Bogus Facebook page harvests login details

By

Fraudulent URL tricks users into revealing credentials.

Security firm PandaLabs is warning of a new spoofed Facebook page that has the ability to steal user passwords and other login details.


Users of the social networking site are urged to watch out for rogue emails containing links to the bogus page, which can give attackers access to their account.

If the user does enter their details, the page redirects to an error message claiming an "incorrect email/password combination".

"This fraudulent URL is probably being spread through emails and through search engine optimisation techniques," said Luis Corrons, technical director of PandaLabs.

"In any event, once cyber-crooks have the user's details, they can take any action from the account, including publishing spam comments with malicious links, sending messages to contacts etc."

The firm has published a series of screenshots on Flickr that illustrate the process. Anyone who believes that they may have fallen victim to the scam should change their login details immediately. Other users should be on the look out for certain clues, such as malformed URLs in emails, or fake web sites with similar addresses.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

NSW Police to embark on $126m IT overhaul

NSW Police to embark on $126m IT overhaul

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

WestJet probes cyber security incident

WestJet probes cyber security incident

Log In

  |  Forgot your password?