This are the most popular ways that hackers are using to penetrate and hijack peoples facebook account and use it for illlegal things.
1. BruteForce Attack
Any password can be cracked easily using Brute-force attack. Brute-force attacks are series of techniques that try every possible combinations of numbers, letters and special characters until the right password is match.
Brute-force attacks usually take a very long time depending upon the complexity of the password. The time required to crack the password is determined by the complexity of the password and the processing speed of the computer.
2. Social Engineering

According to Wikipedia : Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information.
A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional “con” in that it is often one of many steps in a more complex fraud scheme.
3. Rats And Keyloggers
4. Phishing
5. Rainbow Table
6. Guessing