Seria alertów o świcie. Ktoś próbował przejąć moje konto - Business Insider Polska
Summary
On September 11, 2026, at 5 a.m., Natalia Szewczak was woken by repeated login attempts to her Facebook account from devices in Uzbekistan, Chile, Kenya, and the UAE. She successfully blocked the access but feared a mistake could grant the hacker control. She quickly changed her password, logged out of all devices, and warned her contacts. The incident mirrors an attack on TVN24 journalist Patrycja Stockinger six months prior, who lost her chat history and profile photos before recovering the account. Experts explain that attackers often use stolen credentials from other breaches or employ MFA fatigue—bombarding users with login requests to force a accidental approval.
Key points
- Natalia Szewczak blocked 12 login attempts to her Facebook account from locations including Uzbekistan, Chile, Kenya, and the UAE on September 11, 2026.
- Patrycja Stockinger had her Facebook account hacked six months earlier, losing her chat history, photos, and profile before recovering it.
- Hacker attacks often use credentials from other data breaches or employ MFA fatigue to trick users into approving logins.
- A 2021 Facebook data leak exposed 533 million accounts with phone numbers and names but not passwords.
- Changing a password on an infected device may fail if malware steals the new credentials or session token.
Timeline
Patrycja Stockinger's Facebook account is hacked, losing chat history and photos.
Natalia Szewczak blocks 12 login attempts to her account from multiple countries.
“"Hakerzy ostatecznie przejmujący konto wcale nie musieli być tymi samymi, którzy wcześniej zdobyli potrzebne dane. Przestępcy mogą korzystać z gotowych baz danych logowania pochodzących z wycieków innych serwisów, phishingu lub od złośliwego oprogramowania, tak zwanych infostealerów."”
Background
A 2021 data leak exposed 533 million Facebook accounts with phone numbers and names, though not passwords.
Why it matters
Attackers use MFA fatigue to trick users into approving logins, and stolen session tokens can bypass password changes.