Hacker Use Fake Facebook Landing Page To Steal 1 Million Facebook Account Credentials

Share post:

A fake Facebook landing page was used by an attacker to steal one million Facebook login credentials over a period of just four months.

According to anti-phishing firm PIXM, the fake Facebook login portal was used to trick unsuspecting users into entering their account details to steal their data.

The fake landing page was modified from Facebook’s legitimate URL, and the fake portal code also contained a link to a traffic monitoring application that allowed the anti-phishing company to view the tracking metrics.

“People often underestimate the value of their social media accounts, failing to enable MFA and otherwise protect their accounts from cybercriminals. Unfortunately, when bad actors take over an account, it is often used to attack their own friends and family. Through the use of a real account that has been compromised, bad actors use the trust inherent in a known connection to trick people into taking actions or risks they normally would not,” said Erich Kron, security awareness advocate at KnowBe4.

To protect against this flaw, users are advised to avoid clicking on links that appear to be fake or illegitimate. They are also advised to use multi-factor authentication.

The sources for this piece include an article in TechRepublic.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways