logo

Google AppSheet Abuse Helped Phish 30,000 Facebook Accounts

ID: 58ba3141-4b78-55c6-b6ad-4051fd6dbc6f

STIX ID: report--58ba3141-4b78-55c6-b6ad-4051fd6dbc6f

Feed Name: TechRepublic Security

Threat Score
72/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Joseph Ofonagoro

...
...

AccountDumpling is an active, large-scale phishing campaign run by a Vietnam-linked operator that leverages Google AppSheet and mainstream cloud services to send authenticated-looking phishing emails to Facebook business/advertiser accounts; approximately 30,000 accounts across ~50 countries have been compromised and the stolen access is monetized through fraud, ad abuse, resale, and recovery services. The report details attacker TTPs (trusted-platform relay, cloud-hosted phishing pages, Telegram-based validation), targeted industries and geographies, and defensive mitigations and IOCs published by the researcher.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.