New phishing attack discovered on Facebook

Cybercriminals have developed a method using real Facebook functions to send fake suspension warnings to business accounts. Kaspersky Security Expert Andrey Kovtun emphasized that links should be carefully scrutinized in cases where users are asked to enter data or make payments.

12punto

Kaspersky has discovered a new phishing attack targeting Facebook business accounts.

According to the statement from Kaspersky, the attack sends deceptive emails threatening account suspension and attempts to gain user trust by using legitimate Facebook infrastructure.

Cybercriminals have developed a method using real Facebook functions to send fake suspension warnings to business accounts.

These emails, which originate from Facebook, contain alarming messages such as, "24 Hours Left to Request a Review. See Why."

PHONE NUMBER AND PASSWORD REQUESTED

When the link in the email is clicked, the user is redirected to a real Facebook page displaying a similar warning. Subsequently, the user is directed to a phishing site disguised with Meta branding, where the time to resolve the issue is reduced from 24 hours to 12 hours.

Finally, the phishing site initially requests harmless information, then proceeds to ask for the account's email, phone number, and password.

Attackers use compromised Facebook accounts to send these notifications. After changing the account name to a threat message and the profile picture to an exclamation mark, they create posts mentioning the targeted business accounts.

Since the delivery is carried out through legitimate Facebook infrastructure, the notifications are guaranteed to reach the targeted recipients.

'USE A BOOKMARK' WARNING

To protect business social media accounts, Kaspersky experts emphasize that users should avoid clicking on links in suspicious emails. They note that if it is necessary to log in to an organization's account, the address should be typed manually or a bookmark should be used.

To protect companies against various threats, Kaspersky experts recommend using solutions from the Kaspersky Next product line, which combines real-time protection, threat visibility, and the research and response capabilities of EDR and XDR for organizations of all sizes and sectors. They highlight that depending on current needs and resources, the most appropriate product tier can be selected, and it is easy to switch to another product if cybersecurity requirements change.

Pointing out the need to invest in cybersecurity courses to keep staff updated with the latest information, experts state that InfoSec professionals can improve staff skills and defend companies against complex attacks with the practice-oriented Kaspersky Expert training.

'CAN MAKE A SIGNIFICANT DIFFERENCE'

In the statement, Kaspersky Security Expert Andrey Kovtun noted that notifications that appear legitimate and come from a trusted source like Facebook can also be deceptive.

Kovtun stated, "It is very important to carefully examine the links you are asked to follow, especially if you are asked to enter data or make a payment. This can make a significant difference in protecting your business accounts from phishing attacks."