Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

New Phishing Scheme Using Fake Copyright Infringement Notices

New Phishing Scheme Using Fake Copyright Infringement Notices

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

A new phishing campaign targeting Facebook users has been identified by cybersecurity firm Trustwave. In this campaign, hackers use fake copyright infringement notices to trick users into giving away their account details.

The phishing messages claim that Facebook will delete the user's account within 48 hours unless they fill out an appeal form to protect themselves. This appeal form collects personal information from the user, such as their name, phone number, and address.

The phishing attack is delivered through email and includes a link to an actual Facebook post. When users click on the link, they are redirected to a fake, custom-built site appearing to be customer support. On this site, the user is prompted with a fake One Time Password (OTP) check. When the OTP fails a pop-up offers an alternative authentication option. By selecting the other option, users are redirected to the official Facebook site.

Users should be cautious if they receive copyright violation notices, as this could signify a phishing attack. Additionally, Trustwave advises users to always verify the authenticity of the source before entering any personal information.

To protect themselves against phishing attacks, users should also use strong and unique passwords for their accounts. In addition, enabling two-factor authentication and being wary of clicking on links in unfamiliar emails can further help reduce the chance of being a victim of these types of attacks. Finally, regularly reviewing the permissions and app connections associated with your Facebook account is also a good idea, as these can sometimes be a vector for phishing attacks.

By following these simple precautions, users can help to protect themselves and their personal information from falling victim to this or any other phishing campaign. It is important to remain vigilant and stay up-to-date on the latest tactics used by hackers in order to keep your information and accounts safe.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime