216.73.216.6

Clickbait to Catastrophe: How a Fake Meta Email Leads to Password Plunder

· Published 21/03/2025 10:33 · Modified 21/03/2025 14:44

Export JSON

Essential information

Published
21/03/2025 10:33
Modified
21/03/2025 14:44
Tags
2025-03-21 business accounts chat support credential-theft instagram meta phishing social media two-factor authentication
Related entities
1 vulnerabilities (cve), 5 observables, 5 techniques (mitre), 1 others

Description

A sophisticated campaign targeting has been uncovered by the Cofense Defense Center. The attack begins with a fake alert claiming the user's ads are suspended due to policy violations. Victims are directed to a fraudulent page mimicking 's business help center, where they're prompted to interact with a fake or follow step-by-step instructions. The ultimate goal is to trick users into adding the attacker's device as a secure login method via , effectively hijacking the account. The campaign employs convincing email templates, landing pages, and even includes live agent support to add credibility. Users are urged to verify communications and examine URLs carefully before taking action to protect their credentials.

External references