska
Edited by Penka Hristovska
facebook-cloning

If you’ve suddenly started receiving messages from friends asking whether you created a “new” profile, your Facebook account might have been cloned. Account cloning, when someone copies your photos, name, and basic info to create a fake profile, is a common tactic used for scams and phishing.

Here’s how to tell if it’s happening and what you can do to protect yourself.

What is Facebook cloning?

Facebook cloning occurs when a bad actor creates a fake Facebook account to impersonate you, using whatever public details they can access. This usually includes your name, profile photo, cover photo, and basic bio information, which is enough to make the duplicate look believable at a glance.

Why scammers clone Facebook accounts

There are many reasons someone might clone a Facebook profile, but the primary one is that it’s a low-effort tactic with a high payoff. Cloning requires practically no technical skill. With minimal work, a scammer can build a convincing duplicate and start using it to deceive the people who trust you.

Most of these impersonations are part of a social engineering attack. Because the fake profile looks like it belongs to you, your friends and followers are more likely to engage with it, making it easier for the scammer to manipulate them into revealing personal information, clicking malicious links, or taking other actions that compromise their security. The end goal of such attacks is often to steal personal information for identity theft, spread malware, solicit money, or damage your reputation.

The risks of having your profile cloned

Having your Facebook account cloned can have serious consequences such as:

  • Identity misuse: Impersonators can use the fake profile to request personal information from your contacts, direct them to phishing pages, or gather details that support identity-theft attempts.
  • Financial scams: Attackers can send urgent or emotional messages to your friends and family, hoping to convince someone to send money.
  • Reputation damage: A cloned account can post harmful, misleading, or inappropriate content under your name, creating confusion and potentially harming your relationships or credibility.
  • Malware: By posing as someone familiar, scammers increase the likelihood that the victim’s contacts will click on malicious links or download unsafe files, helping them spread malware or steal information on a wider scale.

Potential consequences of Facebook cloning.

Facebook cloning vs. hacking

Unlike Facebook cloning, Facebook hacking involves gaining unauthorized access to your account. In other words, a malicious actor knows the victim’s email or phone number and password and can freely access the account and even lock out the legitimate owner of the account.

How to tell if your Facebook account has been cloned

Most of the time, you’ll discover that someone has cloned your Facebook account because a friend or family member alerts you. Cloned accounts often try to add your contacts to exploit their trust in you to scam them. So if your contacts ask why you’ve sent them a new friend request, whether you’ve created a second account, or mention you sending them strange links or requests for money, that’s a strong indication that you’re a victim of Facebook account cloning.

If you want to be more proactive, you can search for cloned versions of your Facebook account yourself. First, type your own name into Facebook’s search bar and look for profiles that use your photos or personal details. You can also ask a trusted contact to run the same search. Some cloned profiles block the real person to prevent you from spotting the duplicate.

What to do if your Facebook account is cloned

If you’ve discovered a fake profile pretending to be you, here’s exactly what to do to shut it down fast.

1. Report the fake profile to Facebook

Facebook actively removes accounts that impersonate real people, but they can only act once the profile is flagged. The good news is reporting a fake account is quick and easy. Here’s how:

  1. Go to the profile page of the cloned account and click the three horizontal dots to open the Options menu.Screenshot of a Facebook profile page with the three horizontal dots menu highlighted.
  2. Select Report profile.Facebook profile page with the options menu highlighted.
  3. Select Something about this profile.Facebook menu for reporting a profile.
  4. Click Fake profile.Facebook's "Why are you reporting this profile" window, with the "Fake profile" option highlighted.
  5. On the next page, select Me.Facebook's "Who or what is it pretending to be" window, with the option "Me" highlighted.
  6. Review the report to confirm you’ve picked the right options and select Submit.Facebook's confirmation report window, showing report retails, with a highlighted "Submit" button at the bottom.

Important: If you don’t use Facebook, but someone has created a fake account in your name, you can still report the scam using this contact form.

2. Alert your friends and followers

Let your contacts know about the fake account. Ask them not to accept friend requests, respond to messages from the scammer, or click on any links they send.

3. Document everything for additional protection

Take screenshots of the cloned profile, any messages it has sent, and any reports from your contacts. Keeping a record is useful if you need to escalate the situation to authorities or follow up with Facebook.

How to prevent Facebook cloning

Cloned accounts rely on using your personal information to craft a convincing impersonation. To make it harder for scammers to copy your profile, you can adjust your privacy settings and limit what strangers can see. An easy way to manage this is by using Facebook’s Privacy Checkup.

Here’s how you can access that feature:

  1. Click your profile picture in the top right corner, and select Settings & privacy > Settings.Facebook Settings & privacy menu with Settings highlighted.
  2. Select Privacy Checkup on the sidebar.Facebook Settings & privacy page with Privacy Checkup highlighted.
  3. Select Who can see what you share and follow the on-screen prompts.Facebook Privacy Checkup page with Who can see what you share highlighted.

Limit who can see your profile information and friends

  1. Under Profile Information, you can decide who can see your profile information, including your email address, birthday, and Facebook friends.Facebook's Profile information window under Privacy Checkup.
  2. To protect your privacy, click on each, and select Only Me.Facebook's "Select audience" window, with the "Only me" option highlighted.

Limit who can see your posts and stories

  1. On the next page, under Audience, you can decide who can see your Facebook posts, reels, and stories.Audience windows on Facebook under Privacy Checkup.
  2. To pick an audience, click on each, and choose from Friends, Friends except, or Custom.Alt text: Facebook's "Select audience" window, with the "Friends" and "Friends except" options highlighted.

Disable public search indexing

  1. Go back to the Privacy Checkup page and select How People Can Find You on Facebook.Facebook Privacy Checkup page, with "How can people find you on Facebook" option highlighted.
  2. Fast forward to the Search Engines window and turn off the option that allows search engines to link to your Facebook profile. This reduces how easily attackers can find and target your account.Search Engines window on Facebook, highlighting the "Do you want search engines outside of Facebook to link to your profile."

Additional security tips for protecting your Facebook account

While the following security tips won’t prevent someone from cloning your Facebook profile, they are essential for keeping your actual account safe from hacking and minimizing the risk of falling prey to scams, such as when a friend’s account is cloned and used to trick you.

Set a strong and unique password

Your Facebook password is the first line of defense against unauthorized access. A strong password is one that’s long, unique, and hasn’t been used for any other accounts. Include a mix of letters, numbers, and symbols, and avoid easily guessable information such as birthdays or names. Better yet, use a password manager to automatically create and store strong passwords.

Turn on two-factor authentication (2FA)

2FA adds an extra layer of security to your Facebook account by requiring a second form of verification, such as a code sent to your phone or generated by an authentication app, to log into an account. This means that even if someone manages to obtain your password, they still won’t be able to access your account.

To turn on 2FA on Facebook:

  1. Click your profile picture in the top-right corner, and select Settings & privacy > Settings.Facebook Settings & privacy menu with Settings highlighted.
  2. Click Accounts Centre on the left side of the screen.Facebook Settings & privacy page with Accounts Centre highlighted.
  3. Select Password and security.Facebook Accounts Centre page with Password and security highlighted.
  4. Select Two-factor authentication.Facebook Password and security page with Two-factor authentication highlighted.

Regularly monitor login and session activity

You can review your Facebook activity in the Activity log. This page gives you information such as on which devices your account was accessed. It also records actions like posts, comments, and reactions. Regularly checking this page can help you spot unusual logins or suspicious activity early.

In the event that you do notice a problem, immediately log out of any unfamiliar devices, change your password, and consider enabling 2FA if you haven’t already.

Recognize and avoid phishing messages

Phishing attacks are designed to trick you into revealing personal information, such as your Facebook password or other sensitive data. These messages often appear to come from friends, Facebook itself, or other trusted sources and may include urgent requests, suspicious links, or attachments.

To protect yourself from online impersonation scams like this, always double-check the sender’s details, avoid clicking on links from unknown or unexpected messages, and verify requests directly with the person or organization before taking action.

Can a VPN help you protect your Facebook account?

A virtual private network (VPN) can’t prevent someone from creating a fake profile that impersonates you. However, it can reduce other privacy and security risks.

On unsecured networks, threat actors can set up fake hotspots or use man-in-the-middle techniques to intercept traffic. A VPN encrypts your connection, which reduces the success chance of these attempts.

FAQ: Common questions about Facebook cloning

What’s the difference between a cloned and hacked Facebook account?

A cloned Facebook account is a separate fake profile made to look like the original, while a hacked account is a real account that’s been compromised because someone has obtained the user’s login credentials.

How do I know if someone cloned my Facebook profile?

You’ll often find out because a friend or family member notices suspicious activity or duplicate friend requests. You can also search for duplicate profiles yourself by typing your own name into Facebook’s search bar and looking for profiles that use your photos or personal details.

Can I prevent my Facebook account from being cloned again?

You can reduce the likelihood of Facebook cloning by limiting public access to your personal information and adjusting your Facebook security and privacy settings. For example, use Facebook’s Privacy Checkup to control who can see your posts, photos, and friends list, and avoid sharing sensitive information in public spaces where scammers could use it to create a fake profile.

How do I report a cloned Facebook account?

You can report a fake profile directly on Facebook by going to the profile page of the cloned account, opening the Options menu, and clicking “Report profile.”

Can scammers clone me on Instagram or other platforms, too?

Yes. Account cloning can happen on most social media platforms that allow public profiles, including Instagram, X/Twitter, and LinkedIn.

Can a VPN prevent Facebook cloning?

No, a VPN can’t stop someone from creating a cloned account because cloning relies on publicly available information like your profile picture, name, and basic details, not on hacking your connection. A VPN encrypts your connection, but it can’t prevent someone from copying information you’ve already shared on Facebook or impersonating you with a separate account.

Take the first step to protect yourself online. Try ExpressVPN risk-free.

Get ExpressVPN
Img26
Raven Wu

Raven Wu

Raven Wu is a writer for the ExpressVPN Blog with a passion for technology and cybersecurity. With years of experience covering these topics, he takes pride in delivering informative, well-researched content in a concise and accessible way. In his free time, he enjoys writing stories, playing hard games, and learning about history.

ExpressVPN is proudly supporting

Get Started