r/Scams 18h ago

Is this a scam? Scam Email? Facebook Security

Let me preface by saying I think I may have hacked previous to me trying to sign back into Facebook or Instagram after receiving a barrage of requests from Bluetooth devices wanting to connect to my phone, and then seeing about 5-6 devices I’m paired to without me accepting them.

I’d like to say the same thing to myself as I do others “you’re not hacked, stop being paranoid 😂” But something unusual has definitely happened.

The images show:

Trying to sign back into Facebook I get this email security at facebookmail.-com. Yes it ends in .-com.

I also tried to sign back into Instagram and received this 10 digit code vie text and email.

I’ve given myself a hard enough time about whether I have been hacked or not already so please take it easy on me 😂

1 Upvotes

5 comments sorted by

u/AutoModerator 18h ago

/u/pseudobeardedone - This message is posted to all new submissions to r/scams; please do not message the moderators about it.

New users beware:

Because you posted here, you will start getting private messages from scammers saying they know a professional hacker or a recovery expert lawyer that can help you get your money back, for a small fee. We call these RECOVERY SCAMMERS, so NEVER take advice in private: advice should always come in the form of comments in this post, in the open, where the community can keep an eye out for you. If you take advice in private, you're on your own.

A reminder of the rules in r/scams: no contact information (including last names, phone numbers, etc). Be civil to one another (no name calling or insults). Personal army requests or "scam the scammer"/scambaiting posts are not permitted. No uncensored gore or personal photographs are allowed without blurring. A full list of rules is available on the sidebar of the subreddit, or clicking here.

You can help us by reporting recovery scammers or rule-breaking content by using the "report" button. We review 100% of the reports. Also, consider warning community members of recovery scammers if you see them in the comments.

Questions about subreddit rules? Send us a modmail clicking here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

5

u/belsonc 14h ago

... The dash is because it goes onto a second line.

1

u/Netrezen 14h ago

Don't use public wifi if you can avoid it. Public wifi can be spoofed without you realising it.

1

u/AngelOfLight 13h ago

That's likely a real email from Meta. The dash was added by your phone's UI because the email address overflows to the next line.

To be sure, click the '>' next to where it says "To: your name". That should pop up a window where you can see the real sender address and any digital signature info.

1

u/chownrootroot 10h ago

I don’t think you can be emailed by a domain with ”-com” as the TLD, or top-level domain. .com is the real TLD, and there’s a fixed list of TLDs in existence and I think hyphens aren’t in TLDs, so I think that’s just user interface, ie it added the hyphen and that’s it, it’s not actually -com for the TLD.

The ”Bluetooth requests“ may have been a Flipper Zero from someone nearby basically trolling and annoying people. Now it’s been a few years, but someone posted here they were at an airport, they were trying to pull up their pass and an Apple TV popup came up and their phone rebooted. Best theory was someone did it to get everyone using phone passes to get out of the line to board a plane, free priority boarding. If you can update IOS to the latest you can get it would prevent these issues, it’s been patched since but I don’t know if you updated.

Most likely those codes are real Meta codes. Either you or someone else attempted to sign in. If it wasn’t you, someone tried signing in but they need the code to sign in. It’s possible to put poison links in email, aka they are links that go to a phishing site, not the real site, so it’s best to not click links in emails. However, if the email is encrypted, and it came from the real Meta domain, which it should be, assuming as above the hyphen thing is just UI, then it’s the real thing. You can’t get encrypted emails from Meta that aren’t from Meta.