Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Facebook Hacked Weird

Sep 21, 2015 10:26AM PDT

So I have an old yahoo email that I use for signing up for things that I think I will get spammed on.

So last night I log in to go do my scheduled Fantasy Hockey Draft and notice in my inbox a bunch of Facebook friend requests being accepted etc...

I do not use Facebook associated to the this email address. Looking back I may have, most likely did, sign up for facebook on this email address and then never touched never added friends etc...

I think I'm very knowledgeable when it comes to Computer Security.

I figured someones hacked it due to it having a weak password. A common (common to me) password I use for things I really don't care if they stay secure or not.

So some forum some where on the internet could have been hacked had the passwords dumped and then decided to try my email registered on said forum in Facebook with the same password.
Good tactic for the hacker should not reuse passwords and i only do when creating throw away accounts.

BUT it starts getting odd.
#1. Why not change the password. They changed the profile pic, my location and added a bunch of people. I've noticed Facebook now lets me sign in with my yahoo mail credentials. So maybe the hackers have found away to do a replay/pass the hash attack against Facebook. Therefore they don't actually have my password and therefor can not reset it.

So this is where it gets weird.
They have changed my address to a City in the southern US.
The only activity on the page is searching for people from the same city that the hackers have changed my location to.
They have made a bunch of friend requests to others in that same city. That Facebook account now has 21 friends. 12 of which are from the same city that the hacker changed it too. 8 friend this is there hometown.

So who are all these people accepting friend requests from this fake Facebook profile?

A little bit weirder there are 4 people requesting to be my friend.

The Facebook name is a fake. Lets say it is Kay Pee. So its not like these people are requesting me by mistake.

AND I just got a message from someone saying:
"
HOW R U JIMMY L!!!

KAY U OK?
"

Jimmy L is his first name last initial.

Discussion is locked

- Collapse -
reply
Sep 21, 2015 10:31AM PDT

I feel like I should reply to Jimmy by saying "YEP I AM OK" and see where it goes from there.

Feels like I am, or i should say his account is, involved in some underground stuff haha i dunno what to think its all so odd. I could care less about this facebook account that i never used.

- Collapse -
Sent Friend Requests
Sep 21, 2015 10:50AM PDT

Looks like they sent out 113 friend request all to people who have something to do with this southern US city.

- Collapse -
(NT) So Why Not Deactivate The Accounts?
Sep 21, 2015 5:28PM PDT
- Collapse -
Deactivate The Account
Sep 22, 2015 8:35AM PDT

Well I could just Deactivate The Account but that doesn't help me understand what happened. It being active is not affecting me in any way.

- Collapse -
It May, Or May Not Affect You
Sep 23, 2015 9:28AM PDT

The simple fact is: Hackers will hack..... and frequently, there is nothing you can do about it. Your previous explanations show you probably know exactly what happened.. Poor/weak passwords allowed others to gain access to your accounts and as such, they are using YOUR NAME/ACCOUNT to do whatever they want.. So it MAY be affecting you more than you know..

I would deactivate everything involved with the accounts and be free and clear of the junk.

Hope this helps.

Grif

- Collapse -
(NT) Naveef, Your Post Was Removed. It Violates Forum Policies
Dec 12, 2015 5:27PM PST