Skip to main content

Facebook scammers are hacking accounts and running ads with stolen money

And they're bragging about it on the platform.
Facebook scammers are hacking accounts and running ads with stolen money

Scammers are hacking Facebook accounts, running ads with stolen money, and bragging about their fraudulent fortunes right on the social network.

If you're one of the 10 million Facebook users running ads on the platform, beware of a growing scam ring that's hacking advertisers' accounts, using their credit cards to steal tens of thousands of dollars in Facebook ads, and openly bragging about the money they're making off the scheme right on the platform.

What's going on here?

The scam

Digital marketer Loni Mayse knew something was wrong when ten of the Facebook ad accounts she manages started running $15,000 per day ads for what she describes as a "Santa Clause on a stripper pole" Christmas decoration.

The fraudulent ads running on Loni Mayse's Facebook pages were pushing users to this ecommerce store.
The fraudulent ads running on Loni Mayse's Facebook pages were pushing users to this ecommerce store.

"Let's be honest who the fuck wants that?" she said, referring to the product being hawked via ads on a Facebook post describing the nightmare scenario she just went through.

Let's be honest who the fuck wants that?

"[The scammers] were in about 10 of my accounts within minutes," she explained in an online conversation with Mashable. "All running this ad. Bypassed every single Facebook security protocol as well."

Mayse says the scammers quickly placed two unauthorized users inside her Facebook Business Manager, which is the backend portal that allows social media managers and marketers to run multiple Facebook Pages and ad accounts from one dashboard. They also changed the names of the Facebook pages.

She explained how their emails and usernames tried to disguise what they were doing. In one instance, the scammers tried to spoof Facebook support by using a fake customer service email address for the user being added to the account. In another, they added a fake profile utilizing her own name, Loni Mayse, perhaps in an effort to make the duplicate look like a glitch and not an actual separate unauthorized account added to her Business Manager.

This is not a glitch. One of those?Loni Mayse accounts are not really hers.
This is not a glitch. One of those Loni Mayse accounts are not really hers.

The scammers were also able to raise the billing threshold on her ad accounts, allowing them to spend more of Mayse's and her clients' funds. Mayse pointed out how this requires approval from Facebook.

"I just do not understand how they got it approved so fast," she told me.

A screenshot of Loni Mayse's Facebook ad manager showing the scammer's ad and the $15k per day advertising budget that they set.
A screenshot of Loni Mayse's Facebook ad manager showing the scammer's ad and the $15k per day advertising budget that they set.

The tens of thousands of dollars a day in Facebook ads that the scammers had access to were pushing users to an online shop called "HappyStore.info." The site is built using ShopBase, an ecommerce platform like Shopify located in San Francisco. In fact, the majority of the ecommerce shops involved in this particular scam ring appear to be built on the ShopBase platform.

ShopBase did not immediately respond to Mashable's request for comment.

The hack

How are these scammers gaining access to all these Facebook ad accounts?

It's pretty sneaky. A scammer will reach out to a digital marketer via Facebook Messenger posing as someone looking to hire a Facebook ad campaign manager. After their pitch, they'll send over a project proposal with all the details about the company, budget, and what they're looking to do. This proposal is cover for a .exe file download, disguised as an innocent PDF, which gives the scammer access to the target's Facebook Business Manager.

A PDF is just simply a document file. An .exe on the other hand is an executable file often used to run or install applications on a Windows-based PC. A user should never download an .exe file from someone they don't know as its often used to install viruses and other nefarious software on their computers.

Ecommerce strategist Alex Stiehl tells Mashable he was also targeted, but had seen the spreading warnings about the scam.

The unsolicited Facebook messages sent to Alex Stiehl.
The unsolicited Facebook messages sent to Alex Stiehl.

"They pretended to want me to run ads for them," Stiehl said. "I did not accept the [Facebook messages] and they have not gotten access to my accounts."

In the messages provided to Mashable, the script used by multiple scammer profiles have been similar, with each sending the target a Dropbox or MediaFire download link to a compressed file that includes the .exe disguised as a PDF. In one instance, the scammer even checked to make sure that its target had been using a PC as the .exe file would not be able to run on a Mac.

Unfortunately for Loni Mayse, she did download the file.

The unsolicited Facebook messages sent to Loni Mayse.
The unsolicited Facebook messages sent to Loni Mayse.

Upon doing so, the scammers were able to completely bypass the two-factor authentication she has on her Facebook account. However, she doesn't think the .exe file provided the scammers with remote access to her computer as she was monitoring the actions in real-time. One possibility is that the scammers were able to swipe Mayse's EAAB, a static access token that provides a user account with access to Facebook's API.

The scammers

Perhaps the most incredible thing about this scam is that the alleged perpetrators are openly bragging about their success right on Facebook, on what appears to be legitimate profile pages.

That's right. It's known who they are, or at least what they go by on Facebook, thanks to sloppiness on their part.

"They left way too many breadcrumbs," Mayse tells me, providing the Facebook Pixel used by the scammers.

A Facebook Pixel is a piece of code that allows the social media company to track the effectiveness of your ad campaigns. Using this, one can find all the campaigns attached to the ad account connected to the pixel. For example, the Facebook pixel tells us that one of the other websites they were advertising is an ecommerce shop called "joynesse.net."

According to the scammers' Facebook Pixel, their scheme appears to be very successful.
According to the scammers' Facebook Pixel, their scheme appears to be very successful.

Using the Facebook pixel, we can see that the scammers were still running ads on Facebook to their ecommerce stores as of the night of Oct. 27. But, the most revealing information came from a crucial mistake that the scammers made while changing the settings around on Loni Mayse's Facebook Pages.

Not long after taking over Mayse's accounts, it appears as if the scammers were attempting to add their fake Loni Mayse profile as an editor to a different Facebook Page they ran. Instead, they mistakenly added Loni Mayse's real Facebook profile, revealing the other profiles that were running the page.

The scammers accidentally added?Loni Mayse as an editor on one of their own Facebook Pages.
The scammers accidentally added Loni Mayse as an editor on one of their own Facebook Pages.

The scammers appear to be based out of Vietnam. When Mayse posted some information to her Facebook profile, one of her followers reached out.

Nguyen Luan, a computer engineer based in Vietnam who is familiar with the scam says he's aware of the scam tactics because he runs legit ecommerce shops that have all but gone out of business as an effect of the grift. Luan says he does not know these individuals personally.

In a conversation with Mashable, Luan explained how these scammers often track what legit ecommerce shops are selling to see what's popular and then clone the websites and its products. Next, they target ad agency owners and use their hacked ad accounts and stolen funds attached to them to run high-priced Facebook ads. The legit ecommerce shops cannot compete because the scammers are outbidding them on ads with this "free money."

Are the scammers at least sending the unsuspecting buyers the product listed on their ecommerce site? That part is unclear. However, if they are, they are most likely selling cheap, scammy knockoff versions from dropshipping websites of the actual advertised item, a common tactic used in other Facebook scams.

The accounts of some of the alleged scammers provided to Mashable by Luan match the users that took over Mayse's accounts, such as profiles belonging to Bá Ti?p and V? V?n Ki?u.

The alleged scammers are making bank.
The alleged scammers are making bank.

Luan pointed to this braggadocios Facebook post from V? V?n Ki?u, with a screenshot attachment of an ecommerce earnings dashboard, as an example of the alleged millions of dollars these scammers are making from their fraudulent activities.

"Guess the result and win a prize," posted V? V?n Ki?u in a Facebook post asking his friends and followers to guess the first number in the 7-figure earnings from the alleged scam.

"They live like a king here with the stolen money," Luan told Mashable. "They have [run the scam campaign] for like 2 years now. The trend is going up and more people are doing this. They can't be caught or go to jail because they live outside the U.S. Shutting down their profiles can't stop them."

What can be done

Unfortunately, it appears Luan is right.

This Facebook ad hack and scam is only getting worse, and it appears like not much is being done about it. For example, Mari Smith, one of the biggest names in the Facebook marketing world, recently shared that she fell victim to this very same scam too.

There is a history of Facebook-related ad schemes attached to scam rings from Vietnam, yet Facebook seems to be struggling to keep up with it. Just this past summer, Facebook announced it was suing four Vietnamese individuals for taking part in a similar ecommerce-related Facebook account takeover scam. While Facebook was able to shut down that particular scheme, the scammers were still able to ring up over $36 million in unauthorized ads.

For users, like Loni Mayse, who've been affected, all they can really do is reach out to Facebook support and wait for help.

"I've had a support ticket open for six days," Mayse told me. While the scammers no longer have access to Mayse's pages or Business Manager, Facebook has put limits on what she can do, too. As of right now, for example, she can't run any Facebook ads.

Most users that fell victim to this scheme who've shared their experience say they've been able to recoup most if not all their funds. Mayse says she caught the issue while the scammers' ads were still in-review and not yet approved by Facebook, so she had not yet been charged.

The company provides information in its Help Center on avoiding scams on its platform and has recently taken additional steps to warn users about possible suspicious activity. Facebook says it is also developing a new type of account so users will no longer have to use their personal Facebook logins to access Business Manager.

"Our teams work around the clock to detect and prevent fraud, safeguard data, and help ensure our systems are secure, a Facebook spokesperson told Mashable. "We’ve proactively launched safety notices and additional tools to support our customers, and encourage our advertisers to use all of the security features in our products and adopt best practices to keep their accounts safe"

While the scammers are no longer inside Loni Mayse's account, they're still on Facebook. On Alex Stiehel's Facebook post warning his friends and followers about the scheme, there are dozens and dozens of comments from users just this week saying they just fell victim to this scam.

Nguyen Luan believes that the only thing that can stop these scams is to cut them off at the payment processor level. If the scammers can't collect their funds via platforms like PayPal or Stripe, then the majority of ecommerce scams will die out.

"Facebook can't do anything about it," Luan explained to me. "What can you do about it?"

UPDATE: Oct. 29, 2021, 3:34 p.m. EDT This post has been updated with a statement from Facebook.

Follow Mashable SEA on Facebook, Twitter, Instagram, YouTube, and Telegram.

?

Recommended For You

Trending on Mashable

universo-virtual.com
buytrendz.net
thisforall.net
benchpressgains.com
qthzb.com
mindhunter9.com
dwjqp1.com
secure-signup.net
ahaayy.com
soxtry.com
tressesindia.com
puresybian.com
krpano-chs.com
cre8workshop.com
hdkino.org
peixun021.com
qz786.com
utahperformingartscenter.org
maw-pr.com
zaaksen.com
ypxsptbfd7.com
worldqrmconference.com
shangyuwh.com
eejssdfsdfdfjsd.com
playminecraftfreeonline.com
trekvietnamtour.com
your-business-articles.com
essaywritingservice10.com
hindusamaaj.com
joggingvideo.com
wandercoups.com
onlinenewsofindia.com
worldgraphic-team.com
bnsrz.com
wormblaster.net
tongchengchuyange0004.com
internetknowing.com
breachurch.com
peachesnginburlesque.com
dataarchitectoo.com
clientfunnelformula.com
30pps.com
cherylroll.com
ks2252.com
webmanicura.com
osostore.com
softsmob.com
sofietsshotel.com
facetorch.com
nylawyerreview.com
apapromotions.com
shareparelli.com
goeaglepointe.com
thegreenmanpubphuket.com
karotorossian.com
publicsensor.com
taiwandefence.com
epcsur.com
odskc.com
inzziln.info
leaiiln.info
cq-oa.com
dqtianshun.com
southstills.com
tvtv98.com
thewellington-hotel.com
bccaipiao.com
colectoresindustrialesgs.com
shenanddcg.com
capriartfilmfestival.com
replicabreitlingsale.com
thaiamarinnewtoncorner.com
gkmcww.com
mbnkbj.com
andrewbrennandesign.com
cod54.com
luobinzhang.com
bartoysdirect.com
taquerialoscompadresdc.com
aaoodln.info
amcckln.info
drvrnln.info
dwabmln.info
fcsjoln.info
hlonxln.info
kcmeiln.info
kplrrln.info
fatcatoons.com
91guoys.com
signupforfreehosting.com
faithfirst.net
zjyc28.com
tongchengjinyeyouyue0004.com
nhuan6.com
oldgardensflowers.com
lightupthefloor.com
bahamamamas-stjohns.com
ly2818.com
905onthebay.com
fonemenu.com
notanothermovie.com
ukrainehighclassescort.com
meincmagazine.com
av-5858.com
yallerdawg.com
donkeythemovie.com
corporatehospitalitygroup.com
boboyy88.com
miteinander-lernen.com
dannayconsulting.com
officialtomsshoesoutletstore.com
forsale-amoxil-amoxicillin.net
generictadalafil-canada.net
guitarlessonseastlondon.com
lesliesrestaurants.com
mattyno9.com
nri-homeloans.com
rtgvisas-qatar.com
salbutamolventolinonline.net
sportsinjuries.info
topsedu.xyz
xmxm7.com
x332.xyz
sportstrainingblog.com
autopartspares.com
readguy.net
soniasegreto.com
bobbygdavis.com
wedsna.com
rgkntk.com
bkkmarketplace.com
zxqcwx.com
breakupprogram.com
boxcardc.com
unblockyoutubeindonesia.com
fabulousbookmark.com
beat-the.com
guatemala-sailfishing-vacations-charters.com
magie-marketing.com
kingstonliteracy.com
guitaraffinity.com
eurelookinggoodapparel.com
howtolosecheekfat.net
marioncma.org
oliviadavismusic.com
shantelcampbellrealestate.com
shopleborn13.com
topindiafree.com
v-visitors.net
qazwsxedcokmijn.com
parabis.net
terriesandelin.com
luxuryhomme.com
studyexpanse.com
ronoom.com
djjky.com
053hh.com
originbluei.com
baucishotel.com
33kkn.com
intrinsiqresearch.com
mariaescort-kiev.com
mymaguk.com
sponsored4u.com
crimsonclass.com
bataillenavale.com
searchtile.com
ze-stribrnych-struh.com
zenithalhype.com
modalpkv.com
bouisset-lafforgue.com
useupload.com
37r.net
autoankauf-muenster.com
bantinbongda.net
bilgius.com
brabustermagazine.com
indigrow.org
miicrosofts.net
mysmiletravel.com
selinasims.com
spellcubesapp.com
usa-faction.com
snn01.com
hope-kelley.com
bancodeprofissionais.com
zjccp99.com
liturgycreator.com
weedsmj.com
majorelenco.com
colcollect.com
androidnews-jp.com
hypoallergenicdogsnames.com
dailyupdatez.com
foodphotographyreviews.com
cricutcom-setup.com
chprowebdesign.com
katyrealty-kanepa.com
tasramar.com
bilgipinari.org
four-am.com
indiarepublicday.com
inquick-enbooks.com
iracmpi.com
kakaschoenen.com
lsm99flash.com
nana1255.com
ngen-niagara.com
technwzs.com
virtualonlinecasino1345.com
wallpapertop.net
nova-click.com
abeautifulcrazylife.com
diggmobile.com
denochemexicana.com
eventhalfkg.com
medcon-taiwan.com
life-himawari.com
myriamshomes.com
nightmarevue.com
allstarsru.com
bestofthebuckeyestate.com
bestofthefirststate.com
bestwireless7.com
declarationintermittent.com
findhereall.com
jingyou888.com
lsm99deal.com
lsm99galaxy.com
moozatech.com
nuagh.com
patliyo.com
philomenamagikz.net
rckouba.net
saturnunipessoallda.com
tallahasseefrolics.com
thematurehardcore.net
totalenvironment-inthatquietearth.com
velislavakaymakanova.com
vermontenergetic.com
sizam-design.com
kakakpintar.com
begorgeouslady.com
1800birks4u.com
2wheelstogo.com
6strip4you.com
bigdata-world.net
emailandco.net
gacapal.com
jharpost.com
krishnaastro.com
lsm99credit.com
mascalzonicampani.com
sitemapxml.org
thecityslums.net
topagh.com
flairnetwebdesign.com
bangkaeair.com
beneventocoupon.com
noternet.org
oqtive.com
smilebrightrx.com
decollage-etiquette.com
1millionbestdownloads.com
7658.info
bidbass.com
devlopworldtech.com
digitalmarketingrajkot.com
fluginfo.net
naqlafshk.com
passion-decouverte.com
playsirius.com
spacceleratorintl.com
stikyballs.com
top10way.com
yokidsyogurt.com
zszyhl.com
16firthcrescent.com
abogadolaboralistamd.com
apk2wap.com
aromacremeria.com
banparacard.com
bosmanraws.com
businessproviderblog.com
caltonosa.com
calvaryrevivalchurch.org
chastenedsoulwithabrokenheart.com
cheminotsgardcevennes.com
cooksspot.com
cqxzpt.com
deesywig.com
deltacartoonmaps.com
despixelsetdeshommes.com
duocoracaobrasileiro.com
fareshopbd.com
goodpainspills.com
kobisitecdn.com
makaigoods.com
mgs1454.com
piccadillyresidences.com
radiolaondafresca.com
rubendorf.com
searchengineimprov.com
sellmyhrvahome.com
shugahouseessentials.com
sonihullquad.com
subtractkilos.com
valeriekelmansky.com
vipasdigitalmarketing.com
voolivrerj.com
zeelonggroup.com
1015southrockhill.com
10x10b.com
111-online-casinos.com
191cb.com
3665arpentunitd.com
aitesonics.com
bag-shokunin.com
brightotech.com
communication-digitale-services.com
covoakland.org
dariaprimapack.com
freefortniteaccountss.com
gatebizglobal.com
global1entertainmentnews.com
greatytene.com
hiroshiwakita.com
iktodaypk.com
jahatsakong.com
meadowbrookgolfgroup.com
newsbharati.net
platinumstudiosdesign.com
slotxogamesplay.com
strikestaruk.com
trucosdefortnite.com
ufabetrune.com
weddedtowhitmore.com
12940brycecanyonunitb.com
1311dietrichoaks.com
2monarchtraceunit303.com
601legendhill.com
850elaine.com
adieusolasomade.com
andora-ke.com
bestslotxogames.com
cannagomcallen.com
endlesslyhot.com
iestpjva.com
ouqprint.com
pwmaplefest.com
qtylmr.com
rb88betting.com
buscadogues.com
1007macfm.com
born-wild.com
growthinvests.com
promocode-casino.com
proyectogalgoargentina.com
wbthompson-art.com
whitemountainwheels.com
7thavehvl.com
developmethis.com
funkydogbowties.com
travelodgegrandjunction.com
gao-town.com
globalmarketsuite.com
blogshippo.com
hdbka.com
proboards67.com
outletonline-michaelkors.com
kalkis-research.com
thuthuatit.net
buckcash.com
hollistercanada.com
docterror.com
asadart.com
vmayke.org
erwincomputers.com
dirimart.org
okkii.com
loteriasdecehegin.com
mountanalog.com
healingtaobritain.com
ttxmonitor.com
bamthemes.com
nwordpress.com
11bolabonanza.com
avgo.top