logo

The Meta 2FA Trap: From Verified Badge to Account Takeover

ID: 2dd4f71e-e8fc-5671-bcea-6a9c1340b755

STIX ID: report--2dd4f71e-e8fc-5671-bcea-6a9c1340b755

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense PDC details an active phishing campaign impersonating Meta Verified that lures users via a Gmail-based message to a Google Form and then to vercel.app-hosted landing pages which harvest credentials and live 2FA tokens for near-real-time account takeover; the report includes observed phishing and payload URLs and IPs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.