Hacker News new | ask | show | jobs
by rograndom 1282 days ago
I was hoping to write up a TellHN about something similar once my situation was resolved, but the same thing happened to me at the end of November.

My Facebook account has MFA and a very strong, unique password. I began to receive emails about my "account recovery code", which I ignored. A day or so later I received an email that MFA was disabled, and then one that my password had been reset. I was able to immediately reset it again from a new device, log in, log out all other sessions and re-enable MFA. Then a few hours later the same thing happened, but by that time it was overnight and I wasn't able to catch it in time. I woke up to the emails outlining that process again along with one saying my account had been suspended.

I went through the recommend process of supplying my ID, which was rejected as "forged" and I was told my account would be terminated, decision is final, no ability to appeal, etc. Luckily (maybe?) my account created Facebook Apps for some state and federal government offices and personnel, and those went away at the same time. Now there's some high level people butting heads with the Meta Pro team on my behalf, and I'm watching the emails as they go back and forth.

It's about 3 weeks later and I still haven't gotten access back yet, but we've collected dozens of other cases of people that have had the same thing happen going back to mid-October.

It appears to be a scam where attackers are able to somehow gain access to Facebook accounts bypassing passwords and other authentication processes and then post about crypto and NFT sales on Facebook marketplace. If the account has a credit card attached, they will buy $100-500 worth of Facebook ads for the same thing.

We're all wondering what happens to the regular people who don't have the business connections to have the ability to reach out to someone that is able to bypass the regular process that is failing in a major way?