Meta
Best Practices
·
June 17, 2024

Don’t Let Your Business be a Victim: Protect Your Facebook Account From Phishing


Today we are providing insights into phishing - what it is and how to protect your Facebook account against it.


Business owners with Facebook accounts have a lot to keep up with. Complete payroll, send out products, hire new employees, and more.


But in the daily rush, it’s important to remain vigilant about protecting your company and clients from scammers.


Many of these scammers use a technique known as phishing to steal your personal and business passwords, data, and more. These scams often result in businesses losing access to their Facebook accounts. They can bring your organization to a stop.


Facebook is committed to helping you protect your business against this threat. In this article, we will:

  • Explain phishing attacks
  • Help you protect your data and Facebook accounts from phishing attacks
  • Provide ways to get help if you’re the victim of phishing

What is phishing?


Phishing is the practice of targeting someone with communications or websites that are designed to look legitimate. The purpose is to trick people into revealing sensitive information such as login credentials, credit card numbers, or other personal information.


During a phishing attack, scammers (also known as bad actors) may attempt to:

  • Lure you into revealing passwords so they can access your information, and accounts
  • Lure you into visiting deceptive landing pages where they can infect your devices with malware or trick you into giving away your account credentials
  • Take over your Facebook account(s) and spam your customers/followers with unwanted or inappropriate content on your feed

Phishing attacks are particularly harmful because they don’t remain isolated to one online service. Clicking on a fraudulent link can result in a loss of control over your device or browser or an email account, which can then be used to phish your family, friends, and customers - negatively impacting you and your business.


Phishing violates Meta’s Cybersecurity policy, and we work hard to prevent phishing messages from reaching our users. However, there are also simple steps you can take to help protect yourself against phishing attacks, and ways to recognize both the signs of a phishing attempt and the signs that you may have fallen victim to an attack.


What are the signs of a phishing attack against your Facebook account?


To help protect yourself from an attack, remember that the following may be signs of phishing:

  • Someone contacting you that you don’t know personally or aren’t friends with online
  • Receiving email messages from an unknown or unexpected source (for example, “There was a problem with your order” when you haven’t ordered anything)
  • Messages that stress urgency (for example, “Payment is needed now…click the link below”)
  • Receiving requests for personal information (for example, your social security number or Facebook password)
  • Communications that are focused on convincing you to click a link

Phished? How do you know?


Here are some signs that you may be the victim of phishing:

  • You are suddenly unable to access any of your Meta accounts (including your Facebook account)
  • Your customers inform you that they are receiving unusual or inappropriate messages, videos, or images from your account
  • You are now following people or pages you don’t want to follow
  • Other accounts of yours, such as those from financial institutions or email services, are compromised

Best practices for protecting your Facebook account


Here are proactive steps you can take to protect your accounts:


Review all messages. Carefully review the email address that any message came from. Scammers will often use an email address designed to look like an official Meta support account, but is not. For example, thisisnotarealmetaaccount@facelook.com.

Any correspondence from Facebook or Meta will only come from one of these email domains, or any subdomains of the following (such as support.facebook.com or business.fb.com):

  • fb.com
  • facebook.com
  • facebookmail.com
  • instagram.com
  • meta.com
  • metamail.com

Note: Recently, we have seen evidence of malicious actors sending Business Manager partner requests that include phishing links. As we investigate this issue, we encourage you to exercise caution as these notifications do come from a legitimate Meta domain (facebookmail.com). If you don’t know the person or business mentioned in the partner request, DO NOT click on any of the included links.


There are often misspellings in messages or things that may seem suspicious to you. Trust your instinct.


Be careful what you share. Don’t provide your username or password to any unknown source that requests it. Remember that Facebook will never ask you for your username or password in an email message, or send you a password to verify in an attachment. Don’t answer messages requesting personal information such as your social security or banking information, including messages that pretend to be from Facebook.


Remember that you can receive fraudulent links and requests in any digital communication. This includes email messages, Instagram direct messages (DMs), and Messenger. If you receive a suspicious message alerting you of issues with your Facebook business account, do not respond. Instead, report it to phish@fb.com and go to Meta Business Support Home to review your account status and note any support issues.


Don’t click links or open attachments from unknown sources. It’s easy to quickly click on links in email or text messages. But we recommend that you don’t click on anything, including links, in any unsolicited email message or text that you receive from anyone including Facebook or Meta.


Also, never open or download attachments in email messages from a business or person you don’t know. Even if you do know the person, be aware that they could inadvertently have sent you a malicious attachment.


Use unique, strong passwords or passphrases that you can easily remember, for your Facebook account. While this won’t necessarily stop phishing, it will strengthen the security of your account. We also recommend that you avoid reusing the same password across multiple websites or apps.


Set up two-factor authentication (2FA) on your Facebook account(s). If you set up two-factor authentication, you'll be asked to enter a special login code or confirm your login attempt each time someone tries accessing Facebook from a browser or mobile device we don't recognize. Never share a code provided by 2-factor authentication with anyone else. 2FA is a good layer of account protection and is recommended on all your accounts.


Use the Security Checkup Tool to help secure your account. This feature will take you through some actions that can help protect your account. Note that the Security Checkup will help you set up two-factor authentication.


Educate all authorized users of your account(s) by sharing this information. Make sure that anyone associated with your company, including friends and family members, understands how to protect your accounts from phishing.


Learn more about additional ways you can avoid spam and scams.


If your Facebook account is compromised, here’s what to do:


Unfortunately, sometimes things happen. If you are the victim of a phishing attack, it’s important to take the following steps as soon as possible.


  1. Reset your password. If you accidentally entered your username or password into a malicious link, someone else might be able to log into your account. Resetting your password helps prevent unwanted logins.
  2. Go to your Facebook account and remove any unauthorized logins/devices that are signed into your account.
  3. Review your activity log to determine if you’re following any unwanted accounts. Unlike any pages you didn't select.
  4. Check recent emails sent by Facebook to determine if there are any issues with your account.
  5. Review your Facebook feed to determine if the attack resulted in unwanted/inappropriate posts. Delete any posts you or someone associated with you, didn't post. To report a post and delete it from your feed, click the three dots located in the top right corner …, then click Report Post.
  6. For business accounts, contact Facebook’s Support team by opening a case through Business Support Home or the Business Help Center (“Get support”).
  7. Access Facebook directly through the addresses listed in the Help section of your account (don’t use any addresses in the questionable email message).

Note: If you think you have received a suspicious message in Messenger, report it using the report function in the chat.


Other steps to take

  • Report any suspicious messages on Messenger using the report function in the chat.
  • If you suspect that someone has accessed your financial accounts or if unauthorized payments have been made, contact your bank immediately.
  • If you believe a crime has been committed, we strongly recommend reporting this to local law enforcement.

Bad actors can compromise your Meta accounts, and undermine your business. But you can stay safe. And Meta is here to support you as you do.

Related Articles