Advertisment

New phishing attack on Facebook

author-image
CIOL Bureau
Updated On
New Update

BANGALORE, INDIA: Kaspersky Lab researchers have warned of a new phishing attack on Facebook that uses hijacked accounts to impersonate the site's security team.

Advertisment

Security vendor Kaspersky Lab has reported a new phishing attack on Facebook that uses hijacked accounts to pose as the social network's security team and trick users into divulging credit card numbers.

The latest scam is unique because it doesn't just try to get Facebook users to click on a link to a malicious Web site, David Jacoby, a Kaspersky Lab security expert, reported Friday on the SecureList blog. The attackers also use the stolen information to log into the person's account and swap the profile picture with a Facebook logo and change the name to "Facebook Security."

Advertisment

Once the account is compromised, it is used to send out a message to all contacts, warning them that someone has reported a problem with their accounts and they will be turned off unless re-confirmed by the accountholder. Within the message is a link that takes victims to a Web sited dressed to look very similar to a Facebook page.

Once on the Web site, the cyber criminals ask for name, e-mail, password, Webmail system and password to e-mail.

Advertisment

With this information, the attackers can compromise more Facebook accounts.

After victims have inputted their personal information, they are asked to provide credit card numbers for verification purposes and to purchase "Facebook credits," as needed. "These scams are just getting more popular and we really recommend not giving out personal information, especially not e-mail, password and credit card information over social medias," Jacoby said. The number of compromised accounts as a result of the scam was not known.



tech-news