Facebook phishing
Mar. 26th, 2010 12:04 pmI have an email address at live.com, which I forward to my main address.
Over a few hours, I got several emails at this address, supposedly notifications from Facebook. They had return addresses and link URLs just like the real Facebook, so I don't know how they're planning to steal your information.
Message #1:
Message #2:
Messages #3 and #4:
If you're wondering why these are all Greek names, it's probably because I use a Greek alias.
At first I thought my account was hacked and they used it to sign up on the real Facebook. However, I was able to login to live.com (Hotmail) normally and the Sent folder has no trace of a confirmation email.
All of their messages end with:
Is it possible that they are trying to coordinate these emails with a DNS attack that redirects facebook.com to their evil site?
Over a few hours, I got several emails at this address, supposedly notifications from Facebook. They had return addresses and link URLs just like the real Facebook, so I don't know how they're planning to steal your information.
Message #1:
<< Hi Jkjhgvfjkjhk,
Your account has been created — now it will be easier than ever to share and connect with your friends. >>
Message #2:
<< To complete the sign-up process, please follow this link:
http://www.facebook.com/confirmemail.php?e=[email]&c=[number]
You may be asked to enter this confirmation code: [number] >>
Messages #3 and #4:
<< Hi Jkjhgvfjkjhk,Then the same thing for "Papou Yiayia"
Dimitri confirmed you as a friend on Facebook. Dimitri Psomas Volou Street >>
If you're wondering why these are all Greek names, it's probably because I use a Greek alias.
At first I thought my account was hacked and they used it to sign up on the real Facebook. However, I was able to login to live.com (Hotmail) normally and the Sent folder has no trace of a confirmation email.
All of their messages end with:
<< Didn't sign up for Facebook? Please let us know. This message was intended for [email]. >>which sounds like yet another attempt to steal your information. I'm just not sure how...
Is it possible that they are trying to coordinate these emails with a DNS attack that redirects facebook.com to their evil site?