Thousands of fake Facebook profiles could be trying to steal your data

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

Experts have warned of an ongoing cybercriminal campaign leveraging thousands of fake Facebook accounts and phishing pages in an attempt to obtain login data to financial service platform accounts belonging to public figures, celebrities, businesses, and sports teams.

Cybersecurity researchers from Group-IB’s Digital Risk Protection (DRP) team claim to have identified more than 3,200 fake Facebook accounts, some of which are impersonating Facebook and its parent company, Meta. 

Through these accounts, the attackers would target legitimate users of the social platform to try and get them to visit fraudulent Facebook login pages.

Targeting the English-speaking community

There, they’d get them to enter their login credentials, and effectively grant them access to their accounts. The premise is that many people use the same username/password combination across a wide variety of accounts and that their Facebook login credentials might work on more serious platforms, such as financial services. 

While the campaign is active in more than 20 languages, Group-IB experts are saying, the majority of the profiles impersonating Meta are speaking English. 

“The scammers impersonate Meta, Facebook’s parent company, in their public posts and on any of their more than 220 phishing sites,” Group-IB researchers Sharef Hlal and Karam Chatra wrote. 

“They appropriate Meta and Facebook’s official logos on their social media profiles and phishing web pages to make them appear legitimate and trustworthy in the eyes of users. These fake profiles have nothing to do with Facebook, and they are frequently taken down quickly by the social network.”

Phishing, especially when paired with identity theft, is a major threat to the online security of both consumers, and businesses. It’s vital IT teams educate their employees on how to spot fake accounts and fake login pages. The easiest way to spot a phishing page is in the address bar - if the address isn’t facebook.com - it’s most likely a scam. 

Via: Infosecurity Magazine

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Hook on Keyboard
Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection