Scammers Forgot To Protect Database Containing Stolen Facebook Login Credentials

Facebook is the largest social media of the web. And for this particular reason, it's easy to say that anyone who wishes to find someone else through the internet, would start from Facebook.

This is because people with social media accounts would use their accounts to upload almost anything about themselves, share their thoughts, post photos and videos of their activities, connect with friends and colleagues, and more.

This is why stolen social media accounts are a hot commodity on dark web marketplaces.

With a high price and huge demand, attempts for getting stolen Facebook account has become a priority for hackers.

In order to steal huge amount of login credentials at once with minimal effort, scammers that want to meet the demand need to set up a fake login page, and trick victims into signing in. This method that is called the phishing scam.

And this time, a group of scammers learned it the hard way, after their hundreds of thousands of stolen Facebook login credentials were left in an unprotected database.

Facebook phishing page
The website tricked Facebook users into providing their login credentials, promising them to show a list of people who had recently visited their profiles. (Credit: vpnMentor)

The team at vpnMentor discovered this unprotected Elasticsearch database as part of their web mapping project, which involves port scanning of particular IP blocks.

According to the team, the login credentials were stolen as part of a widespread phishing operation targeting Facebook users with fake landing pages.

The researchers believed the scammers used websites that offered fraudulent services to Facebook users, such as reports on who recently visited their page.

Through the phishing scam pages, victims would sign in with their username and password, thinking that they were actually signing up for the service through their Facebook account, while in fact, their credentials are recorded and stored for malicious purposes by the scammers.

The database was unprotected, simply because the hackers forgot to add a password to their treasure trove of stolen data.

Because of this, anyone with an internet connection and a web browser, could easily access the database. And making things worse, the stolen credentials were stored in cleartext format, meaning that anyone who found the unprotected database, could view the entries, plain and clear.

The researchers at vpnMentor also believed that the stolen accounts were used to scam even more victims into joining a cryptocurrency scam.

[block:block=87]
Facebook phishing page
When victims clicked on the link to see the full list, they will be sent to a fake Facebook login page. (Credit: vpnMentor)

In detail, the researchers found:

  • 13.5 million records, totaling over 5.5GB of data.
  • Facebook login credentials (usernames and passwords) for between 150,000 to 200,000 accounts on Facebook.
  • Text outlines for comments the scammers would make on Facebook hosts, via a hacked account, directing people to suspicious and fraudulent websites.
  • Personally Identifiable Information (PII) data such as emails, names, and phone numbers from hundreds of thousands of people who’d registered at a fraudulent Bitcoin site, also run by the scammers.
  • Domains for the websites used in the scam.
  • Technical information about how the scammers had automated their processes.

This massive amount of data came from June to September 2020, but the researchers argued that the scam was probably much more extensive and had been operating for far longer.

"Based on results from the internet search tool Shodan, we believe that we discovered the database after most of its contents had been deleted. At the time Shodan registered it, the database contained 11GB of additional data potentially related to the scam," the researchers wrote.

According to the researchers, the impact of this breach include: Facebook account takeover, external account takeover, fraud, identity theft, blackmail, disinformation, and also fake news.