logo

“AccountDumpling” Hijacked Google Infrastructure to Steal 30,000 Facebook Accounts

ID: 73908015-a821-5695-9b23-52f9ae062c0f

STIX ID: report--73908015-a821-5695-9b23-52f9ae062c0f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Ddos

...
...

Guardio Labs uncovered "AccountDumpling," a sophisticated phishing campaign that abused Google AppSheet to deliver authenticated, signed phishing emails and compromise approximately 30,000 Facebook accounts; the operation uses multiple attack clusters (cloned help centers, fake verification rewards, real-time human-in-the-loop panels, and fake job offers), exfiltrates data to Telegram-based C2 bots, and is linked via document metadata to a Vietnamese individual allegedly monetizing account recovery services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.