Wednesday, April 23, 2025
Homecyber securityNew Facebook Fake Copyright Notices to Steal Your FB Accounts

New Facebook Fake Copyright Notices to Steal Your FB Accounts

Published on

SIEM as a Service

Follow Us on Google News

A newly discovered phishing campaign is using fake Facebook copyright infringement notices to trick users into divulging their credentials, potentially compromising business accounts.

Phishing Campaign Exploits Facebook Brand to Target Businesses

Researchers at Check Point Software Technologies revealed that this campaign, active since December 20, 2024, has already targeted over 12,279 email addresses across hundreds of companies.

The campaign primarily impacts enterprises in the European Union (45.5%), the United States (45%), and Australia (9.5%), but localized versions in Chinese and Arabic indicate its global reach.

- Advertisement - Google News
Facebook
Chinese-language sample email

The attackers leverage Salesforce’s automated mailing service to distribute phishing emails, exploiting its legitimate infrastructure without breaching its security systems.

By using the sender ID “noreply@salesforce.com,” the emails appear credible and are branded with Facebook logos.

These emails falsely alert recipients of alleged copyright violations, stating that their recent activity may infringe on copyright laws.

Credential Harvesting Through Fake Support Pages

Victims who fall for this ruse are redirected to counterfeit Facebook support pages designed to harvest their credentials.

These pages prompt users to input sensitive information under the pretense of having their accounts reviewed to avoid deactivation.

The phishing sites are sophisticated, embedding credential harvesting technology that captures login details in real-time.

Businesses relying on Facebook for advertising, customer engagement, or as a storefront are particularly vulnerable.

A compromised Facebook admin account can allow cybercriminals to alter content, manipulate messaging, delete posts, or lock out legitimate administrators by changing security settings.

According to Check Point Software Technologies, such breaches can erode client trust and damage a company’s reputation.

For businesses in regulated sectors like healthcare or finance, the risks extend further, potentially resulting in non-compliance penalties and legal ramifications.

Organizations can take proactive steps to mitigate this threat. Setting up alerts for suspicious logins and unusual activity is a critical first step.

Educating employees about phishing tactics is equally important Administrators should be advised to verify account statuses directly through Facebook rather than clicking on embedded email links.

Businesses should also inform customers about how they communicate via official channels to prevent them from falling victim to phishing scams post-account hijacking.

Additionally, maintaining an incident response plan is essential for recovering compromised accounts and managing communications with affected customers.

As this campaign demonstrates, cybercriminals continue to exploit trusted platforms like Facebook and Salesforce to execute sophisticated attacks, underscoring the importance of robust cybersecurity measures for businesses worldwide.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Zyxel Releases Patches for Privilege Management Vulnerabilities in Firewalls

Zyxel, a leading provider of secure networking solutions, has released critical security patches to...

Marks & Spencer Confirms Cyberattack Disrupting Payments and Online Orders

Leading British retailer Marks & Spencer Group plc (M&S) has confirmed it has been...

CISA Issues Five ICS Advisories Highlighting Critical Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released five urgent advisories on...

Google Cloud Composer Flaw Allows Attackers to Gain Elevated Privileges

Research disclosed a now-patched high-severity vulnerability in Google Cloud Platform’s (GCP) Cloud Composer service,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Zyxel Releases Patches for Privilege Management Vulnerabilities in Firewalls

Zyxel, a leading provider of secure networking solutions, has released critical security patches to...

Marks & Spencer Confirms Cyberattack Disrupting Payments and Online Orders

Leading British retailer Marks & Spencer Group plc (M&S) has confirmed it has been...

CISA Issues Five ICS Advisories Highlighting Critical Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released five urgent advisories on...