Latest news
The two main reasons why scammers are grateful for Facebook's existence are the fact that they can easily access a great number of people in a short period of time, and the fact that victims often end up "endorsing" the scams and by doing so add an aura of legitimacy to them.It's easy to get lulled into a false sense of security, as Facebook often seems like a private and secure part of the Internet where one meets up with friends and family and mostly keeps tabs on their personal matters. But, it's not, and every user would do well to remember it.
Here is a list of the most popular scams lurking on Facebook, often repeated with small modifications, and obviously still successful.
Facebook account-themed scams
An even greater number of scams targets those who aren't satisfied with features offered by the social network and are tricked into believing that there are ways to add functionalities such as the ability to view who checks out their profile more often, view who has deleted or unfollowed them, to see how many hours they spent on Facebook, to post again their first post, to add a Dislike button, to change their Facebook color theme, and even to add a Facebook security app to guard their accounts or to try a Facebook 2013 Demo app.
Next we have the scams that profess that Facebook is giving out something for free: an official Facebook T-shirt or mug to celebrate the social network's birthday, the random $50,000 reward, free Facebook Credits, or even a free mobile recharge.
Lastly, there are scams that try to scare users into doing something because Facebook is closing all accounts, will close theirs because of overpopulation, will start charging users, or the Facebook Security Team will suspend their page.
It's also good to know that Facebook-themed scams - and especially phishing attempts and malware-infection attempts - can often come in the form of fake Facebook notification emails - password change notifications, account cancellation (or deactivation) warnings, offensive comment notices, friend requests, and so on.
Scams that offer free goods from third-parties
Scams that take advantage of news or fake news
Scams that take advantage of the innate curiosity of people
What are the scammers after?
They aim to get some or all of these things:
- Email address and phone number for spamming purposes
- Personal information for identity theft purposes
- Facebook login credentials (username and password) in order to hijack the users' account and spread scams through it
- Users to inadvertently subscribe to pricy mobile services (by hiding the fact in very small print at the end of the page)
- Users to inadvertently allow continuous access to their account to malicious Facebook apps, along with the ability to post things on the users' Timeline in their name
- Users to complete online surveys so that the scammers can get paid for each one
- Users to "Like", "Share" or in any other way inadvertently or knowingly promote a wide array of scams and pages that are set up for the sole reason to spam their followers
- Users to download malware, adware or grayware disguised as YouTube plugins, video player updates, and similar legitimate software.
There are many reasons:
- Users can't curb their curiosity
- Users - especially Internet novices - are not aware that such scams exist so they are easily tricked or scared into clicking offered links
- Users implicitly trust posts and links on Facebook because they originate from friends and family
- Users wrongly consider Facebook a safe place on the Internet.
Next week I'll be writing about what to do when you fall for any of these scams, how to minimize the danger to yourself and others after you were effectively tricked, and what to do to prevent falling for the scammers' tricks again.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





