Proofpoint: Security, Compliance and the Cloud

May 16, 2011

No, You Can't See Who's Looking at Your Facebook Profile, Stalking You on Facebook: New Profile Views Counter Scam

Facebook-Stalking-Your-Profile-Scam-2As regular readers of this blog no doubt realize, phishing scams aren't confined to email. On Facebook, one of the most popular phishing/malware distribution schemes has been come-ons that allege to let you "see who's been viewing your profile" or "see who's stalking you."

Per Facebook's own FAQ on this subject (see Facebook FAQ item "Can I see who's viewed my profile?"):

"Facebook does not provide applications or groups with the technical means to allow people to track profile views or see statistics on how often a particular piece of content has been viewed and by whom."

Proofpoint spam fighter Scott Panzer sent me an example of the latest version of this scam which encourages users to drop a bit of Javascript code into their browser's address bar to enable you to see who is viewing your profile.

As you've probably guessed, the code itself is malicious. If executed, it spams itself to your Facebook wall and your online friends. It then friends you to several other random accounts, probably with the goal of executing further phishing attacks.

We see Facebook friends getting fooled by these sorts of scams quite frequently and it's worth reminding your friends (or users inside your organization) to be aware of phishing attacks on Facebook and to specifically note that any application that purports to let you see who is viewing your profile is certainly phony and malicious.

You might also find it helpful to share our "Seven Simple Rules for Staying Safe Online", most recently posted in my article, "Stay Safe from Email Threats in the Wake of Epsilon Email List Breach."

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Archives

Blog Search

Email Security Gateways, 2011

Magic Quadrant

Tweets

What people are saying right now about us.

©2012 Proofpoint, Inc.
threat protection: Proofpoint Enterprise Protection compliance: Proofpoint Enterprise Privacy governance: Proofpoint Enterprise Archive secure communication: Proofpoint Encryption