Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Important Resources & Information Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Your FB Trusted Contacts Should Not Be Trusted
Facebook   X   LinkedIn   Email

Your FB Trusted Contacts Should Not Be Trusted

November 5, 2023

As anyone who uses Facebook (or any social media) there is a seemingly endless supply of scams that go around all the time. Once we think we’ve seen them all, we are bombarded again with new ones or with new versions of them. Often, trickier to spot. This goes on ad nauseam. School may be out for the summer, but education continues on when it comes to cybersecurity threats. One, first reported in 2017, is circulating again that takes advantage of a feature of Facebook that no longer is supported. It’s the “Trusted Contacts” capability. The following is based on a true story.

Who are trusted contacts?

The “Trusted Contacts” functionality was set up by Facebook (FB) to allow a friend to be a trusted contact in case you could not log in to your account. It was Facebook’s earlier version of two-factor authentication (2FA). These days we get a one-time code by text, use an authenticator app, or a hardware key to do that 2FA. There are many other and better ways to do 2FA now and perhaps because of that, Facebook discontinued the support of the “Trusted Contacts.” Whatever the reason, they don’t offer it any longer.

Well, this phishing trick brings the trusted contacts terminology back. You may receive a text or Messenger request from a friend on FB with the message “can I add you to my facebook trusted contacts list" or something similar.

Your reply is…

We’re just going to say right now that your answer is to not answer. Don’t reply with something snarky or reply at all. That’s because your reply is going to be sent to a scam artist. And worse, even if you don’t get that message, you can get contacted at some point. You may get a response from the phisher-person. In fact, if they figure out you’re onto them, they change the verbiage to “I’m trying to secure my account and facebook gave me an option to send a password reset code to my active friends.” Nope. There are other ways to reset the password and neither your friends nor your enemies need your help to do it. So, just ignore that. Whoever that is, is not your friend. Preferably, remove or delete that chat so you don’t accidentally reply to it later.

So, what happens if I do reply?

Here’s what is going on with this scam. Somehow these scammers got your FB name. It could be in any number of ways. They send that message about being a trusted contact. Because you think it’s your friend, you reply that it’s ok. They trust you enough to ask you this favor, right? Well, maybe that real friend does, but in this case, it’s the furthest from a friend who is asking. In fact, it may not even be a person. It could be a bot.

They tell you they are sending an “unlock” code to your email address. You are to go to your email, get that code and send to them. Then you get a link to click to supposedly reset their FB password so they can get into their account again. What it actually does, is allow them to reset YOUR password and get into your account. That’s because they actually request a password reset from your account by clicking the “forgot password” link in FB from your account login page.

Now what?

Well, this is the problem. Now they have your password and they’ve likely already changed it and the email address associated to your FB account. So, if you try to reset it again, they’ll get your reset code. Fortunately, FB does have other safeguards in place so you can get your reset code some other way. But, you have to be fast if you’re going to beat them. Likely, they’ve changed your phone number too. They have probably collected your friends’ contact info, stolen your photo to use on a fake page, and tried contacting your friends to continue the scam.

What if I just cannot get control of the FB page?

First, don’t feel bad. It happens. Next, take a deep breath.

  • Have someone post to their FB feed that your account was taken over and not to accept any new friend requests from you or reply to any messages asking to be your trusted contact. In other words, get the word out so no one else falls for this.
  • Next, change your email password. This is just for safety’s sake and not because they have your email password.
  • Next, check out Facebook’s help and support section to find out how to recover your account and give it a try. However, it’s unlikely you will be able to recover it since the attackers have full control.
  • Admit defeat and let everyone know not to send to or accept messages from you using Messenger or your FB account.
  • Ask everyone to unfriend you and block you.

Yes, folks, this one is a doozy.

Do you use your FB credentials to log in to other accounts?

If you use your FB, Google, or whatever other credentials to log into any other accounts online, don’t do it again. Why? Because now you have to go to each of those accounts and change your password. Make sure those are unique passwords. Do not reuse them. It’s a bit more challenging to remember them all, but find a naming system that works for you and use it to create a different one for each and every online account. If you have to write them down in a spiral notebook, do it. Just keep it tucked away out of sight.

If you get messages from friends you haven’t communicated with in a while with some request for help, it very well could be a phishing attack. Contact that friend by phone or email separately and get the scoop rather than replying to a text message that you weren’t expecting. Most of the time, you’ll probably find out it was not really someone to be trusted.

If you decide to create a new Facebook page, try to use an authenticator app or a hardware key set to your 2FA rather than your email or phone number. But the best way to avoid this is not to reply to such messages in the first place.


There Is Plenty Of Phishing On Online Apps--Don't Get Hooked

Mobile Security

There Is Plenty Of Phishing On Online Apps--Don't Get Hooked

A recent documentary aired on subscription streaming service, Netflix, that highlighted how difficult it is to detect when someone is trying to take advantage of human nature and kindness. You may have seen it. It has been discussed on various media and it may be difficult to watch. But it is yet another example of how criminals use social engineering and trust to get what they want. One interviewee tells the story of how she met a guy that matched and swept her off her feet and swept her bank account clean. READ FULL STORY

How Your Instagram and Facebook “Friends” Can Steal Your Social Media Account

Your Security

How Your Instagram and Facebook “Friends” Can Steal Your Social Media Account

It’s time to resurrect the old adage “With friends like these, who needs enemies?” Thanks to the nonprofit Identity Theft Resource Center (ITRC), their work has uncovered a social media hack victimizing users of Facebook and Instagram using friendship as a lure. Although attacks targeting social media users are nothing new, this latest scam tugs on the heartstrings of helping a friend in need. But the only thing this friend really needs is overtaking your social media account with your help, of course. READ FULL STORY

Facebook, Instagram Shopping Scams Run Wild And Rake In Millions

Scams & Phishing

Facebook, Instagram Shopping Scams Run Wild And Rake In Millions

Data recently released by the Federal Trade Commission (FTC) shows that the number of complaints about social media shopping scams more than tripled over the last year. Consumers reported losing more than $117 million to this type of scam in just the first six months of 2020 compared to $134 million for all of 2019, according to the FTC’s latest Consumer Protection Data Spotlight. The social media sites overwhelmingly involved in these scams are Facebook and Instagram, with consumer scam reports totaling 94% of all rip-offs involving a specific platform. READ FULL STORY

Social Media Brings Out The Worst Scammers

Scams & Phishing

Social Media Brings Out The Worst Scammers

Social media attacks are a favorite of those pesky cybercriminals. One might wonder why. Well, it’s because it’s easy pickin's going for those accounts. Researchers at Arkose Labs found that of 1.2 billion social media interactions, 53% of the logins were fraudulent and 25% of new accounts were phony. Millions of people use one form of social media or another, whether it’s Facebook, Instagram, Snapchat, LinkedIn, or something else. That leaves a barrel full of phish used for targets for hackers and scammers. READ FULL STORY

More Pop-Up Ads? Yes Please! Said No One. Ever!

Your Security

More Pop-Up Ads? Yes Please! Said No One. Ever!

Those intrusive pop-up ads that slow down our browsers and bounce the content we want to read are by most accounts, insufferable. Knowing that, developers have created ad blocker extensions to help with this annoying and potentially harmful web surfing issue. One self-proclaimed ad-blocking extension, AllBlock Chromium, however, is doing the exact opposite of what it says it does and those behind it are making profits off that broken promise. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...