A widespread Facebook scam campaign with the message: “ I can’t believe he’s gone. I’ll miss him so much ,” leads unsuspecting users to a website that steals their account credentials
See also: Facebook Messenger: You can play multiplayer games during video calls

This phishing attack is ongoing and widespread on Facebook through friends' compromised accounts, as perpetrators create a massive army of stolen accounts to use in further scams on the platform .
As the posts come from hacked accounts of friends, they appear more convincing and trustworthy, causing many to fall victim to the scam.
The scam began about a year ago as Facebook struggled to block the posts, which continues to this day. However, when new posts, Facebook disables the Facebook.com redirect link in the post so that they no longer work.
The scam Facebook posts come in two forms: one simply states “I can’t believe he’s gone. I’ll miss him so much,” and contains a Facebook redirect link.
By clicking on the link from the Facebook mobile app ,visitors will be directed to a fake news website called “NewsAmericaVideos,” which asks them to enter their Facebook credentials to verify their identity and watch the video.
To convince a visitor to enter their password, they display a distorted video in the background, which is simply an image taken from Discord. If you enter your credentials on Facebook, the malicious actors will steal them and the site will redirect you to Google.
See also: Facebook: New features including Reels
Even though it is not known for what purpose the stolen credentials are used, the actors are likely using them further to promote the same scams through the hacked accounts.

Visiting these pages from a computer results in different behavior, with the websites redirecting users to Google or other scams promoting VPN, browser add-ons, or affiliate pages.
Since this phishing attack does not attempt to steal two-factor authentication (2FA) data, it is strongly recommended that Facebook users enable two-factor authenticationin order to prevent access to their account in case they fall victim to a phishing scam.
Once enabled, Facebook will ask you to enter a unique one-time code each time your credentials are used to log into the site from an unknown location. Since only you will have access to these codes, even if your identity is stolen, they cannot log in.
For greater security, when enabling two-factor authentication on Facebook, use an authentication app instead of SMS messages, as your phone number can be stolen in SIM swap attacks.
See also: Ducktail hacking group targets Facebook Business Accounts with malvertising
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What security strategies can someone use to avoid phishing posts on Facebook?
First, it is important to stay informed about the latest phishing techniques used by attackers. This may include recognizing the signs of a phishing post, such as spelling errors and suspicious URL addresses.
Second, you should always check the source of the post. If the post appears to come from a friend, but the writing or content seems unusual, it may be a scam.
Third, you should be careful with common phishing schemes, such as posts that ask you to enter your login credentials or your credit card information.
Finally, you need to configure your Facebook security settings to protect yourself. This may include setting notifications for suspicious activity, enabling two-factor authentication, and limiting access to your profile.
Source: bleepingcomputer
