{"id":644301,"date":"2026-05-03T03:10:10","date_gmt":"2026-05-03T03:10:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/644301\/"},"modified":"2026-05-03T03:10:10","modified_gmt":"2026-05-03T03:10:10","slug":"google-appsheet-exploited-in-30000-user-facebook-phishing-operation","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/644301\/","title":{"rendered":"Google AppSheet Exploited in 30,000-User Facebook Phishing Operation"},"content":{"rendered":"<p>Cybersecurity researchers at Guardio Labs have discovered a massive\u00a0phishing operation that uses <a target=\"_blank\" rel=\"noopener nofollow\" href=\"https:\/\/hackread.com\/google-chrome-update-infostealer-cookie-theft\/\">Google<\/a>\u2019s own infrastructure to hijack <a target=\"_blank\" rel=\"noopener nofollow\" href=\"https:\/\/hackread.com\/tag\/facebook\/\">Facebook<\/a> accounts. This research reveals a Vietnamese-linked operation code-named AccountDumpling that has already compromised over 30,000 users globally.<\/p>\n<p> AppSheet Abuse<\/p>\n<p>Guardio Labs researchers explained in the report that this campaign abuses the notification system of <a target=\"_blank\" rel=\"noopener nofollow\" href=\"https:\/\/hackread.com\/google-appsheet-phishing-scam-fake-trademark-notices\/\">Google AppSheets <\/a>(a no-code tool designed for business automation). By using this service, hackers send emails from <a href=\"https:\/\/hackread.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"2a4445584f5a46536a4b5a5a59424f4f5e04494547\" rel=\"nofollow noopener\" target=\"_blank\">[email\u00a0protected]<\/a> and appsheet.bounces.google.com.<\/p>\n<p>These emails originate from Google\u2019s servers, and that\u2019s why passing the authentication checks like SPF, DKIM, and DMARC becomes possible. Researchers noted that the phishing lures involve Meta-related themes. Such as fake copyright complaints or account disablement warnings. One email from April 2026 included the text \u201cCase ID: 6480258166\u201d and warned of permanent disablement within 24 hours.<\/p>\n<p>Technical Methods and Attack Clusters<\/p>\n<p>Researchers noted that this isn\u2019t just one simple trick. The operation is split into different methods, or clusters, to catch different types of victims:<\/p>\n<p>Cluster A- Netlify Clones: Some attackers used a tool called HTTrack to copy the Facebook Help Centre. They hosted these on Netlify to steal passwords and photos of government IDs.<\/p>\n<p>Cluster B- The Reward Trap: Another group used social engineering to lure users, such as by promising Blue Badge verification. They used zero-font tactics like Cyrillic homoglyphs (a Cyrillic \u201c\u0430\u201d instead of a Latin \u201ca\u201d) and hair spaces (invisible Unicode characters) to bypass spam filters.<\/p>\n<p>Cluster C- Live Control: This cluster is the scariest as it is highly advanced. It uses a Google Drive-hosted PDF and Socket IO and WebSockets to create a live operator panel. When the victim clicks on it, the hackers can interact with the victims in real-time to request 2FA (two-factor authentication) codes.<\/p>\n<p>Cluster D: This involves fake job recruitment for brands like Adobe, Apple, and Coca-Cola, and redirects victims to private <a target=\"_blank\" rel=\"noopener nofollow\" href=\"https:\/\/hackread.com\/microsoft-whatsapp-attachments-backdoor-windows-pcs\/\">WhatsApp<\/a> chats.<\/p>\n<p><a target=\"_blank\" rel=\"noopener nofollow\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/google-appsheet-facebook-accountdumpling-scam.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"569\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/google-appsheet-facebook-accountdumpling-scam-1024x569.jpg\" alt=\"Google AppSheet Abused to Hit 30,000 Facebook Accounts in AccountDumpling Scam\" class=\"wp-image-144792\"  \/><\/a>Attack clusters (Source: Guardio Labs)<\/p>\n<p>Attribution<\/p>\n<p>Further <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/guard.io\/labs\/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts\">investigation<\/a> revealed a clear trail leading back to Vietnam. A Canva-generated PDF file from the attack contained the name Ph\u1ea1m T\u00e0i T\u00e2n in the metadata. This same name is linked to a business that openly \u2018helps\u2019 people recover locked Facebook accounts.<\/p>\n<p>According to researchers, the data stolen by these kits is sent to Telegram bots like @haixuancau_bot and @globalglobalglobalbot_bot. These channels are run by users known by their aliases \u201cBig Bosss\u201d and \u201c@mansinblack.\u201d<\/p>\n<p>While the attack is global, 68.6% of the victims in the main dataset were from the United States, followed by the UK, Canada, and Italy. Guardio Labs warned that this is a professional supply chain. One group steals the account, and another sells the access back or uses it for fraud. It\u2019s a dark business model that turns user trust into a product.<\/p>\n<p>Attack clusters (Source: Guardio Labs)<\/p>\n","protected":false},"excerpt":{"rendered":"Cybersecurity researchers at Guardio Labs have discovered a massive\u00a0phishing operation that uses Google\u2019s own infrastructure to hijack Facebook&hellip;\n","protected":false},"author":2,"featured_media":644302,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-644301","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/644301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=644301"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/644301\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/644302"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=644301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=644301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=644301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}