A well-designed phishing scheme that tries to steal usernames and passwords

May 3, 2012 14:01 GMT  ·  By

Emails entitled “New comment on Facebook” have been seen landing in inboxes, informing recipients that their accounts are disabled. These notifications are part of a phishing campaign that’s designed to dupe users into handing over their credentials.

“You have disabled your Facebook account. You can resume your account at any time by logging into Facebook using your old login email address and password. You will be than able to exploit the site in the same way as before,” the message reads.

Users who rush to reactivate their accounts and click on the links are taken to a website that replicates the Facebook login page.

Once the username and password are entered, nothing spectacular happens, except for the fact that at this point the cybercriminals have gained access to the information which they can later  use for malicious purposes.

If you come across this email, delete it immediately. If you have already fallen victim to this scam, be sure to change your passwords before it’s too late.