A Facebook scam that has been circulating for years seems to be making a comeback. And if you fall for it, you’ll have your Facebook login info stolen by the scammers, who can then hack your account and use it for a variety of nefarious purposes.
The scam works by tricking Facebook users into clicking a link to a video. The video will often have some variation of “Is this you?” or “Did you make this video?” in the description to pique your interest, and will likely come from one of your friends (who already fell for this scam and had their credentials stolen).
If you click on the link, you’ll be taken to a fake Facebook login page with a message about confirming your information before you can access the video. It is pretty obvious the page is fake if you notice the URL at the top. But if you're not paying attention and you enter your info here, you’ve just given the scammers what they need to take over your account.
As a final insult, you won’t be taken to the video (which never existed in the first place), but dumped into a spammy affiliate ad network for NSFW games, sketchy app downloads and survey scams. I’ve seen a few valid apps, too, such as Norton Secure VPN on Google Play, but these companies have no part in the scam (after I notified Symantec, Norton’s parent company, about the app’s inclusion, a spokesperson told me “Upon learning of this issue, we worked with our mobile advertising partner to quickly identify and blacklist the bad actor responsible for this threat. We are also working to identify consumers who may have been impacted to help them with any residual effects.”)
The best course of action if you get one of these video links from a friend is to not click it and notify your friend by phone or email, if possible, that their account may have been compromised. It’s also possible the video was sent from a friend’s cloned Facebook account that a scammer used to friend you in the past.
If you made the mistake of entering your credentials on that fake login page, you should immediately change your Facebook password before the scammers have a chance to get in. This would also be an excellent time to consider setting up Two-factor authentication for Facebook so you won’t lose access to your account if you fall for another phishing scam in the future.
And if the scammers have already taken control of your Facebook account, you’ll need to go through Facebook’s account recovery process to regain access.
Author's note 5/25/2021: A number of comments have come in indicating that their accounts were compromised even though they didn't not attempt to log in. I've researched this issue quite a bit and, despite nearly two years having passed since I first wrote this story, I still haven't seen any credible evidence that malware or other hacks are being exploited to steal user credentials through this scam. Everything I've read from security research sources indicates that this is a pure phishing scam. And given how much press this has received, I'm sure it is also something that Facebook has researched and would have patched if it were a security hole on their end.
So how come all the reports of exploits where people didn't log in? Here's what I think may be happening:
1) People did log in, but it's such a natural action for them that they don't even remember that they did.
2) Your account was already compromised, either through a previous phishing attempt or because you have weak password security that allowed an attacker to access your account through a data breach from another source.
3) These requests are coming from cloned accounts
4) You didn't log in, but did click on a malware download (e.g., fake Flash update to view video) that compromised your system.
For more insight on what is happening, go to your Facebook Settings > Security and Login to see where and when you have been logged into your Facebook account.
If I uncover any new information about malware associated with this scam, I will update the article.
From Mike on December 16, 2019 :: 12:28 pm
I have a friend who was infected by this. She claims all she did was click on the link, didn’t enter her credentials. Is that possible or likely?
Reply
From Josh Kirschner on December 16, 2019 :: 2:56 pm
It’s not an “infection” - there is no malware involved - so the video scam only works by tricking someone into revealing their Facebook login credentials. And you can’t have your Facebook credentials stolen simply by clicking on the link. It’s possible she may have entered her info without even thinking about it and now doesn’t remember. It’s also possible that her Facebook account was cloned and videos that you’re seeing in your feed that you think are coming from her are actually coming from a cloned account you were tricked into friending.
Reply
From roxi on January 11, 2020 :: 3:27 am
i clicked the link and it didnt take me to a login page, but my credentials are ‘stored’ in google. WOuld google know that it wasnt a legit facebook page though? My facebook seems fine so far
Reply
From Josh Kirschner on January 13, 2020 :: 1:19 pm
Even if your Facebook login info is stored in Google, you would still have to log in when you get to the scam page (the scam page can’t access that information automatically). And Google password manager shouldn’t auto-fill on a scam page because the url won’t be a Facebook url.
From ########## on January 07, 2021 :: 8:29 am
i have waiten about a year now
From Lavonya on August 19, 2020 :: 10:59 am
He would be correct. I recently had this happen to me. I am smart enough to know that Facebook does not require you to enter your credentials to view a video, so I never would. I simply clicked “play” and I was forward to the link, which I closed immediately. A few days later, all my contacts were sent the same video from my account.
Reply
From JS on December 11, 2020 :: 3:48 pm
Hello,
I’m curious to know if you experienced any further issues with your account after this happened?
The same thing happened to my dad this evening. He received a “is this you in the video?” link via messenger app on his phone, clicked on it, tells me the link went nowhere and that there wasn’t any option to enter any details, and then hours later noticed that the same video had been sent from him to all of his contacts.
We have just been “unsending” the messages, but I am wondering if we need to go further and wipe his phone entirely. I looked at his access facebook history and can see that his account was accessed from another phone that isn’t his at the time the messages were sent.
If you have any more detail about what happened to you after you clicked on the message, and whether any more of your details were compromised beyond your facebook account, it’d be appreciated.
From Devon on April 18, 2021 :: 7:02 am
I swear I didn’t enter my user/pass either & it happend to me.
Reply
From Devon on April 18, 2021 :: 7:00 am
I swear on everything I didn’t enter my credentials- it never asked, I closed the page immediately after opening it. I also noticed my fb account sent an email to videos 18+ with the word “start” then shit hit the fan and all my fb friends got the message. I hate fb !!
Reply