Cybercriminals are always changing their methods of delivering phishing emails. Their latest strategy is to exploit Facebook’s mechanisms. These hackers use the platform to send fraudulent notifications. The messages threaten to block business accounts.
The phishing attacks often start with emails that appear to come from Facebook. The email targets the address associated with the victim’s business account.
The email will have an alarm icon. It also comes with a warning that the recipient only has “24 Hours Left To Request Review.” There’s an added instruction to see why they must review the email.
A report states the email gives the impression that Facebook is blocking the account. This could cause Facebook managers or recipients to ignore the strange phrasing. They could end up clicking the link in the email due to panic.
The recipients might also log into Facebook to check for notifications. They will see a notification with the same ominous message. It will claim Facebook is blocking the account for non-compliance. It will infer the account has violated the terms of service. It will also prompt the user to follow a link to dispute the decision.
The link leads to a webpage bearing the Meta logo. This page will state that the resolution time is now 12 hours.
Hackers are using this phishing method in other Meta platforms, like Instagram.
The phishing page will ask for benign information. It will ask for the user’s page name, first and last name, and phone number. The next screen will ask for the user’s email address or the phone number linked to the Facebook account. It will also ask for the recipient’s password, the hacker’s main target.
The hackers will then use the hijacked Facebook account to send phishing notifications. They’ll post the messages from this account. It will even mention the victim’s page. This strategy lets cyber attackers send bulk notifications using Facebook’s infrastructure.

