An unknown threat actor exploited Meta's Business Account Manager service to send phishing emails from legitimate Meta addresses between November 2025 and June 2026. The attackers manipulated the business partner mechanism by embedding URLs in the business name field, causing emails to appear as legitimate Meta communications. The campaign evolved to incorporate Facebook Messenger chatbots and exfiltrated stolen credentials, MFA codes, phone numbers, and identity documents to a private Telegram channel. The phishing pages impersonated Meta's Agency Partner Program and Verified badge services, targeting businesses to capture account credentials. Meta responded by implementing detections and blocking accounts attempting to use URLs in business names. Vietnamese language elements in the exfiltration process suggest the attackers' possible origin.
Created: 2026-07-09
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。