Facebook confirms ‘Fakebook’ phishing attacks
A rapidly spreading phishing worm has been hitting Facebook users, looking for usernames and passwords.

Facebook has confirmed reports that it has been targeted by phishing attacks over the past couple of days.
According to reports, messages linking to the websites fbstarter.com or fbaction.net were spreading fast through the social network.
Security firm Websense describes one of the phishing lures in 'fbstarter', which arrives in a user's Facebook inbox or is forwarded to their email inbox if forwarding has been configured.
The message contains a link that redirects the user to a Facebook phishing page imitating the real site's sign-in page.
Once they've entered their username and password, that's enough for an attacker to log into an account and spam a user's friends.
"Remember never to click on links in suspicious emails or messages and to only log in from legitimate pages with the Facebook.com domain," Facebook Security said in a wall post.
"You should make sure that your Facebook password is different from the passwords you use for other online accounts."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Facebook uses MarkMonitor to help protect users against phishing attacks, and recently expanded the deal to help protect against malware attacks.
-
RSAC Conference 2025: The front line of cyber innovation
ITPro Podcast Ransomware, quantum computing, and an unsurprising focus on AI were highlights of this year's event
-
Anthropic CEO Dario Amodei thinks we're burying our heads in the sand on AI job losses
News With AI set to hit entry-level jobs especially, some industry execs say clear warning signs are being ignored
-
Latest Meta GDPR fine brings 12-month total to more than €1 billion
News Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing
-
"Unacceptable" data scraping lands Meta a £228m data protection fine
News The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators
-
Meta notifies around 1 million Facebook users of potential compromise through malicious apps
News The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics
-
Facebook business accounts hijacked by infostealer malware campaign
News Threat actors are using LinkedIn phishing to seize business, ad accounts for financial gain
-
Meta begins encrypting Facebook URLs, nullifying tracking countermeasures
News The move has made URL stripping impossible but will improve analytics
-
Meta hit with €17 million fine over multiple GDPR breaches
News The social media giant set aside over €1 billion in November to help it cope with potential fines arising from data protection investigations
-
Meta says Apple's iOS privacy changes will cost it $10 billion in 2022
News The company's CFO suggests Google "faces a different set of restrictions" because it pays Apple to remain the default iOS search engine
-
Google, Facebook fined €210 million for making it difficult for users to reject cookies
News Data regulator CNIL gives companies three months to provide a system for refusing cookies that is as easy as single click consent