Friend of mine who uses FB for her business had her personal account hacked. They somehow got the business account, too. Friend did NOT have two factor authentication enabled. The hackers did enable it.
So for any account that has the feature - social media, banking, shopping, etc.- enable the feature.