iPhone app iPad app Android phone app Android tablet app More

Featuring fresh takes and real-time analysis from HuffPost's signature lineup of contributors
Donna Estes Antebi

GET UPDATES FROM Donna Estes Antebi
 

Facebook: I've Been Hacked

Posted: 05/31/2012 1:55 pm

Hackers have a far better understanding of the weakness of Facebook's privacy issues than any of us. Right now, thanks to some devious cyberjerks, many of my Facebook friends think I'm an obnoxious, knockoff Nike shoe vendor. Donna Antebi: Shoe Hawker.

The nightmare began when I logged-on to Facebook and, to my horror, found that "Donna Antebi" was hell-bent on selling her friends knock-off, gold lamé, tricked-out Nike sneakers. My closest friends knew immediately that I'd been hacked. Think about it. Could this really be me? Recommending shoes without heels? That's obviously an impostor! Messages from my not-so close friends rolled in: "Hey, Donna. Thanks for the cheap shoes. Unfriending you, boycotting Nike. Btw, have you been drinking?"

Mortified, I tried to report the problem to Facebook, hoping I could quickly retrieve my account. No such luck.

The hackers hit me with a one-two punch that thwarted my ability to access help from any of the usual Facebook security solutions. First, they hijacked my www.facebook.com/donnaantebi account and changed the URL to www.facebook.com/losokana. Next, they used my stolen registration information -- which included my password, email, and cell phone number -- to set up a new Donna Antebi account www.facebook/antebi.donna. They even pre-loaded it with some of my friends and personal photographs. They then began a campaign to relentlessly harass a few thousand of my nearest and dearest friends by spamming them with fake Nike solicitations.

The hackers' new party trick was effective. Changing the name of my URL, and setting up a decoy account, meant that all of my complaints and subsequent Facebook security solutions bypass my real account, which is no longer under my name, and instead, get redirected to the fake Donna Antebi account. The hackers made it impossible for me to correct the problem via computer complaining -- which is the only frustrating way to communicate anything to Facebook. Genius.

Every day since April 22, 2012, I have emailed back and forth with a Facebook robot in their virtual complaint department, trying in vain to regain custody of my account. All the usual, "reset your password," "send a code to a trusted friend," or "show your identification" solutions continue to be redirected to the fake account. It's maddening.

These scammers are bold. On my hijacked account, they even pretend to be me and respond to my friends as if I'm answering. "Hey Donna, is this really you?" "Oh yes, I just really love these Nike shoes!" There is nothing I can do but watch as the bad guys leisurely have their way with thousands of my very aggravated friends.

My Facebook detractor friends launched into a sea of "I told you so's" and "that's why I don't use Facebook." But the fact is, Facebook is here to stay, and I would like to have my account back. Realizing the futility of an automated solution, I decided to call the company, and that's when I got an even bigger eye-opener. Telephone prompt option one: "Thank you for calling Facebook. Unfortunately, we do not offer customer support at this time." Then it gets even more alarming. Option two is for law enforcement. "Please note that due to a large call volume, current call back time is 2-4 days." For law enforcement? How is that for disturbing? What if the FBI is hot on the tail of a child-abduction lead? Too bad. Get in line like the rest of us.

I wanted to understand how this could happen, so I searched "How to hack Facebook." Much to my surprise, 294,000,000 results came up! Hackers go after Facebook 600,000 times a day! Not only is hacking Facebook a potential felony, it's also very big business. There are pages and pages of people and companies that, for a fee, will either hack into Facebook for you -- guaranteed, or teach you how to do it yourself. Want discover what your boss is doing? Or maybe how to gain real insight as to why your relationship status is "complicated?" You can, for a price. Really? Maybe they can fix this for me.

Everyone on Facebook should understand what is at risk if they are hacked. I have discovered the hard way that the implications of privacy violations are far greater than marketing companies appropriating our data to sell us targeted goods, or the inconvenience of losing friends and starting over from scratch. Being hacked flings the door wide open for identity theft -- the fastest growing crime in the United States.

I gave my home address to friends on Facebook. I have also acknowledged the identity of my sweet mother, who still lives in the town where I was born. Two clicks on www.genealogy.com and the hackers have my mother's maiden name. Bingo. My Facebook disclosures have inadvertently rolled out the red carpet for criminals to access my bank accounts, and I've set myself up for credit card fraud too. Also -- if you think Facebook is the photographic time capsule of your life, you better think again and back up those photographs now. You are only one hack away from being violated and walking a mile in my counterfeit Nike shoes.

Hey, Facebook, are you listening!? This is America. We believe in quality products and customer service. You have made company growth a priority at the expense of customer care. Doing business "the hacker way" allowed you to swiftly create a corporate Godzilla. Your philosophy of "Done is better than perfect" has clearly worked well for your wallet. Your letter to investors outlined many things, including your five core values: Focus on Impact, Move Fast, Be Bold, Be Open, Build Social Value. What you failed to mention is concern for the user or the quality of your product -- which is nowhere near perfect.

Mr. Zuckerberg, the IPO is completed. It's now time to stop counting your money and catch your breath. You need to focus on shoring up Facebook infrastructure before funding more expansion. Facebook hacking is out of control. If user privacy and security is not strengthened, then Facebook should issue a bold warning on every page -- just like the cigarette companies do. "Warning! Facebook is not a secure site. Users may be targeted by criminals, and are at serious risk for personal and professional violation."

On behalf of all Facebook users, I would like to say that when robot solutions run dry, the ability to reach a fraud division with real, live human beings should not be too much to ask. By the way, your plan to offer privacy software that your users pay for, and Facebook profits from, is not good enough. Facebook can afford to do a better job. There are no good excuses for not doing so. You spent one billion dollars to acquire Instagram. How about parting your wallet for some Instahelp? Remember, corporate greed is uncool even if people under 30 run the company.

And regarding Nike, Mr. Parker, CEO -- all press is not good press. Certainly the incessant solicitation to buy fake Nike's seems like something that would pique your interest? Maybe you'll have more luck getting through to Facebook than I did. I suggest you start by tracking down who is behind "losokana" and prosecute. Demi Lavato's hacker just got one year in prison, so maybe we have a case. Hey... if you do manage to speak with Mark Zuckerberg, Chris Cox, Dustin Moskovitz, Adam D'Angelo, Jeff Rothschild, Chris Kelly, or any one of Facebook's 3,559 tech-savvy employees, could you please ask them to rescue my thousands of friends and associates from the hijacker operating as facebook.com/losokana and return the account to me: facebook.com/donnaantebi?

Right now I am going to do something that's becoming less common -- pick up the old-fashioned telephone. I need to apologize to my friends and family for suggesting they buy ugly, gold, bedazzled fake shoes. Wish me luck. I have a lot of explaining to do. In the mean time, you can all reach me at what I hope will be my temporary Donna Estes Antebi Facebook account, with the ridiculously long URL: www.facebook.com/people/Donna-Estes-Antebi/617185477

(Note: Post-Facebook hack, my mail has been stolen, my banking has been compromised and two checks linked to my credit card were cashed. I tried to reach the Facebook PR department for comments, but as of this publication, I still not have heard back).

 

Follow Donna Estes Antebi on Twitter: www.twitter.com/donnaantebi

FOLLOW TECH
Hackers have a far better understanding of the weakness of Facebook's privacy issues than any of us. Right now, thanks to some devious cyberjerks, many of my Facebook friends think I'm an obnoxious, k...
Hackers have a far better understanding of the weakness of Facebook's privacy issues than any of us. Right now, thanks to some devious cyberjerks, many of my Facebook friends think I'm an obnoxious, k...
 
 
  • Comments
  • 35
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2  Next ›  Last »  (2 total)
photo
HUFFPOST SUPER USER
LawGeekNYC
I am Queens Boulevard.
11:33 PM on 06/23/2012
You spelled "Nikes" wrong in the second to last paragraph. There is no early reason to put an apostrophe there.
photo
Iamrebelriser
iamrebelriser
02:18 AM on 06/03/2012
This is exactly why I will never join the Facebook crowd. I've said all along that I could never trust a site that "accidently" and too often lets people's information out. Whether it is hackers or mistakenly letting information out, it is still not a safe site as far as I'm concerned, and so what if Facebook will always be around? That is no reason to let them have our information to do with as they please. Just for an experiment, type your own name into search and see what you learn about yourself that is out there for anyone to see. Also, ask any senior citizen about all of the junk mail they get from hearing aid companies and other sharks once they begin getting social Security & are on Medicare.That should be enough for anyone to decide not to give ANY information over for a Facebook or Twitter account. Not worth it as I see, since already too much information about us is available and so much of our information is available online just through government agencies.
03:10 PM on 06/02/2012
I do not believe you were the victim of a weakness of Facebook. There would be more many more people coming forward, especially targets of more value. If it were as easy as you suggest then Facebook would be useless. As others have said, it is more likely you were a victim of phising or had a weak password or (if Facebook uses them) security questions. Again, if it is as easy as you suggest go ahead and hack your account back.
11:50 PM on 06/01/2012
Is facebook really less secure than any other site? I doubt it. The way you were hacked seems to be basic social engineering, and not anything specific to facebook itself. What was different about facebook than other sites was the data you stored there. People constantly underestimate the value of the information they store on facebook. Basically, you should have learned the value of discretion of information you share (although honestly, I share some of the same information) and the value of a secure password (which I would test against common password crackers).
photo
HUFFPOST SUPER USER
Tingalor
The Dude...takin 'er easy for all us sinners.
04:10 PM on 06/01/2012
Hey Donna, multiple thousands of friends? You learn a lot about a person on how many Facebook friends they have. Sounds like you'll accept anyone and everyone that takes a gander at your profile, which makes perfect sense about why you were hacked.
photo
BeerLover
Carpe Diem!
10:18 AM on 06/03/2012
Good point! I think I have the fewest friends of ANYONE I know on facebook.....because I only friend actual friends and family.
photo
HUFFPOST SUPER USER
Tingalor
The Dude...takin 'er easy for all us sinners.
09:02 AM on 06/04/2012
I'll admit I'm still weening my list out from college (three years later), but my numbers are (and never were) no where near that!
photo
nermz345
floating somewhere over southern new jersey
12:13 PM on 06/05/2012
you're right. i never understand those people who have what seems like a "bah-jillion" friends. and it continues to amaze me how many people who's facebook pages are public.
photo
HUFFPOST SUPER USER
Tingalor
The Dude...takin 'er easy for all us sinners.
12:24 PM on 06/05/2012
Reminds me of the girls you'd meet in passing at a party in college and you'd wake up to facebook request the next morning.
This user has chosen to opt out of the Badges program
01:31 PM on 06/01/2012
"the fact is, Facebook is here to stay"

Sure, like AOL and Compuserve, no doubt about it.
photo
Iamrebelriser
iamrebelriser
02:24 AM on 06/03/2012
And why is it a good reason to be part of Facebook just because it is here to stay? Prostitution is here to stay too, but that does not make it good for anyone. I refuse to be part of Facebook, and I resent it that persons in media try to get us to contact them using facebook. Just say "NO."
01:19 PM on 06/01/2012
So, you don't have Nikes?
11:29 AM on 06/01/2012
Nobody needs Facebook. It's just a bauble you eventually get tired of.
Would you put out your personal info out on a CB radio? That's what Facebook is except more permanent.
I don't even use my real name or birthday on FB. I don't store passwords and if you found my computer you'd be hard pressed to find out who it belongs to because I don't keep identifying info on my box. I disable the microphones and put black tape over the camera.
FB is just a bit of fluff so best not to get too attached.
photo
HUFFPOST SUPER USER
Parade Keegan
I Can Hear You
10:50 AM on 06/01/2012
I would think this would be frustrating. Then again when people use FB for to promote their own commercial interests (a few thousand friends?) I can see how their "accounts" could become targets. Like any commercial enterprise they should have paid you a commission such as legitimate advertisers do. I suggest setting up your own web site.
This user has chosen to opt out of the Badges program
photo
08:35 AM on 06/01/2012
the upside is that someone can only get hacked by their own actions or something they are 'tricked' into doing to give out the personal information in relation to their account. But overall it comes back to the actions or the awareness of the account user. They must of clicked on a link or been invited to a fake login page, and then not seen the situation for what it truly was. It still comes back to those actions that invite a person to end up selling out to the potential hacker by their own actions
08:29 AM on 06/01/2012
But I have heard that Facebook account can not be hacked now a days. Facebook has made its pages highly secure. There is no direct HTML in their pages. In Facebook pages everything runs in javascript. So it is difficult to hack.


This is Hari from www.funbutlearn.com
03:23 PM on 06/01/2012
You obviously don't know what you are talking about.
photo
KarmaPatrol
Riverboat Gambler, satellite whisperer. Independe
07:40 AM on 06/01/2012
Welcome to the downside of the digital age. Hackers are increasing infiltrating all aspects of online life for fun or for (their) profit. My attempted hacking came after trying to log on at the airport in Bucharest, Romania, but Facebook caught it.
This user has chosen to opt out of the Badges program
photo
08:37 AM on 06/01/2012
There may be some ways for Facebook to tweak their security. But, the fact is, they could run the tightest ship possible and people will still lose their accounts to hackers if they engage in unsafe internet use habits. What really needs to be done is an education campaign to teach people how to avoid falling for scams or using their machines in ways which compromise their security.

Using public WiFi is an extremely dangerous thing to do if one doesn't take precautions. In such situations, you should have a software firewall on your machine and only connect to websites via an encrypted connection. If there is no "https" in the URL, don't log into it. Anyone with a packet sniffer will be able to get your login credentials. There's also the risk that the public Wifi access point you are hitting is a fake and that, when you login to a site like "Facebook," it's actually a fake page that harvests your data for an attacker before passing you on to the real site. For those who truly need to be security conscious, they are better off using a personal cellular modem that plugs directly into their computer. There are prepaid models with plans for as cheap as $10-$15.
This user has chosen to opt out of the Badges program
06:29 AM on 06/01/2012
So much fail. First mistake was assuming that facebook was a secure site, and it was all downhill from there.

I didn't know people thought facebook was secure. That's interesting.
04:02 AM on 06/01/2012
Wake up already.

Every site out there can be hacked. And often it is a simple matter of guessing passwords.

Relying on some faceless company to protect you was your second mistake. Your first was to put out a bunch of personal info in the first place.
11:41 AM on 06/01/2012
People are putting their stuff in the "Cloud." Eventually they'll get hacked. Another thing is that now the government is screening e-mails and such, what's to keep these people from selling say business secrets or blackmailing you over an affair, ect. Politicians could buy info on their challengers. With so many crooks out there and a government that supports spying on citizens you would have to be crazy to trust any of your personal info on the web.
10:47 PM on 05/31/2012
The SAME thing happened to me! I had shoe spam all over my FB, and I have yet to recover my account. Thanks for explaining the situation, Donna. Please let your readers know if there's any follow up. Hope you had better luck than I did!