A very serious scam has spread, with an SMS message with an OTP code and a Facebook or Google logo as if it were officialانتشرت عملية احتيال خطيرة جداً، بتوصل رسالة SMS فيها كود OTP ومعاها شعار فيسبوك أو جوجل كأنها رسمية
A very serious scam has spread, you receive an SMS message with an OTP code with the logo of Facebook or Google as if it were official, like the one in the picture: 151853 is the Facebook for Android confirmation code The trick here is to fake the sender's name - the scammer can make the message appear in the name of Facebook and it is not from Facebook at all. How does the process work? 1. The OTP code you requested will be sent to you. 2. Minutes later, someone claiming to be from Facebook's technical support calls you and says, "You got a code by mistake, we paid the code to stop the hack." 3. Or it sends you a fake link facebook-security-check.com and asks for code to be inserted there. If you give him the code, your account will be stolen instantly. Key danger signs: • An OTP message and you have not asked for a login. • The sender appears as Facebook, but when you enter the details, you find a regular number and not a verified code, or you meet it, the sender cannot accept the replies like the one in the picture. • You are asked to share the code with anyone or enter it in an external link. How to stay safe: 1. Don't share the OTP code with anyone at all, Facebook and Google are old enough to ask you for the code in a call. 2. Do not click on any link in the OTP message. 3. If you receive a code that you did not request, log in immediately and change your account password and activate two-step verification. 4. In Truecaller, open the sender's details, if it is not documented with a blue tick and an official company, block it and report it as spam. Security Researcher: The Warrior is a Loophole Catcher انتشرت عملية احتيال خطيرة جداً، بتوصل لك رسالة SMS فيها كود OTP ومعاها شعار فيسبوك أو جوجل كأنها رسمية، زي اللي في الصورة: 151853 هو رمز تأكيد Facebook for Android الخدعة هنا هي تزوير اسم المرسل - المحتال يقدر يخلي الرسالة تظهر باسم Facebook وهي مش من فيسبوك أصلاً. كيف تتم العملية؟ 1. يبعت لك كود OTP انت ما طلبته. 2. بعدها بدقائق يتصل بك شخص يدعي انه من الدعم الفني لفيسبوك ويقول "وصل لك كود بالغلط، ادينا الكود عشان نوقف الاختراق". 3. أو يبعت لك رابط مزيف facebook-security-check.com ويطلب تدخل الكود هناك. لو اديته الكود، حسابك هيتسرق في نفس اللحظة. علامات الخطر الرئيسية: • رسالة OTP وانت لم تطلب تسجيل دخول. • المرسل يظهر كـ Facebook لكن لما تدخل على التفاصيل تلاقيه رقم عادي وليس رمز موثق، او تلاقيه لا يمكن للمرسل قبول الردود زي اللي في الصورة. • يطلب منك مشاركة الكود مع أي شخص أو إدخاله في رابط خارجي. كيف تبقى آمناً: 1. لا تشارك كود OTP مع أي شخص نهائياً، فيسبوك وجوجل عمرهم ما هيطلبوا منك الكود في مكالمة. 2. لا تضغط على أي رابط في رسالة الـ OTP. 3. لو وصلك كود لم تطلبه، ادخل فوراً وغير باسورد حسابك وفعل التحقق بخطوتين. 4. في تروكولر افتح تفاصيل المرسل، لو مش موثق بعلامة زرقاء وشركة رسمية، اعمل له حظر وابلاغ كـ غير مرغوب فيه. باحث امني : المحارب صائد الثغرات