{"id":643210,"date":"2026-05-02T15:01:10","date_gmt":"2026-05-02T15:01:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/643210\/"},"modified":"2026-05-02T15:01:10","modified_gmt":"2026-05-02T15:01:10","slug":"free-facebook-blue-badge-offer-is-a-trap-dont-fall-for-it","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/643210\/","title":{"rendered":"Free Facebook Blue Badge Offer Is A Trap\u2014Don\u2019t Fall For It"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">A newly published security report has warned Facebook users to beware of emails promising, amongst other things, a free blue verification badge. The attack campaign, which Guard.io security researcher Shaked Chen said has already compromised 30,000 accounts, is linked to a Vietnamese criminal operation and has been named AccountDumpling. \u201cOver the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,\u201d Chen warned, adding that the attacks were part of a \u201cFacebook account hijacking ecosystem\u201d and involved the use of emails that are delivered by Google.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\"><a data-yga=\"{\" ylinkelement=\"\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/meta-discloses-2-whatsapp-vulnerabilities-114834107.html\" data-ylk=\"elm:link;elmt:article_link;slk:MORE FROM FORBESMeta Discloses 2 WhatsApp Vulnerabilities In New Security AdvisoryBy Davey Winder;itc:0;sec:content-canvas;outcm:mb_qualified_link;_E:mb_qualified_link;ct:story;\" class=\"link  yahoo-link\" rel=\"nofollow noopener\" target=\"_blank\">MORE FROM FORBESMeta Discloses 2 WhatsApp Vulnerabilities In New Security AdvisoryBy Davey Winder<\/a><\/p>\n<p><a data-ylk=\"ct:story;elm:img;itc:0;\" class=\"stretched-box\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/meta-discloses-2-whatsapp-vulnerabilities-114834107.html\" rel=\"nofollow noopener\" target=\"_blank\"><img alt=\"\" loading=\"lazy\" width=\"960\" height=\"640\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-lg\" style=\"color:transparent\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/4b90cf1a5710c88ca49475530074aee9.jpeg\"\/><\/a>Blue Badge Facebook Attacks\u2014AccountDumpling Campaign Exposed<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Like users of other major technology brands, Meta product users are in the crosshairs of threat actors seeking to compromise accounts and access user data. With some 3 billion users, it is no surprise that Facebook is often front and center of phishing attack campaigns. Earlier this year, I reported on a surge in such campaigns aimed at compromising <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/16\/facebook-password-warning-for-3-billion-users-as-attacks-surge\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:Facebook account passwords;itc:0;sec:content-canvas\">Facebook account passwords<\/a>, and now another report has warned of a new and dangerous attack called AccountDumpling that has already racked up tens of thousands of victims.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">\u201cOver the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,\u201d the <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/guard.io\/labs\/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:Guard.io report;itc:0;sec:content-canvas\">Guard.io report<\/a> confirmed. Although the researchers found that the attacks used different lures and post-click paths, the destination was always the same: \u201cpeople controlling accounts with real financial value.\u201d Indeed, the attackers appear to have turned Google AppSheet into what you might call a phishing relay as part of an exploit loop which ultimately \u201csells the stolen accounts back through a storefront run by the same hands.\u201d<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">genuine resources for such account-compromising campaigns. PayPal users were targeted via a <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/16\/if-you-see-this-message-from-paypal-you-are-under-attack\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:legitimate PayPal email;itc:0;sec:content-canvas\">legitimate PayPal email<\/a> at the end of 2025. This time it is Google that is being abused by the scammers to get the exploit ball rolling, something that we have seen before with Google features being used to distribute malicious emails originating from <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/24\/critical-new-google-email-warning-as-password-attacks-surge\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:trusted Google infrastructure;itc:0;sec:content-canvas\">trusted Google infrastructure<\/a>.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\"><a data-yga=\"{\" ylinkelement=\"\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/password-security-2-86-billion-135709612.html\" data-ylk=\"elm:link;elmt:article_link;slk:MORE FROM FORBES2.8 Billion Credentials Stolen As Password Attacks SurgeBy Davey Winder;itc:0;sec:content-canvas;outcm:mb_qualified_link;_E:mb_qualified_link;ct:story;\" class=\"link  yahoo-link\" rel=\"nofollow noopener\" target=\"_blank\">MORE FROM FORBES2.8 Billion Credentials Stolen As Password Attacks SurgeBy Davey Winder<\/a><\/p>\n<p><a data-ylk=\"ct:story;elm:img;itc:0;\" class=\"stretched-box\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/password-security-2-86-billion-135709612.html\" rel=\"nofollow noopener\" target=\"_blank\"><img alt=\"\" loading=\"lazy\" width=\"960\" height=\"640\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-lg\" style=\"color:transparent\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/d1a5b3bda881a4eec82c659603eb7105.jpeg\"\/><\/a><\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In the case of the AccountDumpling Facebook campaign, the attackers are using the no-code Google AppSheet platform designed to automate workflows and notifications. The threat actors were found to be abusing the AppSheet notification mechanism to deliver phishing emails at scale. \u201cThere was no need for spoofing, no reliance on compromised Google accounts,\u201d Chen confirmed, \u201cjust a service doing exactly what it was built to do.\u201d As Chen said, a fully authenticated email proves only that the platform sent it, not that the message itself is trustworthy. And, oh boy, these ones certainly are not.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Although a number of different email messages were used, mostly of the panic-inducing variety, such as warnings that the recipient\u2019s Facebook account would be disabled, or a copyright claim that needed to be addressed, the one that stood out for me was the blue badge offer. No panic required, just temptation. \u201cGet your free blue Facebook badge,\u201d the emails promised. No need to pay for a <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/www.facebook.com\/help\/1288173394636262\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:Meta Verified subscription;itc:0;sec:content-canvas\">Meta Verified subscription<\/a>, just jump through a few <a data-yga=\"{\" ylinkelement=\"\" class=\"link  yahoo-link\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/sms-pumping-attack-starts-hitting-133258545.html\" data-ylk=\"elm:link;elmt:article_link;slk:fake CAPTCHA;itc:0;sec:content-canvas;outcm:mb_qualified_link;_E:mb_qualified_link;ct:story;\" rel=\"nofollow noopener\" target=\"_blank\">fake CAPTCHA<\/a> and contact detail hoops, before entering a password and a few rounds of 2FA codes. The evasion stack used by the attackers for this particular lure was \u201cthe most layered we saw at the email stage.\u201dSender display names padded with spaces using Unicode invisible characters, body text with words broken halfway through to confuse contextual text detection and even Cyrillic homoglyphs in the footer Meta branding that looked identical to Latin characters.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">I have reached out to Meta for a statement regarding the new attack campaign report and advice for Facebook users. In the meantime, however, there\u2019s a useful support page at the Meta Help Center on <a data-yga=\"{\" ylinkelement=\"\" class=\"link \" href=\"https:\/\/www.meta.com\/en-gb\/help\/policies\/1273750300141929\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:how to avoid scams and phishing attempts;itc:0;sec:content-canvas\">how to avoid scams and phishing attempts<\/a> that I recommend you refer to.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\"><a data-yga=\"{\" ylinkelement=\"\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/gmail-accounts-under-attack-3-125950632.html\" data-ylk=\"elm:link;elmt:article_link;slk:MORE FROM FORBESGmail Accounts Under Persistent Hacking Attacks\u2014\u2018Always Be Wary\u2019By Davey Winder;itc:0;sec:content-canvas;outcm:mb_qualified_link;_E:mb_qualified_link;ct:story;\" class=\"link  yahoo-link\" rel=\"nofollow noopener\" target=\"_blank\">MORE FROM FORBESGmail Accounts Under Persistent Hacking Attacks\u2014\u2018Always Be Wary\u2019By Davey Winder<\/a><\/p>\n<p><a data-ylk=\"ct:story;elm:img;itc:0;\" class=\"stretched-box\" href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/gmail-accounts-under-attack-3-125950632.html\" rel=\"nofollow noopener\" target=\"_blank\"><img alt=\"\" loading=\"lazy\" width=\"960\" height=\"640\" decoding=\"async\" data-nimg=\"1\" class=\"rounded-lg\" style=\"color:transparent\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/f4f1dec567e1eb6dd6a817b8ac4aaea6.jpeg\"\/><\/a><\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">This article was originally published on <a data-yga=\"{\" ylinkelement=\"\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/02\/free-facebook-blue-badge-offer-is-a-trap-dont-fall-for-it\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"elm:link;elmt:article_link;slk:Forbes.com;itc:0;sec:content-canvas\" class=\"link \">Forbes.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A newly published security report has warned Facebook users to beware of emails promising, amongst other things, a&hellip;\n","protected":false},"author":2,"featured_media":643211,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,2096,192,12954,239686,239687,61],"class_list":["post-643210","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-facebook","tag-google","tag-google-accounts","tag-phishing-attack","tag-shaked-chen","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/643210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=643210"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/643210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/643211"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=643210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=643210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=643210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}