Meta Files Lawsuit Over Phishing Attacks



Facebook Meta Phishing AttackMeta (Facebook’s corporate parent) and the digital banking company Chime have filed a joint lawsuit against two Nigerian citizens for allegedly impersonating Chime in phishing attacks, BleepingComputer reports. The defendants are accused of using “more than five Facebook accounts and more than 800 Instagram accounts” to direct users to spoofed Chime login pages in order to harvest their credentials.

“Many of these accounts used the Chime logo as their profile photo and the word “Chime” with varied spellings in the username, such as ‘_ch_im_e_’ and ‘chime942,’” the lawsuit says. “Between no later than March 2020 and October 2021, Defendants used their network of Chime-branded Facebook and Instagram accounts to impersonate Chime in violation of the Terms. For example, Defendants used Chime-branded usernames, domains, and/or profile photos in these accounts without Chime’s authorization.”

BleepingComputer says the phishing sites were designed to take over victims’ Chime accounts.

“One such phishing website is still online at chime62.godaddysites[.]com, asking visitors to enter their phone number, email, Social Security Number, and Chime password,” BleepingComputer says. “The end goal of the scheme was to withdraw money out of hijacked Chime accounts without the victims' knowledge. These phishing websites prompted users to enter their Chime usernames and passwords to compromise users' Chime member accounts and withdraw funds.”

BleepingComputer notes that Facebook and Instagram repeatedly blocked these accounts and phishing sites, but the defendants continued setting up new ones.

“Meta disabled Facebook and Instagram accounts used to impersonate Chime and blocked the phishing websites from its services,” BleepingComputer says. “On July 9, it also sent cease-and-desist letters notifying the two defendants that their conduct violated the platforms' terms and revoking their Facebook and Instagram access.”

New-school security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for phishing and other types of social engineering attacks.

BleepingComputer has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews