CSCU Social Media Security 2 — Questions and Answers
Question 1: What is social media account hijacking?
- Creating a new social media account
- Unauthorized access and takeover of someone's social media account, typically through stolen credentials or session tokens (Correct answer)
- Sharing someone else's social media posts
- Deactivating your own social media account
Correct answer: Unauthorized access and takeover of someone's social media account, typically through stolen credentials or session tokens
Account hijacking occurs when an attacker gains unauthorized access to a social media account through phishing, credential stuffing, session theft, or exploiting security vulnerabilities.
Social media account hijacking is the unauthorized takeover of a user's social media account by an attacker. Common methods include: phishing attacks that steal login credentials through fake login pages, credential stuffing using passwords leaked from other breaches, session token theft through XSS attacks or network interception, SIM swapping to bypass SMS-based two-factor authentication, social engineering of customer support to gain account access, and exploitation of account recovery mechanisms. Once hijacked, attackers can post malicious content, send phishing messages to the victim's contacts (leveraging trust), access private messages and personal data, demand ransom for account return, or use the account for larger influence operations. Protection requires strong unique passwords, hardware or app-based two-factor authentication, regular review of active sessions and connected apps, keeping recovery information current, and being alert to phishing attempts targeting social media credentials.
Question 2: Why is oversharing personal information on social media a security risk?
- It uses too much internet bandwidth
- Attackers can use shared personal details for social engineering, identity theft, and to answer security questions (Correct answer)
- Oversharing makes your profile load slower
- Social media platforms charge extra for more posts
Correct answer: Attackers can use shared personal details for social engineering, identity theft, and to answer security questions
Personal information shared on social media—birthdays, pet names, schools, vacation plans—can be harvested by attackers for identity theft, social engineering attacks, and to answer account security questions.
Oversharing personal information on social media creates multiple security risks. Attackers routinely mine social media for: answers to common security questions (mother's maiden name, first pet, high school, birthplace), personal details for crafting convincing social engineering and phishing attacks, information for identity theft (date of birth, address, workplace), real-time location data and travel plans (enabling physical burglary when you post vacation photos), professional information for business email compromise (organizational hierarchy, projects, travel schedules), and family relationship data for impersonation attacks. Even seemingly innocent information can be aggregated to build comprehensive profiles. Photos may contain metadata revealing location data. Check-ins and tagged locations reveal routine patterns. Employment details help attackers craft targeted spear-phishing. The aggregation of many small pieces of information—none individually sensitive—can paint a complete picture useful for targeted attacks. Review privacy settings regularly, limit audience for personal posts, and consider what each piece of shared information could reveal to a motivated attacker.
Question 3: What is a social media phishing attack?
- Posting fishing photos on social media
- Using fake messages, posts, or pages on social media platforms to trick users into revealing credentials or clicking malicious links (Correct answer)
- A feature for finding friends on social media
- A type of social media advertisement
Correct answer: Using fake messages, posts, or pages on social media platforms to trick users into revealing credentials or clicking malicious links
Social media phishing uses deceptive messages, fake login pages, fraudulent posts, or impersonated profiles on social platforms to trick users into revealing personal information or clicking malicious links.
Social media phishing encompasses various deceptive techniques on social platforms designed to steal credentials or personal information. Common forms include: direct messages containing malicious links (often from compromised friend accounts), fake login pages that mimic the social media platform to steal credentials, fraudulent brand pages offering fake giveaways or deals, impersonated profiles of friends, celebrities, or authority figures, malicious applications requesting excessive permissions, fake 'account verification' or 'security alert' notifications, and phishing links embedded in post comments. Social media phishing is particularly effective because it leverages the trust inherent in social networks—people are more likely to click links from apparent friends or trusted brands. The informal, fast-paced nature of social media also encourages quick, less cautious interactions. Protection includes verifying sender identity through alternative channels, hovering over links before clicking, being skeptical of unusual requests, using two-factor authentication, and reporting suspicious profiles and messages.
Question 4: Why should you regularly review the third-party applications connected to your social media accounts?
- To check which apps have the best ratings
- Connected apps may retain access permissions and can access your data, post on your behalf, or be compromised themselves (Correct answer)
- To see which apps are available for download
- To increase your social media follower count
Correct answer: Connected apps may retain access permissions and can access your data, post on your behalf, or be compromised themselves
Third-party apps connected to social media retain their granted permissions until revoked, potentially accessing personal data, posting content, or becoming a security risk if the third-party app is compromised.
When you use 'Login with Facebook/Google/Twitter' or grant access to third-party applications, you often provide permissions that allow those apps to access your profile data, friends lists, posts, and sometimes even post on your behalf. These permissions persist until explicitly revoked. Over time, users accumulate many connected apps, many of which they no longer use or remember authorizing. Security risks include: abandoned apps that still have access may be acquired by malicious actors or their developer accounts compromised; apps may have been granted overly broad permissions at a time when users were less security-conscious; data accessed by these apps is stored on their servers, subject to their security practices; compromised apps can be used to spread spam, phishing, or malware through your account. Regular audits of connected apps—revoking access for any that are no longer needed or recognized—is an essential social media security practice. Most major platforms provide an 'Apps and Websites' or 'Connected Apps' section in their security settings.
Question 5: What is the security risk of using public social media profiles for professional networking?
- Public profiles load more slowly
- Attackers can harvest professional details to craft targeted spear-phishing and social engineering attacks against you or your organization (Correct answer)
- Public profiles cost more to maintain
- Public profiles cannot receive direct messages
Correct answer: Attackers can harvest professional details to craft targeted spear-phishing and social engineering attacks against you or your organization
Public professional profiles provide attackers with organizational structure, job roles, projects, and business relationships that enable highly targeted spear-phishing and social engineering attacks.
Public professional social media profiles (particularly on LinkedIn) provide a treasure trove of information for attackers planning targeted attacks. From professional profiles, attackers can learn: organizational hierarchy and reporting structures (enabling CEO/executive impersonation), specific job responsibilities and tools used (crafting relevant phishing lures), project involvement and business relationships (impersonating vendors or partners), upcoming events, conferences, and travel (creating timely pretexts), technology stack and software used (targeting specific vulnerabilities), and email address formats (constructing valid addresses for other employees). This information fuels sophisticated spear-phishing attacks, business email compromise, and social engineering campaigns. While limiting professional networking to private profiles is often impractical, mitigation includes being selective about what details you share publicly, being skeptical of connection requests from unknown individuals, verifying unexpected professional requests through known channels, and training employees to recognize targeted social engineering that leverages publicly available information.
Question 6: What is catfishing in the context of social media security?
- A fishing game on social media
- Creating a fake online identity to deceive and manipulate other users for personal, financial, or malicious purposes (Correct answer)
- Sharing photos of cats on social media
- A technique for gaining more social media followers
Correct answer: Creating a fake online identity to deceive and manipulate other users for personal, financial, or malicious purposes
Catfishing involves creating a fake social media persona using stolen or fabricated photos and information to build trust with victims for deception, emotional manipulation, or financial fraud.
Catfishing is the practice of creating a fake online identity to deceive others on social media and dating platforms. The catfisher typically uses stolen photographs and fabricated personal details to create a convincing persona, then builds relationships with victims over time to exploit them. Motivations include: romance scams (building emotional relationships to eventually request money), corporate espionage (connecting with employees to extract company information), influence operations (fake personas amplifying disinformation), revenge or harassment (creating fake profiles to defame someone), and intelligence gathering (social engineering through false trust). Warning signs include reluctance to video call, inconsistencies in personal stories, new accounts with few connections, rapid emotional escalation, and requests for money or sensitive information. Protection measures include reverse image searching profile photos, being cautious of unsolicited connection requests, verifying identities through video calls, never sending money to people you have not met in person, and being skeptical of profiles that seem too perfect or whose stories don't add up.
What is social media account hijacking?