Hacked verified Facebook pages impersonating Meta are buying ads from Meta
· 2023-05-06

Sketchy Facebook pages impersonating businesses are nothing new, but a flurry of recent scams is particularly brazen.

Sketchy Facebook pages impersonating businesses are nothing new, but a flurry of recent scams is particularly brazen.


A handful of verified Facebook pages were hacked recently and spotted slinging likely malware through ads approved by and purchased through the platform. But the accounts should be easy to catch — in some cases, they were impersonating Facebook itself.


Social consultant Matt Navarra first spotted some of the ads, sharing them on Twitter. The compromised accounts include official-sounding pages like “Meta Ads” and “Meta Ads Manager.” Those accounts shared suspicious links to tens of thousands of followers, though their reach probably extended well beyond that through paid posts.


cdb9c738e683b77f4e21502bfcbabed5.png


In another instance, a hacked verified account purporting to be “Google AI” pointed users toward fake links for Bard, Google’s AI chatbot. That account previously belonged to Indian singer and actress Miss Pooja before the account name was changed on April 29. That account, which operated for at least a decade, boasted more than 7 million followers.


dcb236bef091e262aff1646dc690f2cf.png160a00517843377ffabaf781b213a17d.png


Facebook now tracks and publicly displays a history of name changes for verified accounts — a welcome bit of transparency but a safeguard that apparently isn’t enough to flag some obvious scams.


What’s most egregious in these cases is that the hacked pages were not only impersonating major tech companies, including Meta itself, but that they were able to purchase Facebooks ads and go on to distribute suspicious download links. In spite of very recent account name changes, those ads were apparently approved without issue in Meta’s automated ads system.


All of the impersonator pages Navarra identified have since been disabled.


This week, Meta shared a report on a recent spate of AI-themed malware scams. In those instances, hackers lure Facebook, Instagram and WhatsApp users to download malware by posing as popular AI chatbot tools like ChatGPT. One of those clusters of malware known as DuckTail has been plaguing businesses on Facebook for a few years now.


As TechCrunch’s Carly Page explained this week:


Meta says that attackers distributing the DuckTail malware have increasingly turned to these AI-themed lures in an attempt to compromise businesses with access to Facebook ad accounts. DuckTail, which has targeted Facebook users since 2021, steals browser cookies and hijacks logged-in Facebook sessions to steal information from the victim’s Facebook account, including account information, location data and two-factor authentication codes. The malware also allows the threat actor to hijack any Facebook Business account that the victim has access to.


It’s possible that the Facebook pages that impersonated Facebook and went on to buy malware-laden ads were compromised through DuckTail or malware like it.


“We invest significant resources into detecting and preventing scams and hacks,” a Meta spokesperson told TechCrunch. “While many of the improvements we’ve made are difficult to see – because they minimize people from having issues in the first place – scammers are always trying to get around our security measures.”



Impersonator accounts and compromised business pages have long been a headache for business owners across Facebook and Instagram. Meta Verified, the company’s newly launched verification program, is positioned to improve the company’s notoriously thin level of customer support for businesses that rely on its apps. Controversially, Meta’s promising offer of “proactive account protection” isn’t a free improvement — Instagram and Facebook accounts will need to pay $14.99 a month to secure the higher level of customer support, a price many businesses will likely begrudgingly pay to avoid drowning in a sea of scam accounts.














熱門文章
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
British gambling levy rates confirmed for each vertical
Regulation
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
首頁
遊戲
合作
發現
我的