TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Meta is using my 2FA to call and sell me

317 pointsby codyZover 2 years ago
I run a couple of businesses with ad accounts connected to my personal account.<p>I received multiple calls this morning on my personal cell that&#x27;s used for 2FA for my personal FB account. All of them, they were pitching me ads to buy for my business accounts.<p>None of my business accounts have my personal cell on them.<p>Edit: Now my personal email connected is getting emails to purchase business ads...

22 comments

cmatthiasover 2 years ago
If you are in the USA, then what you received are unsolicited marketing phone calls under the TCPA, a law which allows you to personally collect up to $1500 per violation of the law or associated regulations, per phone call that you received. If your personal phone is on the federal &quot;Do Not Call&quot; registry, it&#x27;s possible that there are at least two violations of the law per phone call you received.<p>I would suggest sending a demand letter to Meta&#x27;s legal department offering to settle for somewhat less than $1500 per violation. Here&#x27;s an example: <a href="https:&#x2F;&#x2F;www.junkfax.org&#x2F;w&#x2F;images&#x2F;0&#x2F;0b&#x2F;SampleDemandLetter.pdf" rel="nofollow">https:&#x2F;&#x2F;www.junkfax.org&#x2F;w&#x2F;images&#x2F;0&#x2F;0b&#x2F;SampleDemandLetter.pdf</a><p>If they ignore you, be prepared to file a local case in small claims court (which you can do yourself without an attorney). The court can force them to pay you if you present evidence of the calls and the law(s) or regulations that were broken.<p>Disclaimer: I am not a laywer and this is not legal advice, but I have collected money from TCPA legal settlements in the past, each without needing to go to court.
评论 #33347756 未加载
评论 #33347190 未加载
评论 #33347375 未加载
评论 #33348516 未加载
crazygringoover 2 years ago
Just to be clear...<p>You&#x27;re <i>absolutely sure</i>, 100%, this is Meta employees themselves calling you? And Meta sending you e-mails?<p>Not spammers, of which there are many, and they get your contact info from all sorts of places? And which often lead you to believe they&#x27;re Meta when they&#x27;re really just scamming you or trying to sell ad placement consulting&#x2F;optimization services?<p>Because with &quot;multiple&quot; calls and emails... this sounds like 3rd-party spammers, not something Meta does. And while Meta has been loose in the past with walling off information internally (to put it mildly...), it&#x27;s not like they sell your contact info to spammers or anything (simply because it&#x27;s not worth the effort, the money&#x27;s way too small for a company of their size). Third-party spammers, on the other hand, will get your personal info from anywhere and everywhere.<p>For you to make a credible claim that Meta is using your 2FA contact info for marketing, you&#x27;ve really got to be sure that it&#x27;s 1) actually Meta contacting you and 2) that they got your phone number specifically from 2FA and not just from looking it up publicly the way salespeople do.
评论 #33351742 未加载
gamegoblinover 2 years ago
I have a feeling that Meta has some kind of internal system for slurping up everyone&#x27;s contact info, and that some kind of bugs&#x2F;criteria occasionally cross some streams.<p>Meta recruiting somehow got a hold of my name@amazon.com employer email -- which I have never posted publicly -- and started sending me recruitment emails to my work email. This struck me as <i>incredibly</i> unprofessional, though I understand it&#x27;s almost certainly an automated system doing it.<p>I still don&#x27;t know how they got the email address (though I guess it&#x27;s just lastname+first initial, so they could have guessed?). I may have DM&#x27;d it to someone in a FB messenger chat? Maybe I used it in an &quot;work email&quot; field during sign up for some industry conference whose data later got hacked? A colleague accidentally merged their work&#x2F;personal contact list and uploaded it somewhere? Who knows.
评论 #33347837 未加载
评论 #33348748 未加载
评论 #33347245 未加载
评论 #33347977 未加载
评论 #33348380 未加载
评论 #33347236 未加载
transcriptaseover 2 years ago
So meta engineers saw all those headlines about Twitter misusing 2FA phone numbers and instead of making sure it didn’t happen to them, kept them available to employees to “accidentally” use as well.<p>Oopsie daisy! Tee hee, it was an honest mistake because ${team} didn’t know they weren’t supposed to!
评论 #33347373 未加载
评论 #33347367 未加载
toomuchtodoover 2 years ago
<a href="https:&#x2F;&#x2F;reportfraud.ftc.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;reportfraud.ftc.gov&#x2F;</a>
评论 #33347080 未加载
nicolashahnover 2 years ago
It&#x27;s more likely that you gave your phone number out somewhere more sketchy. The personal email thing sounds like straight fraud.<p>As someone who works for Meta and and sees all the privacy trainings and the hoops you have to jump through to do anything with user data anymore at this company, someone is definitely getting fired for this if it was indeed Meta&#x27;s fault and intentional.
celestialcheeseover 2 years ago
Facebook is the absolute worst with this, Google second.<p>We spend &gt;$10m on ads annually on FB, yet haven&#x27;t had a dedicated account rep since 2019.<p>Instead, they farm out &quot;account marketing specialists&quot; who pitch you on giving up more control to FB algo and generally have significantly less insight and experience with FB ads than the people they are calling.<p>One week last summer, I received 8 calls in a single day from different FB marking reps. I think they had some kind of call queue system based on the number of ad accounts, instead of on &quot;Business manager&quot; accounts, but it took a lot of firmly saying &quot;Remove me from this list&quot; and accusing them of phishing to get it to stop.<p>I just assumed I gave my cell to FB at some point, never thought of 2FA.
评论 #33348043 未加载
useaover 2 years ago
Vote for candidates that support stronger consumer protection and data privacy laws. Do not give your personal information to companies that do not directly need it for the service you&#x27;re engaging in. Delete your facebook accounts yesterday.<p>Services that require a phone number like twitter, discord, blizzard, signal, twitch, etc are giving you a heads up that they&#x27;re abusive and will work against your interests. Stay far away.
rkagererover 2 years ago
This is why I really hate how the big players are gating user access through phone numbers and smartphones.<p>Even government portals are copying the tactic. (I didn&#x27;t agree to a draconian ToS recently for an online fee filing, and it took months and hours on the phone just to make a simple VISA payment).
ridgered4over 2 years ago
Facebook already used 2FA gathered numbers for ads in the past so I&#x27;m not sure why there is so much doubt in this story.<p><a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2018&#x2F;09&#x2F;27&#x2F;yes-facebook-is-using-your-2fa-phone-number-to-target-you-with-ads&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2018&#x2F;09&#x2F;27&#x2F;yes-facebook-is-using-your...</a>
评论 #33360785 未加载
rodricover 2 years ago
You should probably use an app like Aegis (Android) or Raivo (iOS) for two-factor authentication rather than your personal phone number.
评论 #33347413 未加载
devindotcomover 2 years ago
Wouldn&#x27;t be the first time this happened, but it&#x27;s hard to verify this without any hard data. Follow up with Meta via your business account and ask them to explain or you&#x27;ll go the FTC and press (me).
kleinschover 2 years ago
They already paid a multi billion dollar fine for misusing 2FA phone numbers and have insane process to prevent this specific scenario. Way more likely that OP put their phone number somewhere else.
btillyover 2 years ago
Their year over year revenue fell in June. They are reporting revenue today after the close of trading, and the stock is currently down 5%: <a href="https:&#x2F;&#x2F;finance.yahoo.com&#x2F;quote&#x2F;META&#x2F;" rel="nofollow">https:&#x2F;&#x2F;finance.yahoo.com&#x2F;quote&#x2F;META&#x2F;</a>?<p>So it may well be that they have bad news and are under pressure to say that they are trying to improve revenue.
rsyncover 2 years ago
Don&#x27;t use your personal mobile phone for 2FA.<p>Use a &quot;2FA Mule&quot; that is only for that purpose:<p><a href="https:&#x2F;&#x2F;kozubik.com&#x2F;items&#x2F;2famule&#x2F;" rel="nofollow">https:&#x2F;&#x2F;kozubik.com&#x2F;items&#x2F;2famule&#x2F;</a><p>I have the ringers silenced on mine so I wouldn&#x27;t know if they got any spam calls ... and I assume they do ...
评论 #33348241 未加载
pengaruover 2 years ago
I have a bridge to sell anyone who actually believed companies requesting your phone number for &quot;security&quot; purposes wouldn&#x27;t make that information available to the rest of their business activities.
persedesover 2 years ago
Did not get a sales pitch, but added my phone number as 2FA a couple days ago and started receiving FB notifications via text msg. Despite having muted all FB notifications years ago.
ardit33over 2 years ago
Sounds like alarmist reaction without proper evidence.<p>How do you even know it is Meta? Anybody can get your phone #, and it is super easy to get spam.
评论 #33351756 未加载
Invictus0over 2 years ago
Your anecdote isn&#x27;t really evidence of anything and I&#x27;m skeptical that this is the case.
评论 #33347544 未加载
评论 #33351760 未加载
ohmanjjjover 2 years ago
Gotta pump up the numbers before market close and earnings
ok_dadover 2 years ago
Didn’t Twitter just get hit with fines for this?
评论 #33347306 未加载
datalopersover 2 years ago
Please stop using phones&#x2F;sms as 2FA.
评论 #33347843 未加载