Thursday, May 21, 2009

Deja vu: New phishing scam hits Facebook

 Friendly Computers wants to make sure that your Facebook account will be protected from a new phishing scam. More information is below…

A new phishing scam is hitting Facebook users on Thursday, sending them to a Web site designed to steal their log-in information, according to report.

Facebook users are receiving messages from friends with a subject line of "Hello" and a prompt to check out "areps.at" or another one ending in .at

If you log in to the site, it steals your email and password, logs you into Facebook and automatically changes your password and sends the same message to all your Facebook friends, according to the All Facebook blog.

"Whoever is behind the scam has been steadily amassing a large number of email addresses and passwords over the past few weeks," the blog says. "Some days as much as three scams will spread throughout the site (possibly even more). Facebook rapidly shuts down all references to the site but by then the scam has spread to thousands of users."

The phishing URLs were blocked by Firefox and flagged as a "Web Forgery" as of 9:50 a.m. PDT. One of them was still up and downloading malware on Internet Explorer.

A Facebook spokesman did not immediately return a call and e-mails seeking comment.

Separately, some Facebook users reported difficulty accessing the site on Thursday morning. It was unclear whether the connectivity issues were related to the phishing scam.

Source: http://news.cnet.com/8301-1009_3-10246536-83.html?tag=newsLatestHeadlinesArea.0