logo

Hackers Abuse Legitimate Meta Business Manager Notifications to Deliver Phishing Emails

ID: 65d4d20d-a2f9-5e17-9814-692c60043530

STIX ID: report--65d4d20d-a2f9-5e17-9814-692c60043530

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A widespread phishing campaign is abusing Meta Business Manager’s partner request feature to send legitimate-looking emails from facebookmail.com that lead to counterfeit login pages (often hosted on vercel.app). Attackers harvest credentials and sometimes 2FA codes in real time, enabling full takeover of Business Manager accounts which can be used to run fraudulent ads, drain budgets, impersonate businesses, or extort victims; researchers observed over 40,000 emails sent to more than 5,000 organizations across multiple industries and regions. Organizations are advised to train staff, audit partner access, avoid clicking email links, and navigate directly to platforms to verify notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.