How Hackers Use Social Engineering to Get Passwords on Facebook

Last Updated : 10 Aug, 2026

Social engineering is the psychological manipulation of users into performing actions or divulging confidential information. Instead of exploiting technical system flaws, cybercriminals exploit human traits like trust, urgency, fear, and curiosity to gain unauthorized access to accounts like Facebook.

Practical Demonstration

Step1: Open the terminal and type the following command to open setoolkit.

setoolkit
 

Step2: Select Social Engineering Attacks

1
 

Step3: Select Web Attack Vectors

2
 

Step4: Select Credential Harvester Attack

3
 

Step5: Select Site Cloner

2
 

Step6: Type your IP address. To perform this attack over WAN you'll need to enter your public/external IP address. To perform over LAN type your internal  IP address provided by your router. To find your IP address type ifconfig in new terminal windows and copy your IP address.

ifconfig
 

Step7: Now input the URL you want to clone and perform a phishing attack over (in this case Facebook)

https://www.facebook.com/
 

The process will complete in a couple of seconds and then the phishing website will be hosted on the specified IP address on port 80 (mostly).

 

Now open the website on other device with the IP. Make sure you are connected to same network in case of LAN.

 

A Facebook Login page is displayed which seems to be legit.

 

As the user enters the email ID and password it is fetched by setoolkit

 

The password and email id entered by the victim is successfully fetched by the Hacker (highlighted in red).

 

The credentials are stored in an XML file to check over them later, to access it open this file location

/root/.set/reports

Now open the only XML file and findthe  email and password parameter.

To make the link more convincing, hackers mask the URL with appealing words and phrases with tools like Maskphish (check out: Maskphish)

Comment