Thursday, February 3

Phishers Spoof Facebook Security to Hijack Accounts - Softpedia

Phishers have begun spoofing Facebook Security within rogue private messages in order to trick users into exposing their login credentials.

The Facebook Secuity page is used by the social networking site to issue important security-related announcements and advices to users. It has over 3.7 million fans.

Giving its popularity and importance it was bound for cybercriminals to try and exploit it sooner or later.

According to researchers from antivirus vendor Trend Micro, recent phishing attacks do just that via fake private messages sent in the name of the Facebook Security team.

These messages inform people their accounts were accessed from another location and asks them to review their activity immediately.

"Reviewing your activity requires only a few moments. We'll start by asking a few questions to confirm that this is your account. (If we recognize your computer, you will be able to skip this step).

"Please verify your account within 24 hours, if you inore then we will block this account for your security," the fake messages warn.

In addition to Facebook Security's popularity and credibility, the phishers are piggybacking on a legitimate feature introduced by the social networking site last year to protect accounts.

The site allows users to register devices they commonly use to log in with and opt to be alerted when someone attempts to authenticate from a device that isn't on the list.

The rogue private messages generated by this phishing attack advertise an URL that takes users to a fake login page asking them for both their Facebook and email login credentials.

Security researchers note that the fake profiles used to send the phishing messages use the Facebook Security name written with diacritics.

As always, users are advised to exercise caution when opening links received via email or social networking, regardless if they appear to originate from a legitimate source or not.

Follow the editor on Twitter @lconstantin


View the original article here

Labels: , , , , , ,

Facebook Awarded $360 Million Judgement Against Spammer - Softpedia

Facebook scored another win in its fight against spammers as a federal court awarded the company $360,500,000 in statutory damages from a phisher.

The ruling from US district court judge Jeremy Fogel is against a man named Philip Porembski, who is believed to have hijacked at least 116,000 Facebook accounts.

"Since October 2008, Defendants [Porembski and his company] allegedly have obtained login credentials for at least 116,000 Facebook accounts without authorization, and they have sent more than 7.2 million spam messages to Facebook users.

"According to Facebook, the messages ask recipients to click on a link to a 'phishing' site designed to trick users into divulging their Facebook login information.

"Once users divulge the information, Defendants use it to send spam messages to the users' friends, repeating the cycle.

"In addition, certain spam messages allegedly redirect users to websites that pay Defendants for each visit," the complaint read.

In addition to the huge sum he was ordered to pay, Porembski is also the subject of a permanent injunction which bans him from using Facebook.

"We're pleased with the win, which is just another result in an ongoing enforcement effort," says Facebook, but the amount of scams circulating every day on the social network doesn't leave the impression that scammers are very scared.

Porembski is not the first to have a huge monetary judgement issued against them for spamming on Facebook, nor is his fine the largest.

A Canadian man named Adam Guerbuez was ordered last year by a San Jose court to pay $873,277,200 (or $1,068,928,721 in Canadian dollars) in damages after sending 4 million spam messages.

Guerbuez appealed the sentence in Canda, but the Quebec Superior Court upheld the default judgment issued in the spammer's absence by the US court.

Follow the editor on Twitter @lconstantin


View the original article here

Labels: , , , , , ,