Hackers Used a Meta Business Feature in Phishing Campaign to Steal Logins — What to Know

Hackers Used a Meta Business Feature in Phishing Campaign to Steal Logins — What to Know

Meta business users received phishing emails sent through Meta’s own email system, making them appear legitimate. Here’s how the phishing campaign worked, why it matters, and how to protect your account.

What Happened?

According to TechRadar, cybersecurity researchers at Huntress discovered a phishing campaign that abused a legitimate Meta business feature to send phishing emails from Meta’s own email infrastructure.

The attackers took advantage of a feature that lets businesses communicate through Meta’s platform. Because the emails were sent through Meta’s systems, they appeared to come from an official Meta email address, making them much more convincing.

The phishing campaign impersonated the Meta Agency Partner Program — a real Meta program that connects businesses with social media marketing professionals. Huntress reported the attack, and Meta has since added new protections that stopped the campaign.

Stolen login details are often only part of the picture. Criminals also combine information from previous data breaches to make phishing emails and account takeover attempts more convincing. 

Many people do not realize their information has already been leaked somewhere online. 

If you are not sure whether your information was affected, automatic monitoring can help you spot problems earlier. 

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Targeted and What Information Was Stolen?

The campaign targeted people who manage Meta business accounts. Huntress did not say how many people received the phishing emails or how many accounts were affected.

Victims who clicked the links were taken to fake websites that looked like the Meta Agency Partner Program. They were asked to sign in, but instead of logging into Meta, they unknowingly sent their usernames and passwords to the attackers. Those credentials were then forwarded to the attackers through Telegram.

Stolen business account logins can be valuable to criminals. 

They may use them to run fraudulent advertisements, take over business pages, or launch more convincing phishing attacks against customers and followers.

How Criminals Used Meta’s Own Email System

The attackers did not break into Meta’s email servers. Instead, they abused a legitimate business messaging feature that Meta provides.

Because the emails traveled through Meta’s official infrastructure, many recipients naturally trusted them. The attackers also found ways around Meta’s built-in disclaimer that warned recipients the sender was not affiliated with Meta.

The phishing emails directed victims to fake websites outside Meta’s platform. These pages closely copied the appearance of the real Meta Agency Partner Program to persuade people to enter their login details. Once entered, the credentials were immediately sent to the attackers through Telegram, a messaging app.

Meta has now introduced additional safeguards that researchers say have effectively stopped this phishing campaign.