South Africa’s Facebook Hackdemic
During the past 24 months, many South Africans have found their Facebook, Instagram, and WhatsApp accounts taken over by cybercriminals.
While these attacks have targeted some prominent individuals like radio personalities, many people who are not in the public eye have also been victims of account hijacks.
The hijacking begins with a fairly sophisticated phishing attack that tricks people into giving out their usernames and passwords.
First, the criminals sent a flood of messages to potential targets.
These exploited a layout quirk in Facebook Messenger, allowing them to hide a link to an attack site resembling a real “Show profile” button.
Clicking on the button opens a Facebook login page, complete with the correct “m.facebook.com” URL in the browser bar.
However, this is faked using a fullscreen image or some other kind of trick to make the attack page look legitimate on a smartphone screen.
Once the attackers have your username and password and they successfully take over your account, they weaponise Facebook’s safety and security policies to keep rightful users locked out.
The first thing they do is change the compromised account’s password and any recovery options they can gain control over to make it harder for the legitimate user to regain control.
In one instance where a personal Facebook account was the administrator of a business page, they added one of the attackers as an admin before posting heinous content from the personal account.
This resulted in the personal account being banned, while the attackers now controlled the business page.
The user’s Instagram profile had also been hijacked, as their personal Facebook account was also their Instagram login.
This is the brilliance of the attack — the cybercriminals turn Facebook’s community safety policies and systems against legitimate users to ensure they can’t get their accounts back without a lengthy investigation.
With their Facebook account banned, users don’t even have a way to log an issue with Meta Platforms to try and recover their social media profiles.
For users to prove that they did not actually post the objectionable content in question is impossible — their only hope is for Facebook’s customer support to conduct more than a superficial investigation.

Screenshots of the Facebook messages baiting users to click on “View Profile” (left), which will navigate to an attack site (right)
MyBroadband contacted Facebook when an internationally renowned artist reached out to us at his wit’s end.
It should be noted that this person is more than tech-savvy. However, the phishing attack caught him while distracted at precisely the wrong time.
He had received an influx of suspicious new followers on his business page, along with a flood of one-word greeting messages.
To try and figure out what was happening, the target responded to one of the messages and clicked on the “View Profile” button.
Had he not been distracted, he would’ve noticed the red flag at this point — he was asked to log in to see the profile.
At the time, he chalked it up to browsing from his personal account when the messages had been sent to his business account.
Of course, in hindsight, he would not have been asked to log in again to view someone’s profile.
By the time he realised his mistake, it was too late. The attackers had hijacked his profile completely and locked him out.
Facebook took more than two weeks to restore the banned account and return control of it to the victim.
Three days later, Facebook had relinked his account to his business page.
Gallingly, the attacker who had hijacked his account was bragging about their exploits online. On Facebook, no less.
A Vietnamese hacker, “Nguyen Vu”, posted screenshots and videos on Facebook of all the accounts they had compromised, several of which were South African.
The goal behind the hacks seemed to be to sell Facebook advertising to unscrupulous operators.
By compromising legitimate users’ accounts, attackers gain access to a reputable profile and often some Facebook advertising credit, too.
Vu’s Facebook profile was eventually banned — but only sometime after the victim’s accounts were reinstated.
However, even though our artist’s accounts had been restored, he remained banned from doing any Facebook marketing.
He found himself stuck in a bureaucratic quagmire.
Attempting to unblock advertising functionality would get his main Facebook profile suspended for suspicious activity.
After getting his account reinstated once more, contacting Facebook support only yielded the same troubleshooting steps that previously got his account suspended.
The victim was still stuck in a Kafkaesque loop eight months later, unable to give Facebook their money and locked out from a substantial portion of their following.
While some core Facebook marketing functionality was eventually restored, many features were still broken or unavailable for his page 22 months later.
