Site offers Facebook account break-ins for $100
Beware! It's a phishing ploy, says PandaLabs
September 18, 2009 03:54 PM ETSecurity Alert
- Microsoft confirms IE6, IE7 zero-day bug
- Microsoft plugs 15 holes, including critical drive-by bug
- Apple delivers mammoth update, patches 58 bugs
- Massive bot attack spoofs Facebook password messages
- Site offers Facebook account break-ins for $100
- Review: Norton Internet Security 2010 checks your reputation
- Microsoft: Patching Windows 2000 'infeasible'
- Microsoft patches slew of 'drive-by attack' bugs
- New flaw causes 'Blue Screen of Death' on Vista, Windows 7
- Could Google be tricked into talking to botnets?
Computerworld - Security vendor PandaLabs has discovered an online service offering to help those so inclined to hack into any Facebook account they choose for a price: $100.
However, those who sign up for the service could find themselves becoming the victims instead, PandaLabs warned today.
The Facebook hacking service, which is delivered via a professional looking Web site, was discovered by PandaLabs earlier this week.
Users of the service are required to first register with the site and then provide an ID of the Facebook account they want hacked, said Luis Corrons, technical director of PandaLabs. Users who enter the ID and click on a "Hack it" button are then presented with the username of the owner of the Facebook account. They then have the option to "Start Facebook hacking."
Those who follow the instructions are eventually told that the hack was successful and a password for the account was retrieved. But to actually get the password, the user is then required to send $100 via Western Union to an individual in Kirovohrad, Ukraine. It's not clear whether sending the money will yield any login and passwords, Corrons said.
But the way the site has been designed and the ease with which a potential client can interact with it lends it a certain degree of credibility, he said. The site contains an FAQ section, which claims the site has been in business for more than four years.
The site even provides a link to a Webmoney account that in fact does appear to be four years old, Corrons said. However the domain itself appears to have been registered by someone in Moscow only a couple of days ago, he said.
"We've been looking at it and we are 99.9% sure it is a ruse," to get people to pay up money in exchange for what they think will be legitimate Facebook credentials, he said.
At least as of the last time PandaLabs inspected the site, it was not downloading or distributing any malware and seems to have been set up purely to scam those seeking to gain illegal access to Facebook accounts, Corrons said.
Those who do fall for the scam are unlikely to go to law enforcement to report it, he noted.
Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Knowledge Center.
Additional Resources



White Papers & Webcasts
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Data in Action: Making the Planet Smarter
Register Now
Email Archiving: A Business-Critical Application
Get this paper now!
Gene Kim's Practical Steps to Achieve and Maintain NERC Compliance
Learn seven steps operators can take to meet IT configuration requirements set forth in the NERC-CIP standards.
The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!
The New World of eCrime: Targeted Brand Attacks and How to Combat Them
Download This Whitepaper Now!
Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.

