TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Is there a known phishing attack via Facebook support inbox?

2 点作者 babuskov超过 1 年前
Hi,<p>I have a business facebook account and got a message from them to verify the business. The only link in the email was going to facebook.com&#x2F;support, which I typed into the browser and it really showed a message (supposedly) from the Facebook support team. Basically, asking for company info, most of which can be obtained from public resources online. Here&#x27;s a screenshot:<p>https:&#x2F;&#x2F;bigosaur.com&#x2F;fb&#x2F;request-company-info.png<p>Interesting thing is that they never mention my company name, but I only have one company registered with them, so I guess that was it. So, I replied to that since the info is public anyway.<p>This was about 2 weeks ago. Today, I get a new message claiming that I applied for &quot;Facebook fundraising tools&quot;. Of course, I never applied to that, my company isn&#x27;t even a non-profit, which seems to be a requirement. At first I though someone must have typed in my company name wrong, but there&#x27;s a peculiar thing: Now they did include the company name, and it&#x27;s IN THE SAME THREAD as the first message.<p>The request wants a copy of ID card for &quot;Ana Petrovic&quot;. I have no idea who that is. It&#x27;s a very common name, like Jane Smith in US. Here&#x27;s a screenshot, note the same item_id:<p>https:&#x2F;&#x2F;bigosaur.com&#x2F;fb&#x2F;request-ana-petrovic.png<p>This looks like a phishing attack, but I&#x27;m trying to figure out how it works. How did they manage to initiate the conversation as if Facebook is contacting me? If I send any info back, does the attacker get it?<p>What if I reply, &quot;I don&#x27;t know Ana Petrovic, my name is XXX&quot;, will they then ask for my ID documents?<p>If anyone from Facebook is reading this and needs more info, please feel free to contact me via the email in my HN profile.

1 comment

babuskov超过 1 年前
Update: I looked at various settings, and found an account Ana Petrovic listed as Payment Account Admin. I have removed it now and set 2FA requirement for all the changes.