This is something really scary and could affect your Facebook account as well.

I just got a notification in my profile saying someone has sent me a message on Facebook. As you can see in the screenshot, the notification looks like a real one.

facebook phishing

I clicked that link but instead of opening my Facebook  Inbox, I was taken to the Facebook login form saying "you must log in to see this page".

The only problem is that this login page is not hosted on facebook.com but fucabook.com (possible a phishing site) and had I not seen the address bar, my Facebook credentials would have easily landed in someone else’s inbox.

facebook password request

The app in question is called Inbox and the bad part is that it is still available in the Facebook Applications directory.

It’s quite possible that the same developer may have created many different Facebook apps with the same purpose so make sure you look at the status bar of the browser before you click any notification messages on Facebook.

Is my Facebook account hacked?

If you see such a notification in your Facebook profiles, it doesn’t necessarily mean that your Facebook account has been hacked. What it means is that one of your Facebook friends added that "rogue" application to his or her Facebook page and that action probably caused this phishing related message to show up in your profile.

You may also like:

  1. Send a Message to All Fans on a Facebook Page
  2. My Facebook Account Got Hacked
  3. Twitter Tip: Send a Direct Message to Yourself
  4. Should You Delete or Deactivate Your Facebook Account
  5. Verifying Ownership of a Facebook Page