4 ms·
Unfortunately I do not have an answer for you, but I do have some suggestions for you. > I had 2FA enabled so I have no idea how someone managed to access my a
by mkdirp 5y ago
Unfortunately I do not have an answer for you, but I do have some suggestions for you.
> I had 2FA enabled so I have no idea how someone managed to access my account. I am not a techie.
What kind of 2FA had you set up? If it's text messaging, this is trivial to bypass, however, if it was TOTP using an authenticator method then this seems suspicious. Please double check your email isn't compromised. My guess is they may have reset the 2FA method either via text messages or via email. Also follow the advise in the other comments regarding backdoors and/or extensions/addons that hijack your browser.
> I sent my ID to FB and have not heard anything more. I feel scared that I have sent my ID to someone that has somehow hacked my account, used my bank card, and now knows more about me than before.
Some years ago when I had to do this, it was a manual process, and so it took a few days, which may be the reason why you haven't heard anything back. Double check where you sent your ID. For example, if you sent it by email, check who you sent it to, if you uploaded it on a website, check that the website you uploaded it to is indeed facebook.com etc (also, check that it isn't an iframe by right-clicking on the see if there is any options about frames or iframes). Having said that, the process could have changed and it may be that it is automated now.
Lastly, and this may be far fetched, but try emailing Mark Zuckerberg's office at zuck@fb.com and zuckerberg@fb.com (send it to both addresses). These CEO emails often get directed to a team that can deal with things. Though, I'm not sure if this is the same with Facebook considering you're not a customer.
I wish you the best and hope you regain access. If/when you do regain access, I suggest you download a copy of your information[0]. This way you won't lose all those precious memories in the future if you happen to lose access again.
[0] https://www.facebook.com/help/212802592074644 https://www.facebook.com/help/212802592074644
- deleted 5y ago[deleted]
- lma21 5y agoWhy (or how) is it trivial to bypass text messaging 2FA ?
- primax 5y agoSim swap attacks are the main way, becoming more common every day
- deepstack 5y agosms can also be intercepted by folks who knows what they doing in the approximate location as the cell phone user. Cell phone/sms is NOT secure.
- orwin 5y agoIt is susceptible to sim swapping (probably not hte case here). I think there is also a method for mirroring the 2FA code, as well as intercepting the message (i don't know how easy it is though).
- mcraiha 5y agoSIM swapping https://en.wikipedia.org/wiki/SIM_swap_scam https://en.wikipedia.org/wiki/SIM_swap_scam
- tetromino_ 5y agoThe problem is that mobile providers, unlike tech companies, prioritize customer service over security. Thus they have human customer service agents instead of heartless robots, and the human agents will, with the tiniest bit of social engineering, allow your phone number to be taken over or ported by a scammer.