11 ms·
As someone who's fairly involved with the e-commerce/digital marketing space, let me just say I'm amazed by how brazenly nasty this scam is. The TikTok promoti
by danielhua 6y ago
As someone who's fairly involved with the e-commerce/digital marketing space, let me just say I'm amazed by how brazenly nasty this scam is.
The TikTok promotional program is actually a real thing that does give around that amount of ad credit, and they have been promoting it very aggressively on Facebook with for a long while now, so it makes sense that OP would've not had any mental red flags triggered by the designs and creatives used by the scammers. The real killer is that PayPal is actually well within their rights to process this transaction (as part of the billing agreement generated when you link PayPal to Facebook Ads Manager: there actually was real ad spend in a real Facebook ad auction), so it's down to Facebook itself to refund the ad spend. (As an aside, I'm actually impressed that OP managed to reach Facebook support at all, and that they acknowledged or even understood what the problem was. I have had worse experiences in the past with FB...). What's really amazing to me is that the scammers managed to get on Google Play with thousands of obviously fake reviews, and get through Facebook ad review at all.
The scammer silently removing OP as an admin from their own ad account, preventing them from noticing or stopping the fraudulent ad campaign is just icing.
I suppose the real lesson to be learned is to simply avoid installing native applications when you can help it. OP didn't screenshot the login screen in app, so I can only assume it was a real Facebook oauth flow, but honestly at that point it's already too late. If anything OP should be grateful that the native app running on what was presumably his personal device didn't do anything worse.
- user5994461 6y ago> The scammer silently removing OP as an admin from their own ad account, preventing them from noticing or stopping the fraudulent ad campaign is just icing. This hints of not having 2 factor authentication anywhere in the chain? Would definitely advise to setup 2 factor authentication on anything managing 5 figure sums.
- danielhua 6y agoI was surprised too since OP's writeup indicates that he has 2FA on everything. You would think that you'd at least get an email or push notification if you get removed from an ad account/notification settings get changed, so it seems like an oversight by FB.
- jandrese 6y agoHardly anybody does the "when changing an email address on an account send an email to the old address to allow them to revert the change and temporarily lock the account". It seems like such an obvious thing to do.
- jellevdv 6y agoMaybe the oauth scope requested edit access to the FB business manager? That way the scammer can remove OP from the business and add himself via the API
- StavrosK 6y agoHow would that help? They were removed via the API, no passwords were stolen.
- kbenson 6y ago2FA is how you protect your credentials from being stolen and used. This wasn't a case of credentials being stolen, this is a case of someone being tricked into authorizing a separate account to take action. They hacker didn't change his credentials to lock him out, it literally revoked access from him Facebook login to the ad account. I'm using "login" and "account" specifically here to highlight the difference. On systems where there are likely to be multiple people that need access, there's a distinction between the "service account" and "logins or user accounts" that can control it. Generally, when the service account is created by a login, that login is added implicitly as a controlling user account with full privileges, and other user accounts (logins) can be added with varying levels of control. This situation appears to have been along the lines of the following: 1. User "real_user" create facebook ads account id 123456, and real_user is the admin of the ads account id 123456. 2. At some point real_user adds "scam_user" to the facebook ads account id 123456 with full admin permissions. 3. scam_user uses the full admin permissions it has for facebook ads account 123456 to remove access for real_user. Note that is is a fully legitimate and common action to take in systems like this. If you are a business and pay someone to manage your facebook ads, they are likely the admin on the account (and you may be too), and if they leave and you hire a new person to manage it, you would want to revoke the old employee's account access and add access to the new employee's account. This is how you handle it on Google Suite, Zoom's business accounts, Active Directory in Windows domains, etc. The real problem here is that the scammer got enough permissions to revoke the original user, and the original user did not get an email notification. I'm not sure if facebook ads allows adding accounts with limited permissions so only certain actions can be taken and part of the scam was making the permissions asked for non-obvious, or if that's a permissions distinction facebook ads doesn't support.
- throwbacktictac 6y agoI'm curious if the oAuth flow requested a specific scope to have permission to remove the user from their Ads account. If so, did Facebook make it clear that the permission was be requested. I must say that it was a pretty clever scheme.
- firloop 6y agoIt's possible that the attack didn't happen through the regular oauth credential request flow — if the OP logged in to Facebook inside of an app-controlled webview, the app could have just exfiltrated the user's login cookie and performed the change using "first-party" Facebook APIs.
- Ayesh 6y agoThis is what I think too. WebView doesn't show the domain of the page, and it is not possible to see if you are really in Facebook login page, or somewhere the attacker controls. Unless the attacker was using Yubikey or some sort of hardware token, the victim would have entered the TOTP code too, which the attacker can ask and pass to authenticate successfully.
- donmcronald 6y agoHow does a YubiKey prevent that kind of relay attack? If those keys blindly sign whatever's given to them, there's got to be a way to trick a user into signing something malicious. This [1] says that U2F avoids phishing by having the browser tell the 2FA device the domain, but that seems a bit weak to me. The same site even has an app where the info is relayed via a browser plugin, so literally relaying the data that's supposed to be trusted. The only way I can see that actually working is if the security key knew to only sign challenges for a specific domain. 1. https://krypt.co/blog/posts/prevent-phishing-on-the-web-with-crypto.html https://krypt.co/blog/posts/prevent-phishing-on-the-web-with...
- jrockway 6y agoThe security of the browser implementation is important. It provides the origin for the security hardware to sign, and the authenticating server ("relying party") verifies it. If your browser tells the key it's google.com when it's really evil.com, then sure, you can log into google.com if the user signs the request. The WebAuthn spec says: "Direct communication between client and authenticator means the client can enforce the scope restrictions for credentials. By contrast, if the communication between client and authenticator is mediated by some third party, then the client has to trust the third party to enforce the scope restrictions and control access to the authenticator. Failure to do either could result in a malicious Relying Party receiving authentication assertions valid for other Relying Parties, or in a malicious user gaining access to authentication assertions for other users." (https://w3c.github.io/webauthn/#sctn-client-authenticator-proximity https://w3c.github.io/webauthn/#sctn-client-authenticator-pr...) If you click further into the older FIDO spec, they cover this more explicitly: "Malicious software on the FIDO user device is able to read, tamper with, or spoof the endpoint of inter-process communication channels between the FIDO Client and browser or Relying Party application. Consequences: Adversary is able to subvert [SA-2]. Mitigations: On platforms where [SA-2] is not strong the security of the system may depend on preventing malicious applications from being loaded onto the FIDO user device. Such protections, e.g. app store policing, are outside the scope of FIDO." (https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-security-ref-v2.0-id-20180227.html#threats-to-the-user-device-fido-client-and-relying-party-client-applications https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-se...)
- beefield 6y ago> I suppose the real lesson to be learned is to ...never, ever buy or even take anything from anyone who approaches you without you being the original initiator of the communication. Simple rule that applies to both online and real world and makes your life simpler and safer.
- toxicFork 6y agoAlso works nicely against advertising too, a good principle ;)
- spurdoman77 6y agoReally nice guideline for work. Should spread it around.
- _jahh 6y agoexcept he clicked the link, he did initiate the communication so your bizarrely overly paranoid guidance doesn't apply. Not taking anything from anyone certainly closes you off to the generosity that can be found in humans.
- jonplackett 6y agoYeah, but they SENT the link. That was the initiation.
- _jahh 6y agoI see your position, but I don't view placing an ad as an initiation. He still initiated the conversation by clicking on the ad like he would've if he had called a phone number or anything else and therefore could still have been scammed.
- chuckSu 6y agoYawn
- zentiggr 6y agoWhen I'm curious about something that I might have to click through, I DDG it and find source material. It's not overly paranoid, it's been good advice for decades. Telephone charity calls are exactly the same way in my world, and started me down that handling path. If I look your org up and you look legit, and I'm interested, we'll see. You having called me isn't always strike one, but it often is.
- tgsovlerkhgsel 6y ago> OP didn't screenshot the login screen in app, so I can only assume it was a real Facebook oauth flow My guess would be that it was an in-app phishing page. Many legitimate login flows result in the official login page opening in a web view and asking for a password, which is indistinguishable from a phishing page. > but honestly at that point it's already too late. If anything OP should be grateful that the native app running on what was presumably his personal device didn't do anything worse. On phones, sandboxing significantly reduces the risk. Yes, it is possible to break out of the sandboxes if you have an exploit for that device, but it's a lot harder than on desktop where by default anything you install has full control over everything and could just steal all the users' passwords.
- tgb 6y ago> Many legitimate login flows result in the official login page opening in a web view and asking for a password, which is indistinguishable from a phishing page. I don't understand how Google/Facebook/etc can allow this to happen, let alone encourage it. I'm just baffled.
- coddle-hark 6y agoHow could they prevent it?
- tgb 6y agoBan apps that do that.
- gruez 6y agoAnd how are they supposed to do that? If it's a fake login (aka phishing) page facebook wouldn't even know about it. The only effective way is dissuade consumers from entering their login credentials in-app, but even that's tricky because if it's a malicious app they could "fake" a web browser complete with a fake "address bar".
- 8ytecoder 6y agoI fell to a (now) very obvious scam on Instagram. It seems to me that it's really easy to bypass their checks. It was a fake ad for a real product. They accepted PayPal and it took forever to get PayPal to refund me. Worst yet, even after multiple escalations PayPal continued to be on the website. Instagram continued to show me ads for the exact same product from different domains. I realized that PayPal is next to useless if you're a victim of fraud. It's much better to use a credit card directly (esp Amex or Discover) and challenge fraud than PayPal.
- jrochkind1 6y agoI recently made a purchase that turned out to be fraudulent on paypal, and somehow had no trouble getting my money back relatively promptly. Maybe have taken about a week from when I filed "I never got the product, I think the whole website was fraud".
- socialist_coder 6y agoBe careful, you can still get scammed here. I got hit for a $75 scam product that I bought with my CC, mistakenly thinking I would be protected. The scammers knew what they were doing though. They ship you a super super super cheap version of the product from china, taking advantage of those low low China -> US shipping rates, so that they have certificate of delivery. So you can't say you never got the product. And in that case, both paypal and the CC company require that you send the item back. Shipping the item back to china costs more than the item itself. So there's no point. Scammers won.
- yawboakye 6y agoI use PayPal as a front to my bank account via SEPA Direct Debit, which has an 8-week no questions asked refund policy. If PayPal doesn’t cooperate when I raise the issue I can easily get my money back through my bank. But I still like to dispute just so the business goes on record for fraudulent transaction.
- TedDoesntTalk 6y ago
- bobbyi_settv 6y ago> avoid installing native applications when you can help it Why couldn't a web site have stolen his credentials in the same way?
- JeanMarcS 6y agoI guess you’ll have a better chance to spot the URL is fake than in an app where you won’t see it
- andybak 6y agoAnd notice that you're logged out which is unusual in many cases. And a bunch of other potential signals that would be missing in a native app. It's not foolproof but it's a step forward.
- Causality1 6y agoTo me the lesson is the same old basic web security practice: don't click links, navigate to pages yourself. When he saw the ad that interested him he should have googled the offer instead of clicking on the ad.
- rsync 6y ago"If anything OP should be grateful that the native app running on what was presumably his personal device didn't do anything worse." I don't understand why any of these actions would be taken with a mobile phone ... What I mean is, managing advertising campaigns and budgets and managing assets and spend, etc., is kind of a complicated workflow ... further, it's a fairly critical business process involving a lot of money. I can see ordering some workroom supplies or paying a hosting bill with my phone ... but creating and managing ad campaigns ? That seems very unwieldy and inefficient. Google adwords, through the web based interface, is very complex and there's a lot of functions there. I can't imagine trying to do this on a phone. So what am I missing here ?
- forgotmypw17 6y agoIt's not that unreasonable. When I am on the road, it can be days between sitting at a desktop. If I can do something on my mobile, I'll do it, or try. I don't get involved in ad buys.
- AdrianB1 6y agoLaptops exist as a very efficient middle way between a desktop and a mobile phone: all the desktop functionality and the benefit of mobility. This is not an add :p
- forgotmypw17 6y agoYeah, except I cannot always carry around my laptop, as my small mobile is already heavy enough. I don't understand the need for snark here on your part, do you not think I have already considered it? By "desktop" I meant "desktop environment".
- andybak 6y ago> so I can only assume it was a real Facebook oauth flow, another reason why we should be training users to only do oAuth in a browser with a password manager. It's one last solid line of defence. OAuth in a native app is a security risk.
- donmcronald 6y agoThat's not a silver bullet though. If the password manager does a poor job of domain matching, the user gets accustomed to having to manually search for logins once in a while.
- andybak 6y agoAgreed. Not perfect but much better than nothing.
- searchableguy 6y ago> I suppose the real lesson to be learned is to simply avoid installing native applications when you can help it. I looked at the playstore page and it immediately raised many red flags. The app isn't by Tiktok or Bytedance. It's like clicking on a similar looking domain link in your email.
- gowld 6y agoTiktok is giving away $3K in ad credit per customer? And the regular price isn't massively overpriced?
- jauntbox 6y agoIs this something that could have just as easily happened through Apple's app store? This sounds like exactly the type of thing that those 30% app store cuts should be going towards to prevent (regardless of the platform).
- rayhendricks 6y agoThe real lesson is to install ublock origin and be done with deceptive advertising. Last time I tried to find nvidia drivers for windows 1st result was an obvious scam/crapware. This is not acceptable that big tech companies are making money while not taking responsibility for advertisements.