Facebook needs to introduce an additional layer of security to the login, a 'token' that requires access to an app or mobile as well as the password.
there is an option available where any attempted logins from an unrecognised device require a texted passcode. I didn't know this or set it up until after i got hacked, obv.
Oh, that's exactly what I meant. Going to switch this on for my account now. If I can see how to do it...
it works well. claire couldn't log into her fb on my phone without getting a code sent to her own phone first