Facebook Friend Request Scam
You’re sitting on Facebook. Suddenly, you get a friend request. Everything is pretty common. It happens all the time. You probably wouldn’t think twice about accepting a friend request from a familiar face or longtime friend. But you have to ask yourself: “Am I already friends with them?” If the answer is yes, the request is likely a scam by a criminal up to no good.
The new tactic works like this: A criminal re-creates a random person’s existing Facebook profile using that person’s profile picture and “About” information. The criminal then uses the phony new profile to send friend requests to the real person’s Facebook friends.
If you accept, you’ve just given this stranger access to the many personal details on your profile: status updates, location, date of birth and photos. Those simple details, in the hands of today’s cyber criminals, can be used to steal your full identity and wreak havoc with your entire life. Posing as you, the scammer can also message your friends asking for money or trying to meet up in person.
What to do: If you get a friend request from an existing friend, verify that the request is real. And of course, be very wary of friend requests from people you don’t know.
Your best way to stay protected is to tighten your security settings so that only your Facebook friends can view your profile, photos and other info. Also, go into the “Friends” section of your activity log. At the top, it says, “Who can see your friend list?” In the drop-down, select “Friends,” rather than “Public.”
Business Email Compromise Scam
This type of attack is so good at what it does, it goes by three different names. Known as B.E.C. scams (business email compromise), CEO Fraud Scams and Payroll Attacks, this scam is on the rise and has been taking some big businesses, like Snapchat, to the cleaners.
In this scam, an employee at a company receives an email, seemingly from the company CEO or someone in the payroll department. It’s a quick email asking for, let’s say, payroll information, or a quick money transfer.
The employee doesn’t bat an eyelash, assuming the email is nothing out of the ordinary, responds, or clicks on a malicious link and all of a sudden sensitive information of the company and its employees is in the wrong hands.
What to do: This scam has gotten so big, the FBI had to step in and issue the following guidelines:
- Be wary of email-only wire transfer requests and requests involving urgency.
- Pick up the phone and verify legitimate business partners.
- Be cautious of mimicked email addresses.
- Practice multi-level authentication.
If someone in your company falls for one of these scams, the FBI urges you to:
- Contact your financial institution immediately.
- Request that they contact the financial institution where the fraudulent transfer was sent.
- File a complaint—regardless of dollar loss—with the IC3.
General Ways to Stay Safe
Scammers are getting trickier by the day, so you’ll have to stay one step ahead of them. One way to do this is to know the warning signs and red flags to look for before clicking on any links or sending out any sensitive information. Here is a list of the general things to look for in any email that you find suspicious:
- Keep an eye out for typos and bad grammar within the body of the email.
- Be able to identify where the email is coming from.
- Hover your mouse over any links before you click to see the site it is pointing to.
- If links are provided to go to a website, don’t click it. Navigate to the company’s site yourself without the link.
- Be wary of email-only wire transfer requests and requests involving urgency.
- Be cautious of mimicked email addresses. If an email claiming to come from Amazon.com has the return email address as gmail.com (for example), it’s a scam.
- Practice multi-level authentication, which means you have at least two forms of verification, such as a password and a security question before you log into any sensitive accounts.
Please share this information with everyone. Just click on any of these social media buttons.
