Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Facebook And Linkedin Data Exposures Show The Scope Of Account Takeover Risks
Articles

Facebook And Linkedin Data Exposures Show The Scope Of Account Takeover Risks

Ralph KooiBy Ralph KooiAugust 5, 2021Updated:January 18, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
New Generation of Cyber Risks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Account takeover (ATO) fraud is big business for criminals, and it’s on the rise. One study found that ATO attacks on ecommerce retailers selling physical goods increased by 378% during the second quarter of 2020, compared to the same period in 2019. What’s driving this increase? In many cases, it’s personal data that’s all too easy to find online, and it doesn’t even need to be sensitive information like passwords in order to fuel ATO attacks.

Recent news about Facebook and LinkedIn user data underscores just how much material fraudsters have at their fingertips and how they can use even publicly available information to commit fraud. In April, news broke that personal data such as phone numbers, email address, birthdates and genders from more than 500 million accounts on each of the two social networks had been collected by data-scraping tools and shared on the dark web.

Facebook in particular took heat for not notifying users at the time the data-scraping incident was first reported, back in 2019. Both Facebook and LinkedIn have noted that the exposed data was shared by users and wasn’t the result of a breach of secured data. However, security experts quickly outlined a number of ways that the scraped data could be used to commit fraud.

What fraudsters can do with scraped social media data

The quantity of email addresses and phone numbers exposed by the data scrapers is particularly worrying, because scammers can target victims for phishing scams via email, text and voice calls to trick them into handing over login credentials and financial information. With those resources, they can take over social media, banking and retail shopping accounts. For example, by targeting Facebook users for phishing scams and stealing their login information, fraudsters then have access to any payment methods the victims have stored in Facebook for social shopping. They also have the ability to sign into the victim’s accounts at online retailers that allow for social logins.

With a bit of research, a scammer armed with a phone number and some other personal data can also commit SIM-swapping fraud by impersonating the victim to their cell provider’s customer service team to take over the victim’s phone number. Then they can get the victim’s messages and calls on a device in the fraudster’s possession, control any SMS-based two-factor authentication the victim has on their accounts and effectively hijack their identity. And because, as one observer noted, most people rarely change their phone numbers and email addresses, this kind of data has a long “shelf life” for fraud once it’s exposed.

How to stop account takeover fraud from hurting your online store

It’s clear that login credentials and social logins can be compromised by fraudsters with stolen data, so the first and simplest ATO prevention step is to review the way you handle customer authentication. If you require customers to sign in with a user ID and a password, consider implementing strong password requirements so their credentials are harder to crack. You can also encourage shoppers to choose a unique password for their store account, to reduce the risk of fraud if their reused password is leaked elsewhere.

Social logins make store account access easy for customers, but they also mean that your customers can lose access to their account with your store if they ever close or are locked out of that social account. You may want to review your use of social logins, to see if the convenience for customers outweighs the cost of fraud due to compromised social accounts. Keep in mind that 44% of Australian shoppers in a March 2020 Sapio survey for ClearSale said they’ve abandoned purchases because of friction during the checkout process, so you need to balance safety with ease of use.

Regardless of how your customers sign in or check out in your store, it’s crucial to screen every order to authenticate the customer—even if they’ve been shopping with you for years. AI-driven fraud programs can quickly detect unusual behavior by existing customers to help spot ATO fraud. These algorithms can also evaluate first-time customers for potential identity theft.

When orders are flagged, they should go immediately to manual review, where experts can decide if the order is good or fraud. That can avoid false declines that drive customers away for good. Among Australian consumers, 38% told Sapio they’d never shop again with a merchant that declined their order, and 22% would say something about the decline on social media. Only 8% said they’d never shop again with a merchant after a fraud experience with their store.

Account takeover fraud shows the risks that merchants take if they assume that their customers—even established customers—are who they claim to be. That’s not an argument for treating shoppers with overt suspicion. Instead, it highlights the need to use best practices and technology to authenticate customer identity in real time for every transaction, even orders coming from longstanding customers, to protect their accounts and your revenue.

Ralph Kooi

Ralph Kooi is the Country Manager Australia at ClearSale, a full-service cloud based platform that automates Fraud Prevention, allowing businesses to increase sales while reducing risk. ClearSale is the only company that never automatically declines an order before a manual review process, which allows us to achieve industry-high approval rates while eliminating false declines and brings in additional revenue for our customers. Ralph Kooi has previously worked for several International SaaS businesses while based in Australia.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}