What's 'hijack profile scam'? Cybercops explain and provide tips to avoid it
The Philippine National Police-Anti-Cybercrime Group (PNP-ACG) warned netizens against what it referred to as “hijack profile scam” after monitoring rising cases of the modus in social media in the last four months.
But what is it?
PNP-ACG director Maj. Gen. Sidney Hernia explained that the “hijack profile scam” entails unauthorized access to a specific social media account, particularly Facebook which is very popular among the Filipino netizens.
Once the cybercriminals gain access to the account, they usually use that access to send messages to the account owner’s contacts, often requesting urgent financial assistance under false pretenses.
“The scammer uses various tactics to gain access to the profile, such as phishing, hacking, or social engineering techniques,” said Hernia.
Phishing, which is a common type of cybercrime and is now becoming increasingly sophisticated according to IT experts, involves tricking people into revealing sensitive information that includes inadvertent installation of malware (malicious software).
Experts said phishing is one of the many types of social engineering techniques for hackers to gain control of a computer system that includes social media accounts with the usual end goal of stealing personal and financial information.
Other types include baiting wherein a scammer would use false promises to lure victims, scareware wherein the scammer would use threats and false alarms, and quid pro quo wherein scammers would dupe their victims by offering computer-related services.
Hernia said all of them are in violation of the Section 4 (a) (1) (Illegal Access), (b) (2) (Computer-related Fraud) and (3) (Computer-related Identity Theft) of RA 10175 (Cybercrime Prevention Act of 2012).
In order to avoid being victimized, the PNP-ACG has these suggestions to netizens:
1. Use strong, unique passwords for online accounts;
2. Enable multi-factor authentication whenever possible;
3. Be cautious about clicking on links or downloading attachments from unknown sources;
4. Regularly monitor your online accounts for any suspicious activity.
“If you suspect that your profile has been hijacked, immediately report it to the platform or service provider, take steps to secure your account, and notify relevant authorities to avoid potential legal liabilities that may arise from unauthorized access or misuse of your online identity,” said Hernia.