There is definitely a hacker on the loose as this is too much of a pattern. I know exactly how to mitigate this activity from my IT background of more than 20 years.
I change my password every quarter (4 times/year). I follow the password guidelines and ensure I can remember it but others cannot. I wouldn't recommend it being a password from another email, social media platform or the like. I have seen what hackers look for and it starts with how the password is structured and encrypted.
I normally wouldn't say write it down. I will say keep a log of former passwords you use for various purposes and keep it in a good hiding place.
I pick my security questions carefully also. I don't use my mother's maiden name, anything family related, cars, first addresses, etc. All of these can be a paper trail to your accounts.
I also would utilize Facebook security measures in the settings. Two are setting up a unique key and having five trusted people just in case you ever get locked out. A bonus one is requiring authentication in case someone does try to come for your account.
I encourage everyone to stay safe and secure as possible. The very least I recommend is changing that password frequently. That's the most common way a hacker can take over an account and it gives you, the user, more peace of mind.