The images in this article were generated with artificial intelligence. How we publish
A new report that shows the sophistication of contemporary digital fraud describes an operation linked to Vietnam that has exploited legitimate services like Google AppSheet to mount what researchers have called a phishing relay and put stolen Facebook accounts on the market. The campaign, nicknamed AccountDumpling by the firm that investigated the case, is not a mere isolated phishing kit: it is a living structure with real-time operating panels, constant developments and a criminal business cycle that turns access to accounts into a commercial commodity, according to analyses published by researchers who gave the alarm voice.
The mechanics of the attack combines social engineering and abuse of reliable platforms: emails that appear to come from the support of Meta, sent from a legitimate sender of AppSheet ("noreply @ appsheet.com") to remove anti-spam filters, target victims (usually account holders or Facebook businesses) to false pages hosted in services such as Netlify, Vercel or Google Drive. These pages mimic verification processes, documentation submission or policy reviews and are designed to capture credentials, 2FA codes, identification photographs and browser metadata. Some of the information collected ends up centralized in channels controlled by the attackers in Telegram, and the records seized point to a 30,000 committed accounts with victims in multiple countries.

The picture that is drawn has important implications for companies and users: in addition to direct damage due to loss of access, advertising theft and supplanting, there is a secondary market that monetizes business reputation, business identity and account recovery processes, which encourages more attacks. It is also worrying that malicious actors systematically use free or easily accessible public suppliers (AppSheet, Netlify, Vercel, Google Drive, Cova) to deliver malicious content, taking advantage of the confidence of filters and users themselves on these platforms.

To reduce the individual and corporate risk, there are concrete measures that should be applied immediately: not responding to urgent emails requesting credentials or following links from unverified messages; always checking the authenticity of the contact channel through the official Meta console or the business account on Facebook; activating more robust authentication methods such as physical keys (FIDO2 / WebAuthn) or authentication applications instead of SMS; review and revoke active sessions, application permissions and third party accesses from account configuration; and audit roles and permissions in page administrators and advertising accounts. At the technical level, organizations should strengthen mail policies with SPF, DKIM and DMARC, set up advanced filters and train teams and customers on regular lures such as false verification processes or alleged job offers of large brands.
In addition to reactive actions, cooperation between platform providers, security firms and authorities to detect and dismantle infrastructure that serves as "layers" of fraud is key. Suppliers such as AppSheet, Cova, Netlify or Vercel face the challenge of balancing availability and abuse: improving the detection of templates used in phishing, vetting the automation of PDFs or malicious pages and accelerating the response to reports are necessary steps to cut off the commercial circuit of the scam.
If you suspect that your Facebook account has been compromised, use only the official recovery channels provided by Meta and document any suspicious communication before acting; keep catches and emails for possible research. In order to deepen the context and findings reported by security researchers, you can consult news and awareness sources such as The Hacker News and resources of training in phishing and simulation of attacks such as KnowBe4 as well as the official documentation of Target on corporate security in Facebook Business Help. The lesson is clear: security is no longer only technical, it is also a battle for trust in platforms; strengthening it requires technical measures, processes and continuing education.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...