New Phishing Scam Spreading Via Facebook Chat

-Phishing Chat Screenshot-Hackers and spammers have been using relatively similar tactics over the past few months to compromise Facebook user accounts. The most recent scam spreading on Facebook involves the use of hijacked user accounts for sending out chat messages with links to the standard Facebook phishing page. When the user clicks the link, they are sent to a fake Facebook login page and then redirected to the actual Facebook after their email and password has been stolen.

The system then automatically logs in with the user’s account and spams all their friends via chat. This form of phishing scam utilizes automated robots to perform these tasks on a large level. Facebook is known for aggressively pursuing phishers, scammers, and hackers. However once in a while new security vulnerabilities appear on Facebook. This is the latest one of those.

My guess is that Facebook will have this new security issue resolved relatively quickly as the offending site will be blocked and Facebook will set up a filter to remove the chat message. The chat message that we received stated: “ROFL this you?! http://3.ly/mZQ”. Had I not known that this is a standard scam, I could have easily been duped.

There’s no telling how many users have had their accounts compromised in this latest attack but if you want to protect yourself, make sure not to click on any questionable links sent by your friends via chat.

  Tags:,



Recommended Articles


Inside Social Apps 2012 is Less Than Two Weeks Away

Inside Social Apps, held on February 8-9 in San Francisco, is less than two weeks away. This is the third conference on the future of monetization on social and mobile platforms. Leaders from the industry will share their views on today's most formidable challenges affecting social and mobile apps and games in 2012. Inside Social Apps conferences sell out in advance, so take advantage of early registration pricing. Early bird rates end on February 1, so register today.

7 Comments »

  1. Thanks for the heads up Nick, Facebook is a breeding ground for this stuff because too many people simply click anything in front of them.

    Comment by Darrell — December 4, 2009 @ 8:54 am

  2. Nick

    It Got me! Thanks for giving an explanation..

    Comment by Bruce Christensen — December 4, 2009 @ 9:00 am

  3. Most typical users will click on these links without thinking… Even experienced tech heads might fall for it.

    I for one don't love the huge growth in the number of URL shorteners, for exactly this reason. You can hide some pretty malicious links in them.

    Users of Firefox should check out the Bit.ly Preview Extension. It pops up a small brown box over http://bit.ly URLs, showing the actual URL that has been shortened. I imagine other URL shorteners may have their own extensions, or maybe not.

    Seems like previewing and checking out shortened URLs should be a function of the browser, or possibly security apps.

    Comment by Brian Honey — December 4, 2009 @ 9:53 am

  4. ok, so was phished or whatever… what do i do to fix the problem… like clear myaccount or something? reset it? any feedback would be appreciated.

    Comment by ricky Shub — December 4, 2009 @ 10:21 am

  5. Such indirect, vague messages are stupid. I'd never respond to them. People should change their passwords once in a while

    Comment by l — December 4, 2009 @ 8:12 pm

  6. Firefox also has another add-on that will show you a preview of all links so you can check all of the links your friends post before you click them, the Add-On is called Cool Previews. Check it out :D

    Comment by Santos Salinas — December 5, 2009 @ 1:24 pm

  7. Thank you,

    I have already gotten multiple posts on my wall about

    "seen this funny ass vid of you?"

    "something about tonix or something"

    AND THEY'RE ALL THE SAME LINK

    i fell for it once, but thanks to firefox, it reported it as web forgery :D

    Comment by John Kane — December 6, 2009 @ 7:27 am

RSS feed for comments on this post. TrackBack URL

Leave a comment

Send us a Tip

tips@allfacebook.com
[Inside Social Apps 2012]
[AllFacebook Stats: Facebook Analytics for Your Business]
[How can Facebook change your business?]

Upcoming Events

Inside Social Apps

February 8-9, 2012 | San Francisco

Inside Social Apps

Developing & monetizing on social & mobile platforms

Social Gaming Summit

23-24 May, 2012 | Berlin

Social Gaming Summit

Where Gaming Meets the Social Web

AllFacebook Marketing Conference

June 28-29, 2012 | San Francisco

AllFacebook Marketing Conference

Your how-to guide for Facebook marketing.