Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Google AppSheet phishing campaign hacks 30,000 Facebook accounts

Cybercriminal groups exploit Vishing and SSO in rapid SaaS extortion attacks

China-linked hackers target Asian governments, NATO states, journalists, activists

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google AppSheet phishing campaign hacks 30,000 Facebook accounts
Identity

Google AppSheet phishing campaign hacks 30,000 Facebook accounts

By May 1, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 1, 2026Malware/Threat Intelligence

A newly discovered Vietnam-related operation was observed using Google AppSheet as a “phishing relay” to distribute phishing emails aimed at compromising Facebook accounts.

The operation was codenamed AccountDumpling by Guardio, and the plan was to sell stolen accounts back through illegal storefronts operated by threat actors. In total, it is estimated that approximately 30,000 Facebook accounts were hacked as part of the campaign.

“What we discovered was not a single phishing kit,” security researcher Shaked Chen said in a report shared with Hacker News. “It was a living operation with a real-time operator panel, advanced evasion, continuous evolution, and criminal and commercial loops that silently preyed on the same accounts to help steal back.”

This finding is just the latest example of how Vietnamese threat actors continue to employ a variety of tactics to gain unauthorized access to victims’ Facebook accounts and then sell them in the underground ecosystem for financial gain.

The starting point for the latest attack is a phishing email targeting Facebook Business account holders claiming to be from Meta Support and urging them to file a dispute or risk having their account permanently deleted. The email is sent from a Google AppSheet address (“noreply@appsheet.com”), allowing it to bypass spam filters.

This false sense of urgency is used to lure users to fake web pages designed to collect credentials. It is worth noting that a similar campaign was reported by KnowBe4 in May 2025.

Over the past few weeks, these campaigns have employed various types of lures designed to induce “meta-related panic.” These range from account deactivations and copyright claims to verified reviews, executive hiring, and Facebook login alerts. The four main clusters identified by Guardio are listed below.

Netlify-hosted Facebook Help Center pages collect dates of birth, phone numbers, government-issued ID photos, and enable account takeover attacks. The data is ultimately transferred to a Telegram channel controlled by the attacker. A blue badge rating directs victims to a Vercel-hosted “Security Check” or “Meta | Privacy Center” page. These pages are gated with fake CAPTCHA checks to collect contact details, business information, credentials (after forced retries), and two-factor authentication (2FA) codes before directing users to phishing landing pages and exfiltrating them to Telegram channels. A PDF hosted on Google Drive disguises as instructions to complete account verification and instructs users to collect passwords, 2FA codes, government ID photos, and browser screenshots through html2canvas. PDF documents are generated using a free Canva account. Fake job offers impersonating companies such as WhatsApp, Meta, Adobe, Pinterest, Apple, and Coca-Cola to build trust with recipients and ask them to join a call or continue a discussion on an attacker-controlled site.

Cumulatively, Telegram channels related to the first three clusters were found to contain records of approximately 30,000 victims, most of whom are located in the United States, Italy, Canada, Philippines, India, Spain, Australia, United Kingdom, Brazil, and Mexico, and whose accounts are locked out.

Conclusive evidence as to who is behind this operation comes from a PDF generated as part of the third cluster using a free Canva account, whose metadata lists the Vietnamese name “PHẠM TÀI TÂN” as the file’s author. Further open source intelligence resulted in the discovery of a website (“phamtaitan”).[.]vn”) provides digital marketing services.

In a post shared on X in February 2023, the website handle said it “specializes in providing digital marketing services, marketing resources, and consulting on effective digital marketing strategies.”

“Taken together, these form a coherent picture of a large-scale mega-operation based in Vietnam,” Chen said. “This campaign is larger than any single AppSheet exploit. It’s a window into the black market for stolen Facebook assets, where access, business identity, advertising reputation, and even account recovery are all tradable goods. It’s another entry into a pattern we continue to surface: trusted platforms repurposed as a distribution, hosting, and monetization layer.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCybercriminal groups exploit Vishing and SSO in rapid SaaS extortion attacks

Related Posts

Cybercriminal groups exploit Vishing and SSO in rapid SaaS extortion attacks

May 1, 2026

China-linked hackers target Asian governments, NATO states, journalists, activists

May 1, 2026

5 sales challenges impacting MSP cybersecurity revenue

May 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google AppSheet phishing campaign hacks 30,000 Facebook accounts

Cybercriminal groups exploit Vishing and SSO in rapid SaaS extortion attacks

China-linked hackers target Asian governments, NATO states, journalists, activists

People are finally using Reddit search.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.