FB account hacked & password & email changed

Options
thelawnet
thelawnet Posts: 2,577 Forumite
Name Dropper First Post First Anniversary Combo Breaker
I have a friend whose FB account has been hacked I believe she originally set it up with a phone number and then added an email address. However the email address was not verified, although we have received some emails there.

Today someone hacked the account and changed both the email & phone number. Trying through the Facebook recovery process using old email & phone number, it says that there is no account with those details. And using the new phone number, it just wants to send an SMS to that number (which we don't have access). And we don't know the new email address.

Facebook says that you can't recover the account without access to either email or phone, but they changed both without any confirmation.
«1

Comments

  • angryparcel
    angryparcel Posts: 926 Forumite
    Options
    I bet they used a weak password that someone guessed or they gave this to someone. have they phone facebook or just tried their auto system
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    edited 28 May 2017 at 2:11PM
    Options
    I bet they used a weak password that someone guessed or they gave this to someone. have they phone facebook or just tried their auto system

    Yeah tbh I think they are a bit clueless. Also it's a bit difficult because the name on the account is like Joanna Diamonds, whereas it should be Joanna Smith (or whatever the account holder's name is), so it's more difficult to prove the name. Also the person's name isn't actually Joanna, it's something like MelianaJoanna, where Joanna is just the shortened form.

    They sell diamonds (actually this is in Indonesia), and it seems the new 'owner' of the account is using it to try and rip people off. Problem is the victims can turn up at the shop and complain...

    Is it actually possible to phone Facebook?
  • angryparcel
    angryparcel Posts: 926 Forumite
    Options
    thelawnet wrote: »

    Is it actually possible to phone Facebook?
    Yes
    http://www.email-support-number.co.uk/facebook-support.html
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    Options
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    Options
    DavidP24 wrote: »
    Did you try clicking on the bit highlighted in yellow that also appears in your second screen, i.e. NOT the continue button??

    I clicked:

    1. Reset my Password
    2. No longer have access to these
    3. I cannot access my email account

    The problem is that they don't see any alternative to using the ((today changed!) email & phone number) due to whatever algorithm.
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    Options
    DavidP24 wrote: »
    Out of interest, how come they no longer have access to the email address or phone? Is there ANY chance of getting at least one of these back?

    It's not that they don't have access - they were both changed - they still can access the original ones, but Facebook only cares about the freshly changed ones. From what I can see, there was an email sent to the email address this morning saying 'verify your email address'. This however was not done, so I guess the email address was never verified, which means it carries little weight. As to why no SMS was sent to the phone number before it was changed I have no idea.
    Step 4:
    Your primary email would be changed so well of course you don't want to send your reset your password link to the hacker's account so, Click "no longer have access to these?" link.

    Step 5:
    Well now you almost got your account back.

    Er, not quite. You click 'no longer have access to these' and you get 'Try to get access to your email account'. Which is no use since said email account belongs to the hacker.

    You don't get the option:
    Now write your new email address that you want to send the change password link as well set as your primary email.

    That never appears - it seems whether that appears is based on some unknown variables. But in this case it doesn't.
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    edited 29 May 2017 at 4:45AM
    Options
    DavidP24 wrote: »
    Did it occur to you that it was the email address that was hacked in the first place, this would have enabled them to delete the message and then empty the trash.

    Yes that did occur to me, however Google didn't show any recent access, though there was an 'Android' from 'USA' three days earlier. You would have thought that reading & deleting an email would show up there, but maybe not, maybe it's still the same login.
    My feeling is that you have to start over in 24 hours, trying to log in with old credentials, it should then trigger the dialog boxes posted above.

    Hmm, it's possible but I don't see anything to say so?

    Edit: I reported the account for being a business profile on a personal account, and they have removed it. I presume it can be restored by the owner (and then converted to a page), but I guess it's not so important.
  • thelawnet
    thelawnet Posts: 2,577 Forumite
    Name Dropper First Post First Anniversary Combo Breaker
    Options
    DavidP24 wrote: »
    So it should be the first thing you secure, make it two factor on your cell and use a lastpass generated password like 4a5mQc8WZKunAPWh

    I think something like

    "I eat tasty green cows on alternate Tuesdays" is better. More entropy.
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Name Dropper First Anniversary First Post Photogenic
    Options
    Just for info, Facebook accounts are never "hacked"


    This would be almost impossible for anyone bar the NSA etc to do.


    What has happened here is your friends password has been socially engineered out of him/her.
    Example, you receive a message on facebook saying "hey is this a picture of you ? <link>"


    The link then takes you to a FAKE facebook login page, and the user just thinks "oh, i have to enter my password again" and types it in.


    Thus handing their credentials to the attacker.


    Moving forward (if you/they do get back in) - Be on the lookout for this kind of scenario
  • angryparcel
    angryparcel Posts: 926 Forumite
    Options
    another one is all these ' win a years shopping from Aldi, click here and enter your details' ( also from other retailers etc) that seems to come from one of your friends. these just harvest your details.
    also when a friend post a sob story message and it says, 'copy and paste - dont share' all these are fake and just after your details.
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.6K Banking & Borrowing
  • 250.2K Reduce Debt & Boost Income
  • 449.9K Spending & Discounts
  • 235.7K Work, Benefits & Business
  • 608.7K Mortgages, Homes & Bills
  • 173.3K Life & Family
  • 248.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards