{"id":24660,"date":"2024-06-11T02:30:10","date_gmt":"2024-06-11T10:30:10","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/06\/11\/news-18390\/"},"modified":"2024-06-11T02:30:10","modified_gmt":"2024-06-11T10:30:10","slug":"news-18390","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/06\/11\/news-18390\/","title":{"rendered":"Notifications from FB and theft of business account passwords"},"content":{"rendered":"<p><strong>Credit to Author: Andrey Kovtun| Date: Tue, 11 Jun 2024 10:29:47 +0000<\/strong><\/p>\n<p>Cybercriminals in the password theft business are constantly coming up with new ways to deliver phishing emails. Now they&#8217;ve learned to use a legitimate Facebook mechanism to send fake notifications threatening to block Facebook business accounts. We explore how the scheme works, what to pay attention to, and what measures to take to protect business accounts on social networks.<\/p>\n<h2>Anatomy of the phishing attack on Facebook business accounts<\/h2>\n<p>It all starts with a message sent by the social network itself to the email address linked to the victim&#8217;s Facebook business account. Inside is a menacing icon with an exclamation mark, and an even more menacing text: &#8220;24 Hours Left To Request Review. See Why.&#8221;<\/p>\n<div id=\"attachment_51448\" style=\"width: 1290px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11060803\/facebook-scam-24-hours-are-left-ro-request-review-see-why-1.jpg\"><img fetchpriority=\"high\" decoding=\"async\" aria-describedby=\"caption-attachment-51448\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11060803\/facebook-scam-24-hours-are-left-ro-request-review-see-why-1.jpg\" alt=\"Email warning that a Facebook business account could be blocked\" width=\"1280\" height=\"628\" class=\"size-full wp-image-51448\" \/><\/a><\/p>\n<p id=\"caption-attachment-51448\" class=\"wp-caption-text\">Email with a fake warning about account problems, sent by Facebook itself<\/p>\n<\/div>\n<p>Added to this are other words which, combined with the above text, look odd. But a manager responsible for Facebook may, in haste or in panic, fail to spot these irregularities and follow the link by clicking the button in the email or manually open Facebook in a browser and check for the notifications.<\/p>\n<p>Either way, they&#8217;ll end up on Facebook. After all, the email is real, so the buttons really do point to the social network&#8217;s site. A notification is waiting there \u2014 with the now familiar orange icon and same threatening words: &#8220;24 Hours Left To Request Review. See Why.&#8221;<\/p>\n<div id=\"attachment_51449\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11060910\/facebook-scam-24-hours-are-left-ro-request-review-see-why-2.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51449\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11060910\/facebook-scam-24-hours-are-left-ro-request-review-see-why-2.jpg\" alt=\"Phishing notification in Facebook\" width=\"690\" height=\"389\" class=\"size-full wp-image-51449\" \/><\/a><\/p>\n<p id=\"caption-attachment-51449\" class=\"wp-caption-text\">Phishing notification informing the victim their account will be blocked for non-compliance with the terms of service<\/p>\n<\/div>\n<p>The notification contains more details, alleging that the account and page are to be blocked because someone complained about their non-compliance with the terms of service. The victim is then prompted to follow a link to dispute the decision to block their account.<\/p>\n<p>If they do, a website opens (this time, bearing the Meta logo, not Facebook) with roughly the same message as in the notification, but the time granted to resolve the issue has been halved to 12 hours. We suspect that scammers use the Meta logo this time because they try similar schemes on other Meta platforms \u2014 we found at least one &#8220;location&#8221; on Instagram with the same name: &#8220;24 Hours Left To Request Review. See Why.&#8221;<\/p>\n<div id=\"attachment_51450\" style=\"width: 1430px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061002\/facebook-scam-24-hours-are-left-ro-request-review-see-why-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51450\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061002\/facebook-scam-24-hours-are-left-ro-request-review-see-why-3.jpg\" alt=\"Phishing page for appealing the account block\" width=\"1420\" height=\"918\" class=\"size-full wp-image-51450\" \/><\/a><\/p>\n<p id=\"caption-attachment-51450\" class=\"wp-caption-text\">On a phishing page outside Facebook, the victim is prompted to appeal the block<\/p>\n<\/div>\n<p>After clicking the Start button, through a series of redirects the visitor lands on a page with a form asking initially for relatively innocent data: page name, first and last names, phone number, date of birth.<\/p>\n<div id=\"attachment_51451\" style=\"width: 1287px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061107\/facebook-scam-24-hours-are-left-ro-request-review-see-why-4.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51451\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061107\/facebook-scam-24-hours-are-left-ro-request-review-see-why-4.jpg\" alt=\"Phishing form asking for personal data\" width=\"1277\" height=\"918\" class=\"size-full wp-image-51451\" \/><\/a><\/p>\n<p id=\"caption-attachment-51451\" class=\"wp-caption-text\">] The second screen asks the victim to enter certain personal data<\/p>\n<\/div>\n<p>It&#8217;s the next screen where things get juicy: here you need to enter the email address or phone number linked to your Facebook account and your password. As you might guess, it&#8217;s this data that the attackers are after.<\/p>\n<div id=\"attachment_51452\" style=\"width: 1313px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061203\/facebook-scam-24-hours-are-left-ro-request-review-see-why-5.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51452\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061203\/facebook-scam-24-hours-are-left-ro-request-review-see-why-5.jpg\" alt=\"Phishing form for entering Facebook credentials\" width=\"1303\" height=\"912\" class=\"size-full wp-image-51452\" \/><\/a><\/p>\n<p id=\"caption-attachment-51452\" class=\"wp-caption-text\">The attackers don&#8217;t waste any time in requesting your Facebook account credentials<\/p>\n<\/div>\n<h2>How the phishing scheme exploits real Facebook infrastructure<\/h2>\n<p>Now let&#8217;s see how threat actors get Facebook to send phishing notifications on their behalf. They do so by using hijacked Facebook accounts. The account name is changed straight away to the most troubling title: &#8220;24 Hours Left To Request Review. See Why.&#8221; They also change the profile pic so that the preview shows an orange icon with the exclamation mark already familiar to us from the email and notification.<\/p>\n<div id=\"attachment_51453\" style=\"width: 478px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061256\/facebook-scam-24-hours-are-left-ro-request-review-see-why-6.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51453\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061256\/facebook-scam-24-hours-are-left-ro-request-review-see-why-6.jpg\" alt=\"Hijacked Facebook account used to send phishing notifications\" width=\"468\" height=\"1119\" class=\"size-full wp-image-51453\" \/><\/a><\/p>\n<p id=\"caption-attachment-51453\" class=\"wp-caption-text\">Attackers change the name and profile picture of the hijacked Facebook account<\/p>\n<\/div>\n<p>That done, the message about the account block is posted from the account. At the bottom of this message, a mention of the victim&#8217;s page appears after a few dozen empty lines. By default it&#8217;s hidden, but on clicking the &#8220;See more&#8221; link in the phishing post, the mention becomes visible.<\/p>\n<div id=\"attachment_51454\" style=\"width: 1890px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061351\/facebook-scam-24-hours-are-left-ro-request-review-see-why-7.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51454\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061351\/facebook-scam-24-hours-are-left-ro-request-review-see-why-7.jpg\" alt=\"Cybercriminal posts that mention company accounts \" width=\"1880\" height=\"1128\" class=\"size-full wp-image-51454\" \/><\/a><\/p>\n<p id=\"caption-attachment-51454\" class=\"wp-caption-text\">The trick is the hard-to-spot mention of the targeted Facebook business account at the bottom of the post<\/p>\n<\/div>\n<p>Threat actors post such messages from the hijacked account in bulk all at once, each of which mentions one of the target Facebook business accounts.<\/p>\n<div id=\"attachment_51455\" style=\"width: 1290px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061438\/facebook-scam-24-hours-are-left-ro-request-review-see-why-8.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51455\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061438\/facebook-scam-24-hours-are-left-ro-request-review-see-why-8.jpg\" alt=\"Bulk publication of posts mentioning a hijacked Facebook account\" width=\"1280\" height=\"1024\" class=\"size-full wp-image-51455\" \/><\/a><\/p>\n<p id=\"caption-attachment-51455\" class=\"wp-caption-text\">Hijacked accounts generate a slew of posts, each of which mentions the account of a targeted organization<\/p>\n<\/div>\n<p>As a result, Facebook diligently sends notifications to all accounts mentioned in these posts, both within the social network itself and to the email addresses linked to these accounts. And because delivery is via the actual Facebook infrastructure, these notifications are guaranteed to reach their intended recipients.<\/p>\n<h2>How to protect business social media accounts from hijacking<\/h2>\n<p>We should note that phishing isn&#8217;t the only threat to business accounts. There exists an entire class of malware specially created <a href=\"https:\/\/www.kaspersky.com\/blog\/how-criminals-can-get-your-password\/46716\/\" target=\"_blank\" rel=\"noopener\">for password theft<\/a>; such programs are known as password stealers. For this same purpose, attackers can also use browser extensions \u2014 see our recent post about <a href=\"https:\/\/www.kaspersky.com\/blog\/ducktail-steals-facebook-business-accounts\/49845\/\" target=\"_blank\" rel=\"noopener\">their use in hijacking Facebook business accounts<\/a>.<\/p>\n<p>Here&#8217;s what we recommend for protecting the social media accounts of your business:<\/p>\n<ul>\n<li>Always use <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-two-factor-authentication\/48289\/\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a> wherever possible.<\/li>\n<li>Pay close attention to notifications about suspicious login attempts.<\/li>\n<li>Make sure all your passwords are both strong and unique. To generate and store them, it&#8217;s best to use a <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\">password manager<\/a>.<\/li>\n<li>Carefully check the addresses of pages asking for account credentials: if there&#8217;s even the slightest suspicion that a site is fake, do not enter your password.<\/li>\n<li>Equip all work devices with <a href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\">reliable protection<\/a> that will warn of danger ahead of time and block the actions of both malware and browser extensions.<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/facebook-scam-24-hours-are-left-ro-request-review-see-why\/51447\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/11061952\/facebook-scam-24-hours-are-left-ro-request-review-see-why-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Andrey Kovtun| Date: Tue, 11 Jun 2024 10:29:47 +0000<\/strong><\/p>\n<p>Through a security hole attackers get the Facebook, to send phishing emails with fake notifications threatening to block business accounts.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[21009,14980,1001,11222,12177,3589,10602,3924,12321,10448,10438],"class_list":["post-24660","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-account-hijacking","tag-accounts","tag-business","tag-email","tag-enterprise","tag-facebook","tag-passwords","tag-phishing","tag-smb","tag-social-networks","tag-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24660"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24660\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24660"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}