Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
30,000 Facebook Accounts Hacked in Phishing Scam

30,000 Facebook Accounts Hacked in Phishing Scam

Posted on May 1, 2026 By CWS

A recent cybersecurity breach has exposed a large-scale phishing operation targeting Facebook accounts, resulting in the compromise of approximately 30,000 profiles. This sophisticated attack utilized Google’s AppSheet service as a ‘phishing relay’ to effectively distribute malicious emails aimed at Facebook users.

Unveiling the ‘AccountDumpling’ Campaign

The operation, identified as ‘AccountDumpling’ by the cybersecurity firm Guardio, involved a series of meticulously crafted phishing emails. These emails tricked recipients into believing they were from Meta Support, urging them to submit an appeal to avoid account termination. The phishing emails were sent from a Google AppSheet address, which enabled them to evade spam detection systems.

Security researcher Shaked Chen highlighted the complexity of the operation, describing it as a dynamic system with real-time operational panels and advanced evasion tactics. The stolen accounts were then sold on illegal online marketplaces, contributing to a growing underground economy of stolen digital identities.

Methods of Deception and Data Harvesting

The phishing campaign employed various deceptive tactics to instill a sense of urgency among Facebook Business account holders. These included fake alerts about account disablement, copyright issues, and verification requests. The emails directed users to counterfeit web pages designed to harvest login credentials.

Guardio’s investigation identified several clusters of these phishing schemes. One method involved using Netlify-hosted pages to collect sensitive information such as dates of birth, phone numbers, and ID photos, which were then sent to a Telegram channel controlled by the attackers. Another tactic involved using Vercel-hosted ‘Security Check’ pages to gather login credentials and two-factor authentication codes.

Identifying the Culprits and Future Implications

The operation has been linked to Vietnamese threat actors, with evidence pointing to a specific individual associated with the digital marketing website ‘phamtaitan[.]vn.’ Metadata from the phishing PDFs revealed the name ‘PHẠM TÀI TÂN’ as the document’s author, suggesting a connection to the broader phishing network.

This incident underscores the evolving tactics of cybercriminals who continue to exploit trusted platforms for malicious purposes. The stolen accounts, primarily from the U.S., Italy, and several other countries, highlight the global scale of this security threat.

As cybersecurity experts continue to unravel the details of this operation, it serves as a stark reminder of the importance of vigilance and robust security measures to protect personal information online. Future efforts must focus on enhancing detection systems and raising awareness about the risks of phishing attacks.

The Hacker News Tags:account takeover, Cybersecurity, digital marketing, Facebook, Google AppSheet, online security, personal data protection, Phishing, phishing emails, spam filters, Telegram channels, threat intelligence, two-factor authentication, Vietnamese hackers

Post navigation

Previous Post: Jenkins Servers Exploited in DDoS Attacks on Valve Games
Next Post: Criminal IP and Securonix Enhance Threat Intelligence

Related Posts

Google to Verify All Android Developers in 4 Countries to Block Malicious Apps Google to Verify All Android Developers in 4 Countries to Block Malicious Apps The Hacker News
Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware The Hacker News
Key Insights from the 2025 State of Pentesting Report Key Insights from the 2025 State of Pentesting Report The Hacker News
eSIM Vulnerability in Kigen’s eUICC Cards Exposes Billions of IoT Devices to Malicious Attacks eSIM Vulnerability in Kigen’s eUICC Cards Exposes Billions of IoT Devices to Malicious Attacks The Hacker News
Stealthy Python Backdoor Targets Cloud Credentials Stealthy Python Backdoor Targets Cloud Credentials The Hacker News
Google Halts Major Cyber Espionage Campaign Targeting 53 Entities Google Halts Major Cyber Espionage Campaign Targeting 53 Entities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Engineering’s Role in AI Development
  • Criminal IP and Securonix Enhance Threat Intelligence
  • 30,000 Facebook Accounts Hacked in Phishing Scam
  • Jenkins Servers Exploited in DDoS Attacks on Valve Games
  • Malware Campaign Exploits SEO to Target IT Professionals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Engineering’s Role in AI Development
  • Criminal IP and Securonix Enhance Threat Intelligence
  • 30,000 Facebook Accounts Hacked in Phishing Scam
  • Jenkins Servers Exploited in DDoS Attacks on Valve Games
  • Malware Campaign Exploits SEO to Target IT Professionals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark