Facebook remains the preferred target for cybercriminals specializing in stealing social network account credentials. According to Kaspersky Lab statistics, in the first quarter of 2014, fake sites imitating Facebook accounted for 10.85% of all phishing incidents, based on the activation of the Anti-phishing heuristic function in the company's products. Overall, most phishing alerts on the Internet concerned fake Yahoo pages, but Facebook was the main target among social networking sites.
Today, Facebook fraud is a global "business" and attacks against it are carried out in various languages such as English, French, German, Portuguese, Italian, Turkish, Arabic, etc.
Unauthorized access to Facebook accounts or any other social network can be used to spread phishing links or malware. Cybercriminals also use compromised accounts to send spam messages to victims’ contact lists. They also post spam messages on the “walls” of victims’ friends, where they can be seen by other users, or forward messages asking their friends for urgent financial help. Compromised accounts can also be used to gather information about specific individuals. This information is then used during targeted attacks in the future.
Smartphone or tablet users who visit social media sites on their mobile devices are also at risk of having their personal information stolen. The situation is made even worse by the fact that some mobile browsers hide the address bar when opening a website, making it much more difficult for users to spot fake sites.
“Cybercriminals have developed many ways to lure their victims to phishing websites. They send links to phishing websites via email, through social networks, or with banners placed on third-party resources. Fraudsters often lure their victims with promises of “interesting content.” When users follow these links, they are taken to a fake page that contains a specific message, asking them to log in before they can view its content. If users are not suspicious and fill in their details, their data will be immediately sent to cybercriminals,” said Nadezhda Demidova, Web Content Analyst at Kaspersky Lab.
What do experts advise:
· If you receive an email notification from Facebook or a message that your account may be blocked, never enter your information into any form contained in that message. Facebook never asks users to enter their password in an email or send their passwords via email.
· Place your cursor over the link and check if it leads to the official Facebook page. Additionally, you should manually type the Facebook URL into your browser, as cybercriminals have the ability to hide the addresses they take you to.
· After typing in the Facebook URL, check again when the page loads to make sure it's not fake.
· Remember that Facebook uses the HTTPS protocol for data transmission. The absence of a secure connection likely means that you have visited a fake site, even if the URL appears to be correct.
More information is available on the website securelist.com.
Source: kathimerini.gr
