ClickFix Campaign Hijacks Facebook Sessions via Fake Verification Pages

ClickFix Campaign Hijacks Facebook Sessions via Fake Verification Pages

First seen 22 Jan 2026, 21:42 UTC GbhackersCybersecuritynews 95% similarity 20.3

Article Content

Browse articles
ThreatCluster

The ClickFix campaign exploits social engineering techniques to steal Facebook session tokens from users. By guiding victims through a fake verification process, attackers have successfully extracted live session credentials directly from browsers. This campaign has expanded significantly since early 2025, with researchers identifying numerous malicious webpages involved in the attack.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
Campaign growth noted since early 2025
Recent
Attackers launched ClickFix campaign
Date unknown
115 malicious webpages identified

Community

Browse all →

Tracked Entities in This Story