We get a lot of spam emails sent to our work account as part of penetration testing. So I'm used to seeing very alarming emails from seemingly legitimate sources that I've been breached, and have learned to ignore them. Partly because I'm now trained to never click on a damn thing, and partly because I keep my online profile pretty lowkey. No LinkedIn, Tumblr, Snapchat, Twitter or w/e dumb social media stuff there is. Just FB, because I was there at the beginning, Amazon, the usuals.
So I see an email today from Facebook security saying my account was accessed. The visible email body I could see said it was from Mac device. I think "whatever, and delete it.
But then I decide, ya know, maybe I should follow up on this. I open FB on my phone (my FB account is linked to my personal email, btw, and I never use the "handy" cross platform login features ever, or saved passwords. I make myself type out all my passwords so I can remember them) and am told I have to login. First time that's happened since I logged into it from my phone a long time ago.
Now I'm kind of alarmed. I change my PW. Email ownership still belongs to me, cool. Do the security audit. No settings have been changed. Alright, cool.....
So now I'm wondering. How would FB know to send an email to my work address. How would someone that compromised my account know to send an email to my work address unless they are SERIOUSLY spear phishing me. Maybe it was a coincidence that I got pen test email at the same time FB decided to log me out...? I reacted on my account within minutes of seeing the email. Plenty of time for a bot or even a human to alter my email address on the account and all sorts of other things.
I sent out a message on FB telling people to not open anything from me, just to be on the safe side. And the password was pretty old and not very secure by the standards I now use. So it was probably for the best. But I'm now kinda nervous.