logo

Meta Phishers Abuse Business Account Manager Service | Huntress

ID: ca0c916e-5dd5-522f-aa51-0c44b4fad8e2

STIX ID: report--ca0c916e-5dd5-522f-aa51-0c44b4fad8e2

Feed Name: Huntress Blog

Threat Score
60/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

...
...

A phishing campaign exploited Meta's business partner messaging to send seemingly legitimate partner requests that redirected recipients to attacker-controlled landing pages (Google Sites, Netlify, and other domains). The pages harvested Facebook/Instagram credentials, MFA codes, phone numbers and identity documents and exfiltrated submissions to a Telegram bot channel; researchers observed older (May) and newer (June, chatbot-driven) variants, captured IoCs (domains and URLs), and noted Meta has implemented mitigations that reduced the abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.