Hacker News new | ask | show | jobs
by thecoppinger 1304 days ago
I faced a somewhat similar predicament earlier this year.

I still have no idea how, but my 2FA enabled Facebook account (with a unique and secure password) was compromised while I was sleeping. Shortly after, the attacker started using my Business Manager account to run ads for fake products on their scam stores.

Here's the catch: my personal Facebook account was permanently banned right away, but my Business Manager account wasn't.

How? According to other folks who had the same done to them around that time, the attackers would upload CSAM content on your timeline so that you get immediately banned/locked out.

Well, that means I could no longer retrieve/change my business manager account, which gave the attacker free reign to run ads for about a month. To some degree this means that Facebooks CSAM system gives the attackers a way to compromise Business Manager accounts more efficiently.

I submitted a ban appeal, but didn't hear back. I read online that if you have an Oculus, reaching out via their support is the only real option, so I did just that.

I wrote down a detailed account of the timeline of events, along with screenshots etc., and sent it to an Oculus support agent. In fact, they thanked me during the interaction or providing 'the most detailed' report they'd seen.

The evidence was pretty clear: at 5am or so, someone had logged in to my account via a foreign IP, change my email to a Chinese address and added a hardware 2FA key. The ads they were running to scam stores were often in Chinese, too. Not exactly a difficult case to crack.

They assured me I'd hear back within 7 days, but a month or so later I received an automated email from Facebook stating that the time for my appeal had expired, so the account would stay permanently banned.

That was mildly infuriating, given I never heard back from anyone.

What did losing my Facebook account mean to me?

As much as I'd been considering moving off social media, it briefly ruined my life.

* I'd had my account since I was 13 years old in 2008. I had a few thousand connections on there, many fleeting and superficial, but at least a few hundred with folks around the world that I care about and have no way of reaching now.

* 90% of communication here in NZ transpires via Facebook Messenger, so I was immediately cut off from my community and friends. What's worse, many have since told me that they were worried I'd blocked them.

* My income from the time came from selling trading cards in FB groups while I was closing an investment round. I lost the ability to do so, and had to move out of my apartment to live outside of the city with my in-laws.

* My father passed away a few years ago, and I had countless photos of him on my account, as well as our message history. This honestly hurt more than anything else.

All in all, this experience has left me a deep scar. I guess I needed to learn a lesson around not relying on one platform so heavily, and to some extent not backing things up such as the photos, but I really wish Facebook could have just done the reasonable thing and let me back in.

Finally, I have no idea if I was reported to the police/LE in any capacity regarding whatever was posted on my account to have me banned. Am I on some kind of list now?

A boring, technocratic dystopia.

edit: on the off chance anyone from Meta reads this and thinks they can help, I would be over the moon to get even a chance of having my account restored. I was told to speak to an Australian law firm who charge $3,500 to hound Facebook to get accounts restored in situations like mine, but unfortunately that's just not within my means.