The phishing email really did come from Facebook – how attackers went after business ad accounts
Security firm Huntress has documented a phishing campaign that solved the problem every phisher has: making the email look real. These attackers did not fake a Facebook address. They got Facebook to send the message.
Meta runs a legitimate service that introduces businesses to agencies who can manage their advertising. The attackers signed up as one of those partners and put a web address into the field meant for the business owner’s name. When Meta’s system then sent its standard introduction email, it dutifully included that address – and the message went out from a real Facebook address that passes every check an email system can make.
Anyone who followed the link reached a convincing copy of a Meta sign-in page. It asked for the password twice, using a fake error message to be sure it had been typed correctly, then asked for the multi-factor code, then a phone number, and finally photographs of identity documents – a passport or driving licence. All of it went straight to the attackers.
Who this affects
Any business with a Facebook page or an advertising account, which on the South Coast means a great many shops, trades, restaurants and gyms. The prize is not your password for its own sake. It is your advertising account.
Somebody in control of that can spend whatever budget you have loaded, run their own advertising under your name, change the recovery details so you cannot get back in, and then aim the next round of scams at the followers and customers who trust your page. The identity documents make it considerably worse, because those are useful long after the account is recovered.
Meta has since stopped this particular trick, so the specific email is no longer arriving. The lesson it leaves behind is the one worth keeping.
What to take from it
- A genuine sender address proves nothing. This is the point. “It came from Facebook” was true, and the message was still a scam. The same applies to any platform that emails on behalf of its users.
- Check the address bar, not the email. Before typing a password, look at where you actually are. Real sign-in pages live on the platform’s own address and nowhere else.
- Never photograph your passport for a login problem. No legitimate account recovery starts with an unexpected email asking for identity documents.
- Treat a request for the code as the alarm. A page that asks for your password and then your multi-factor code, one after the other, is collecting both to use immediately.
- Check who has access to your page. Old agencies, the marketing person who left, a personal account nobody can name. Fewer people with control means fewer ways in.
The part that training actually fixes
Nobody falls for this because they are careless. They fall for it because the email was genuine, and everything they have been taught says a real sender address means a real message. That is a gap in what people have been told, not a gap in their attention – and it closes by showing them the trick before it turns up.
That is what our security awareness training and human risk management do, using real examples like this one rather than a yearly quiz. We are available round the clock if something does go wrong and you need the account back.
Call us on 01202 237 273 or book a call.