Advertisement
Canada markets open in 4 minutes
  • S&P/TSX

    21,656.05
    +13.18 (+0.06%)
     
  • S&P 500

    5,022.21
    -29.20 (-0.58%)
     
  • DOW

    37,753.31
    -45.66 (-0.12%)
     
  • CAD/USD

    0.7267
    +0.0004 (+0.05%)
     
  • CRUDE OIL

    83.07
    +0.38 (+0.46%)
     
  • Bitcoin CAD

    85,840.00
    +80.75 (+0.09%)
     
  • CMC Crypto 200

    885.54
    0.00 (0.00%)
     
  • GOLD FUTURES

    2,399.90
    +11.50 (+0.48%)
     
  • RUSSELL 2000

    1,947.95
    -19.53 (-0.99%)
     
  • 10-Yr Bond

    4.6120
    +0.0270 (+0.59%)
     
  • NASDAQ futures

    17,680.25
    +21.75 (+0.12%)
     
  • VOLATILITY

    17.87
    -0.34 (-1.86%)
     
  • FTSE

    7,868.62
    +20.63 (+0.26%)
     
  • NIKKEI 225

    38,079.70
    +117.90 (+0.31%)
     
  • CAD/EUR

    0.6817
    +0.0015 (+0.22%)
     

Hundreds of apps are stealing people’s Facebook accounts, Meta warns

Nigeria Meta Court Case (Copyright 2021 The Associated Press. All rights reserved.)
Nigeria Meta Court Case (Copyright 2021 The Associated Press. All rights reserved.)

Hundreds of apps are secretly stealing people’s Facebook logins, parent company Meta has warned.

The apps hide inside the iPhone and Android app stores, appearing to offer useful services. They might show as photo editors that offer fun filters, for instance, or useful tools such as flashlights.

But more than 400 such apps have been found actually stealing Facebook login details and then getting into people’s accounts, the company said in an update.

It warned users to be careful when downloading new apps, if they ask for social media credentials when signing up.

Most of the apps were photo editors, it said, with almost 43 per cent coming in that category. But that apps can take a number of forms, with developers seemingly targeting categories that are likely to encourage people to download them.

ADVERTISEMENT

Developers also use a number of other tricks to hide the scam. That can include publishing fake positive reviews so that critical reviews from those who have spotted the malicious nature of the app will be drowned out.

When the app is finally installed, users are prompted to login with Facebook, so that they can get access to those features. But the login is actually intended to steal the password and username.

With that, attackers can break into Facebook accounts, stealing other data or messaging friends in an attempt to get even more people involved.

There are few very obvious ways to distinguish those malicious apps from legitimate ones. Many real apps might offer such services – and require users to log in with their Facebook accounts.

But Meta advised that people take three steps before downloading and logging into such an app. First anyone should be suspicious of apps that require a social login to use features, should check their reputation, and check whether the app really seems to be offering the services it promised.

If anyone is affected, Meta advised resetting passwords, switching on two-factor authentication and switching on login alerts so that you will be warned if anyone tries to get into you Facebook account.