惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
博客园 - Franky
MyScale Blog
MyScale Blog
L
LangChain Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
Stack Overflow Blog
Stack Overflow Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 司徒正美
量子位
A
About on SuperTechFans
C
Check Point Blog
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
小众软件
小众软件
Apple Machine Learning Research
Apple Machine Learning Research
I
InfoQ
V
Visual Studio Blog
Vercel News
Vercel News
B
Blog
爱范儿
爱范儿
aimingoo的专栏
aimingoo的专栏
U
Unit 42

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Free Facebook Blue Badge—New Warning Issued For All Users
Davey Winder · 2026-05-02 · via Forbes - Innovation
Facebook logo seen on smartphone with blue verifcartion badges in the image background.

Beware this free Facebook blue badge offer.

SOPA Images/LightRocket via Getty Images

A newly published security report has warned Facebook users to beware of emails promising, amongst other things, a free blue verification badge. The attack campaign, which Guard.io security researcher Shaked Chen said has already compromised 30,000 accounts, is linked to a Vietnamese criminal operation and has been named AccountDumpling. “Over the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,” Chen warned, adding that the attacks were part of a “Facebook account hijacking ecosystem” and involved the use of emails that are delivered by Google.

ForbesMeta Discloses 2 WhatsApp Vulnerabilities In New Security Advisory

Blue Badge Facebook Attacks—AccountDumpling Campaign Exposed

Like users of other major technology brands, Meta product users are in the crosshairs of threat actors seeking to compromise accounts and access user data. With some 3 billion users, it is no surprise that Facebook is often front and center of phishing attack campaigns. Earlier this year, I reported on a surge in such campaigns aimed at compromising Facebook account passwords, and now another report has warned of a new and dangerous attack called AccountDumpling that has already racked up tens of thousands of victims.

“Over the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,” the Guard.io report confirmed. Although the researchers found that the attacks used different lures and post-click paths, the destination was always the same: “people controlling accounts with real financial value.” Indeed, the attackers appear to have turned Google AppSheet into what you might call a phishing relay as part of an exploit loop which ultimately “sells the stolen accounts back through a storefront run by the same hands.”

genuine resources for such account-compromising campaigns. PayPal users were targeted via a legitimate PayPal email at the end of 2025. This time it is Google that is being abused by the scammers to get the exploit ball rolling, something that we have seen before with Google features being used to distribute malicious emails originating from trusted Google infrastructure.

Forbes2.8 Billion Credentials Stolen As Password Attacks SurgeBy Davey Winder

In the case of the AccountDumpling Facebook campaign, the attackers are using the no-code Google AppSheet platform designed to automate workflows and notifications. The threat actors were found to be abusing the AppSheet notification mechanism to deliver phishing emails at scale. “There was no need for spoofing, no reliance on compromised Google accounts,” Chen confirmed, “just a service doing exactly what it was built to do.” As Chen said, a fully authenticated email proves only that the platform sent it, not that the message itself is trustworthy. And, oh boy, these ones certainly are not.

Although a number of different email messages were used, mostly of the panic-inducing variety, such as warnings that the recipient’s Facebook account would be disabled, or a copyright claim that needed to be addressed, the one that stood out for me was the blue badge offer. No panic required, just temptation. “Get your free blue Facebook badge,” the emails promised. No need to pay for a Meta Verified subscription, just jump through a few fake CAPTCHA and contact detail hoops, before entering a password and a few rounds of 2FA codes. The evasion stack used by the attackers for this particular lure was “the most layered we saw at the email stage.”Sender display names padded with spaces using Unicode invisible characters, body text with words broken halfway through to confuse contextual text detection and even Cyrillic homoglyphs in the footer Meta branding that looked identical to Latin characters.

I have reached out to Meta for a statement regarding the new attack campaign report and advice for Facebook users. In the meantime, however, there’s a useful support page at the Meta Help Center on how to avoid scams and phishing attempts that I recommend you refer to.

ForbesGmail Accounts Under Persistent Hacking Attacks—‘Always Be Wary’By Davey Winder