The phishers set up a spoofed Facebook page offering an app that purportedly protects Facebook accounts from getting hacked:
Unfortunately for those who fall for the "certified by Facebook" sign, the fake Facebook stock certificate image and the "insert confirmation code" trick, the Facebook username and password they submit to the site get sent directly to the scammers.
The victims are left with a notice that their Facebook account will be secure in 24 hours time and by the time they begin to think that there might be something wrong with the whole deal, the phishers have already hijacked their accounts or harvested information from it.
Reading our newsletter every Monday will keep you up-to-date with security news.
Receive a daily digest of the latest security news.