TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Is there a known phishing attack via Facebook support inbox?

2 pointsby babuskovover 1 year ago
Hi,<p>I have a business facebook account and got a message from them to verify the business. The only link in the email was going to facebook.com&#x2F;support, which I typed into the browser and it really showed a message (supposedly) from the Facebook support team. Basically, asking for company info, most of which can be obtained from public resources online. Here&#x27;s a screenshot:<p>https:&#x2F;&#x2F;bigosaur.com&#x2F;fb&#x2F;request-company-info.png<p>Interesting thing is that they never mention my company name, but I only have one company registered with them, so I guess that was it. So, I replied to that since the info is public anyway.<p>This was about 2 weeks ago. Today, I get a new message claiming that I applied for &quot;Facebook fundraising tools&quot;. Of course, I never applied to that, my company isn&#x27;t even a non-profit, which seems to be a requirement. At first I though someone must have typed in my company name wrong, but there&#x27;s a peculiar thing: Now they did include the company name, and it&#x27;s IN THE SAME THREAD as the first message.<p>The request wants a copy of ID card for &quot;Ana Petrovic&quot;. I have no idea who that is. It&#x27;s a very common name, like Jane Smith in US. Here&#x27;s a screenshot, note the same item_id:<p>https:&#x2F;&#x2F;bigosaur.com&#x2F;fb&#x2F;request-ana-petrovic.png<p>This looks like a phishing attack, but I&#x27;m trying to figure out how it works. How did they manage to initiate the conversation as if Facebook is contacting me? If I send any info back, does the attacker get it?<p>What if I reply, &quot;I don&#x27;t know Ana Petrovic, my name is XXX&quot;, will they then ask for my ID documents?<p>If anyone from Facebook is reading this and needs more info, please feel free to contact me via the email in my HN profile.

1 comment

babuskovover 1 year ago
Update: I looked at various settings, and found an account Ana Petrovic listed as Payment Account Admin. I have removed it now and set 2FA requirement for all the changes.