Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I got scammed on a Facebook group (not marketplace). It was a surprisingly sophisticated scam but now that I'm aware of it I see it constantly in every group that has people posting wanted to buy posts.

I was searching for a hard-to-find car part. I asked in the group and got a reply saying "try this page" with a link to another Facebook page that appeared to be a business a few cities away selling car parts. The posts on that page all looked legit, with listings for vehicles that make sense for my region, real-looking photos of parts laid out and labelled, etc. The posts had timestamps that made sense, not just hundreds of posts made on one day.

So it seemed trustworthy, I messaged the group and got an immediate response (should have been a red flag, response was "yes I have that part" within seconds). We negotiated a price ($200), he sent through bank details and I transferred the money. About an hour later someone else responded to my original post with "that's a scam".... sadly, too late.

I dug into the page a bit and found Facebook has a "view post history" feature. Every single post on the page had been edited. The original posts had all been a rabbit enthusiast posting pictures of their rabbits. They had been edited to be pictures of car parts with descriptions matching the pictures. Clearly someone's credentials had been stolen and their page hijacked.

It's unbelievable to me that Facebook can't detect this kind of fraud. Surely someone logging into an account from a new location, editing every single post on the page then spamming Groups with links to that page should set off automated alarm bells. As mentioned, now that I'm aware of this scam I see it in every single group that allows "wanted to buy" posts, constantly. Like, in every thread.



The infuriating part is how easy it apparently is to highjack dead people / inactive accounts, and use them for fraud.

Case in point, I never use FB except for the marketplace every now and then. I naturally forgot my login/password, hit the "Forgot password" option, put my phone number and... got given access to someone else's account, that they've not used in years. They likely had my number before, I guess, passing away.

I contacted FB and did my best to try to lose access to the account, starting with login out, but I kept receiving notifications through text messages, and was permanently given the option to "switch account" with no authentication whatsoever. Out of option, I ultimately deactivated the account in question, but that pisses me off because I really really did not want to alter it in any way.

Long story short, it's not a surprise Facebook is riddled with shit like that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: