1/ Log in to Facebook, check if the email information matches the account, and check your email password.
2/ Change your Hotmail password, add a recovery email to Hotmail (if you've logged into Hotmail and verified your phone number and email address correctly, you should use an incognito browser and a local network ("home network") to avoid phone security breaches).
Change your email password via this link: https://account.live.com/password/change
Add your recovery email via this link: https://account.live.com/proofs/manage/additional
If your Hotmail account already has a MailKP, just add a new MailKP and wait 30 days. During this time, you can still log in to your email normally.
3/ Change your Facebook password without delay: by recovering your account, click "forgot password" to change to a new password.
4/ For those who plan to nurture their Facebook accounts long-term, you need to add a new email address. Currently, Facebook is restricting access, so you can't delete old emails or change 2FA for new accounts. You need to allow time for browser trust; after 30 days, delete the old email address. If you change your Hotmail password, you don't need to add a new email address.
Note: Facebook is currently returning the old phone number and email address associated with the account. Therefore, spamming or any other activity could easily trigger a phone number connection. Users should nurture trust and then delete the phone number; Facebook will then restore the account.
Steps 2 and 3 are mostly okay, so you don't have to worry about your account being backed out.