Facebook again targeted by phishing attacks
Friday, May 15, 2009
Facebook was once again hit by spammers who hacked user accounts to send out spear phishing emails in an attempt to steal user login credentials on Thursday.
A Facebook spokesman told the New York Times Gadgetwise blog that yesterday it was cleaning up spam Wall posts and messages, resetting passwords of affected users and blocking access to malicious websites linked in the phishing messages.
Users reportedly received messages to their accounts that appeared to come from friends, but were sent by spammers from hijacked accounts.
Users who followed the spam links were directed to log back in to the Facebook site, but actually logged into a dummy site controlled by the hackers, giving spammers their passwords. The fake domains included www.151.im, www.121.im and www.123.im.
An unnamed Facebook spokesman told the New York Times the attack "is not widespread and is only impacting a small fraction of a percent of users."
Web security experts said an acceleration of cyberattacks on Facebook has been ongoing over the last several months, due to the huge number of users of the site. Facebook claims it has about 200 million users.
Facebook was hit last Thursday by another spam attack that attempted to get users to download adware onto their computers. It appeared to be the second stage of a phishing attack from the previous week.

|