Skip to main content

Facebook hit by phishing attacks for a second day

  • Story Highlights
  • Facebook stopped a phishing attack Thursday, its second day of battling a worm
  • Worm lures people to a fake Facebook page and prompts them to log in
  • The page then steals their information when they type their username and password
  • Facebook spokesman: The attacks were stopped within a few hours in each case
By Elinor Mills
Decrease font Decrease font
Enlarge font Enlarge font
CNET.com

(CNET) -- Facebook stopped a phishing attack on Thursday, its second day in a row of dealing with a worm on the site that lures people to a fake Facebook page and prompts them to log in.

Facebook has faced two phishing attacks in the past two days but officials aren't sure whether they are related.

Facebook has faced two phishing attacks in the past two days but officials aren't sure whether they are related.

Unsuspecting Facebook users get a message from a friend urging them to "check this out" and including a link to a Web page that appears to be a Facebook log-in page, but it is a fake site that steals their information when they type in their username and password. The worm also sends a copy of the message to the infected Facebook member's contacts.

In the latest attack, the Web address was "FBStarter.com." In Wednesday's attack, the address was "BAction.net."

The attacks were stopped within a few hours in each case, said Facebook spokesman Barry Schnitt. He said it was too early to say whether the two phishing attacks are related. "We are investigating," Schnitt said.

Once Facebook learns of a phishing attack, either by members notifying the company or employees noticing that a URL is being distributed to a lot of people, the company deletes the URL from members' pages, blocks fresh postings, and removes the redirect to the URL that appears in e-mail messages, Schnitt said.

Facebook also goes in and resets the passwords of member accounts that had been used to distribute the spam, he said.

The company also alerts anti-fraud partner MarkMonitor, which passes the phishing URL on to the major browsers to block it and contacts ISPs to take the site down, according to Schnitt.

To protect against phishing scams, Facebook users should make sure that the URL they are visiting says "www.facebook.com." If it doesn't use that domain it's likely to be spam. Also, members that are already logged in to Facebook will not be asked to log in again.

"People should have a healthy dose of suspicion, and ask themselves 'why did I get logged out?'" Schnitt said. "If something looks a little strange you should check the address bar."

Facebook users who think they have been affected by the scam should change their passwords and review their Facebook stream for any unauthorized changes. If they use their Facebook password for other sites, they should change those passwords as well.

And if they are using their Facebook authentication to log in to any other sites, they should check for any unauthorized changes on those sites.

© 2009 CBS Interactive Inc. All rights reserved. CNET, CNET.com and the CNET logo are registered trademarks of CBS Interactive Inc. Used by permission.

  • E-mail
  • Save
  • Print
Today's Featured Product:
2011 BMW Z4 sDrive35is
 8.0 out of 10
Recent Product Reviews:
RIM BlackBerry Torch 9800 (AT&T)
 8.0 out of 10
Motorola Rambler - black (Boost Mobile)
 7.0 out of 10
Samsung UN46C6500
 6.9 out of 10