Jump to content

The fool in question, me.

Earlier today (well yesterday now), I got a message that I ignored about changing my password on Facebook. I'm guessing that it was legit, because I blocked, reported the message thinking it was dodgy. This was followed by an e-mail about a password change request. I managed to change the password and lock down the facebook account but not before the intruder changed the recovery email address. I immediately went into threat assessment mode and changed e-mail and all critical passwords. I can only assume though that the intruder had access to my e-mail address. Said address is my own domain hosted with a well known hosting company. I assume this because all my emails had disappeared. The intruder managed to pop everything into the trash just before I changed my password of that address and the four others I have. I've gone through my password manager and altered every password for every account I have (to the best of my knowledge).

 

So, the first question I have and what I need some help with....is there any recourse with Facebook? I have gone through every visible support option I can find but come up against the problems.

  1. The recovery e-mail address is one that clearly doesn't belong to me.
  2. The account has been deactivated/marked for deletion, so reporting through a friend, or reporting use of my identity isn't possible.
  3. There is a second account associated with my e-mail named Hoang Long that clearly also isn't mine.

Some mix of all of these makes me think I'm best off leaving the account to rot and writing off my losses. I did have a business account with Facebook which had *some* unpaid funds due to a theatre show I put on and sold through FB, so my main concern about this is compromise of business data/funds.


Secondly, and perhaps most importantly, is there anything beyond 2FA, or resetting passwords and recovery options I should be doing in this circumstance? I won't lie, I feel like such an idiot and have no answer for how this could've happened other than me having forgotten to enable 2FA for Facebook. That still doesn't answer how my e-mail was compromised other than a data leak that I'm as yet unaware of from hosting company. I'll be kicking myself for months I think, but want to do whatever I can to beef up my security protocols across the board. Any help, or advice is massively appreciated.

I used to work as a tech and consultant, now I've become an odd person who plays dress-up and calls themselves a theatre maker.

My Rig: Ryzen 5 3600 | AsRock B450 Pro4 | Corsair Vengence RGB Pro 16GB 3200Mhz | Asus TUF GeForce 1660 Super OC | Corsair Carbide 175r | XPG Core Reactor 750W
Keyboard Corsair K55 | Mouse Corsair Harpoon | Sound AKG 52 Headphones,

 
Link to comment
https://linustechtips.com/topic/1363433-a-fool-needs-some-help/
Share on other sites

Link to post
Share on other sites

1 hour ago, MartinTheActor said:

The fool in question, me.

Earlier today (well yesterday now), I got a message that I ignored about changing my password on Facebook. I'm guessing that it was legit, because I blocked, reported the message thinking it was dodgy. This was followed by an e-mail about a password change request. I managed to change the password and lock down the facebook account but not before the intruder changed the recovery email address. I immediately went into threat assessment mode and changed e-mail and all critical passwords. I can only assume though that the intruder had access to my e-mail address. Said address is my own domain hosted with a well known hosting company. I assume this because all my emails had disappeared. The intruder managed to pop everything into the trash just before I changed my password of that address and the four others I have. I've gone through my password manager and altered every password for every account I have (to the best of my knowledge).

 

So, the first question I have and what I need some help with....is there any recourse with Facebook? I have gone through every visible support option I can find but come up against the problems.

  1. The recovery e-mail address is one that clearly doesn't belong to me.
  2. The account has been deactivated/marked for deletion, so reporting through a friend, or reporting use of my identity isn't possible.
  3. There is a second account associated with my e-mail named Hoang Long that clearly also isn't mine.

Some mix of all of these makes me think I'm best off leaving the account to rot and writing off my losses. I did have a business account with Facebook which had *some* unpaid funds due to a theatre show I put on and sold through FB, so my main concern about this is compromise of business data/funds.


Secondly, and perhaps most importantly, is there anything beyond 2FA, or resetting passwords and recovery options I should be doing in this circumstance? I won't lie, I feel like such an idiot and have no answer for how this could've happened other than me having forgotten to enable 2FA for Facebook. That still doesn't answer how my e-mail was compromised other than a data leak that I'm as yet unaware of from hosting company. I'll be kicking myself for months I think, but want to do whatever I can to beef up my security protocols across the board. Any help, or advice is massively appreciated.

Contacting Facebook probably can’t hurt.  At the very least they will know that there were shenanigans associated with that account.  Might even deem to do something.  I don’t know what their policies are on such things.  If you don’t contact them how are they to know though?  Difficulties may include that they can’t tell which of the two of you is the real owner.  That one is as old as the Old Testament.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
https://linustechtips.com/topic/1363433-a-fool-needs-some-help/#findComment-14920548
Share on other sites

Link to post
Share on other sites

3 minutes ago, Bombastinator said:

Contacting Facebook probably can’t hurt.  At the very least they will know that there were shenanigans associated with that account.  Might even deem to do something.  I don’t know what their policies are on such things.  If you don’t contact them how are they to know though?  Difficulties may include that they can’t tell which of the two of you is the real owner.  That one is as old as the Old Testament.

Sensible suggestion but there is literally no contact details for them. No response on Instagram or on Twitter. And their own forms on Facebook can't be used to provide Government ID if the account isn't active...so basically, that suggestion doesn't work I'm afraid. They're really difficult to get in touch with.

I used to work as a tech and consultant, now I've become an odd person who plays dress-up and calls themselves a theatre maker.

My Rig: Ryzen 5 3600 | AsRock B450 Pro4 | Corsair Vengence RGB Pro 16GB 3200Mhz | Asus TUF GeForce 1660 Super OC | Corsair Carbide 175r | XPG Core Reactor 750W
Keyboard Corsair K55 | Mouse Corsair Harpoon | Sound AKG 52 Headphones,

 
Link to comment
https://linustechtips.com/topic/1363433-a-fool-needs-some-help/#findComment-14920552
Share on other sites

Link to post
Share on other sites

12 minutes ago, MartinTheActor said:

Sensible suggestion but there is literally no contact details for them. No response on Instagram or on Twitter. And their own forms on Facebook can't be used to provide Government ID if the account isn't active...so basically, that suggestion doesn't work I'm afraid. They're really difficult to get in touch with.

Something I suspect the attacker knew or they wouldn’t have tried it.   I don’t know any useful contact methodology.  I stay well away from Facebook in general and have for years.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
https://linustechtips.com/topic/1363433-a-fool-needs-some-help/#findComment-14920564
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×