Security researchers at vpnMentor have discovered an exposed database ElasticSearch containing a file with more than 100,000 compromised accounts Facebook. The file was being used by cybercriminals as part of a global hacking campaign against users of the social media platform.

“We discovered the scam (hacking campaign and compromised accounts) through an unsecured database, which the scammers use to store data belonging to 100,000 of their victims,” the researchers said in their report.
According to researchers, criminals tricked users Facebook credentials account through a toolthat supposedly revealed who visited their profiles.
The scammers used the stolen credentials to log into victims' Facebook accounts and make spam comments on posts. All of these comments eventually led to a fake Bitcoin trading platform, where users were asked to deposit at least €250.
“By using links that led to fake sites , the scammers were attempting to bypass Facebook’s fraud detection tools,” the researchers said. “If the compromised accounts posted the same Bitcoin scam links over and over again, they would be quickly blocked by the social networking platform.”
The data in the exposed database of hacked Facebook accounts includes emails, names, and phone numbers. These details belong to people who had registered on a fake Bitcoin trading site.
The specialists discovered, also, dozens of domains that the scammers used in this campaign.
Researchers initially compromised the Facebook accounts) had access to the exposed database.
The file size was over 5.5 GB. The database was exposed from June to September. According to experts, at least 100,000 users Facebook

The researchers informed the social network of their discovery, after confirming that the database was real.
A day after the discovery, the database was likely subjected to a Meow attack, which wiped out all of its data. Since July, security experts have identified dozens of unprotected Elasticsearch and MongoDB databases that have inexplicably disappeared from criminals in a campaign known as the Meow attack.
"If you are a Facebook user and believe you have fallen victim to this scam, change your credentials immediately," the researchers say.
“Additionally, if you use your Facebook password on other accounts, change it there as well to prevent a possible intrusion. We recommend using a password generator to create unique and strong passwords for every account you have“.
Source: Securityaffairs.co
