Messenger chatbot abused to steal Facebook passwords


A brand new phishing campaign leveraging chatbot software (opens in new tab) on Messenger has been uncovered by cybersecurity firm SpiderLabs.
The goal of the campaign is to obtain people’s Facebook credentials and various other personal information, the researchers explained.
At first, the victim receives an email, pretending to be from Facebook, claiming that their page is in violation of the site’s community standards and will be terminated in 48 hours.
The email also carries an “Appeal Now” link, which gives the victim a chance to appeal the termination.
Red flags galore
Thankfully, the content of the email contains a few red flags that should help users identify the message as fraudulent.
For example, there are a few spelling and grammar mistakes in the body of the message, and the recipient’s name appears as “Policy Issues”, which is not how Facebook handles such cases.
Should the victim still press the “Appeal Now” link, they are then taken to a Messenger chatbot, where they are prompted to click through to another “Appeal Now” link. This is most likely done to circumvent any email security services, as the link to the chatbot is not malicious in itself.
Here, the researchers found more red flags: the page that owns the chatbot has a handle @case932571902, which is most definitely not Facebook’s. It’s also empty, having zero followers and zero posts.
If the victim proceeds, they are taken to a website hosted on Google Firebase. This one is disguised as a Facebook “Support Inbox”, and this is where the victim ends up giving away sensitive data to the attackers.
According to the researchers, the attackers are asking for email addresses, mobile numbers, first and last names, page names and, obviously, passwords (opens in new tab).
“Chatbots serve a huge purpose in digital marketing and live support, so it is no wonder that cyber attackers are now abusing this feature. People are not inclined to be suspicious of its contents, especially if it comes from a seemingly genuine source,” the report states.
“The fact that the spammers are leveraging the platform that they are mimicking makes this campaign a perfect social engineering technique. As always, we advise everyone to remain vigilant when surfing the web and to not interact with unsolicited emails.”
Audio player loading… A brand new phishing campaign leveraging chatbot software (opens in new tab) on Messenger has been uncovered by cybersecurity firm SpiderLabs. The goal of the campaign is to obtain people’s Facebook credentials and various other personal information, the researchers explained. At first, the victim receives an email,…
Recent Posts
- Everything new on Apple TV+ in March 2025: Severance season 2 finale, Dope Thief, The Studio, and more
- Powerplay 2: Logitech made its magic mousepad cheaper instead of better
- Is your business primed to respond to downtime?
- AT&T Promo Code: Get a Gift Card Worth Up to $200
- Top digital loan firm security slip-up puts data of 36 million users at risk
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010