惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
H
Help Net Security
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
V
V2EX
M
MIT News - Artificial intelligence
Vercel News
Vercel News
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
美团技术团队
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
Free Facebook Blue Badge—New Warning Issued For All Users
Davey Winder · 2026-05-02 · via Forbes - Consumer Tech
Facebook logo seen on smartphone with blue verifcartion badges in the image background.

Beware this free Facebook blue badge offer.

SOPA Images/LightRocket via Getty Images

A newly published security report has warned Facebook users to beware of emails promising, amongst other things, a free blue verification badge. The attack campaign, which Guard.io security researcher Shaked Chen said has already compromised 30,000 accounts, is linked to a Vietnamese criminal operation and has been named AccountDumpling. “Over the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,” Chen warned, adding that the attacks were part of a “Facebook account hijacking ecosystem” and involved the use of emails that are delivered by Google.

ForbesMeta Discloses 2 WhatsApp Vulnerabilities In New Security Advisory

Blue Badge Facebook Attacks—AccountDumpling Campaign Exposed

Like users of other major technology brands, Meta product users are in the crosshairs of threat actors seeking to compromise accounts and access user data. With some 3 billion users, it is no surprise that Facebook is often front and center of phishing attack campaigns. Earlier this year, I reported on a surge in such campaigns aimed at compromising Facebook account passwords, and now another report has warned of a new and dangerous attack called AccountDumpling that has already racked up tens of thousands of victims.

“Over the past few weeks, we tracked waves of emails aimed at Facebook users, page admins, and operators,” the Guard.io report confirmed. Although the researchers found that the attacks used different lures and post-click paths, the destination was always the same: “people controlling accounts with real financial value.” Indeed, the attackers appear to have turned Google AppSheet into what you might call a phishing relay as part of an exploit loop which ultimately “sells the stolen accounts back through a storefront run by the same hands.”

genuine resources for such account-compromising campaigns. PayPal users were targeted via a legitimate PayPal email at the end of 2025. This time it is Google that is being abused by the scammers to get the exploit ball rolling, something that we have seen before with Google features being used to distribute malicious emails originating from trusted Google infrastructure.

Forbes2.8 Billion Credentials Stolen As Password Attacks SurgeBy Davey Winder

In the case of the AccountDumpling Facebook campaign, the attackers are using the no-code Google AppSheet platform designed to automate workflows and notifications. The threat actors were found to be abusing the AppSheet notification mechanism to deliver phishing emails at scale. “There was no need for spoofing, no reliance on compromised Google accounts,” Chen confirmed, “just a service doing exactly what it was built to do.” As Chen said, a fully authenticated email proves only that the platform sent it, not that the message itself is trustworthy. And, oh boy, these ones certainly are not.

Although a number of different email messages were used, mostly of the panic-inducing variety, such as warnings that the recipient’s Facebook account would be disabled, or a copyright claim that needed to be addressed, the one that stood out for me was the blue badge offer. No panic required, just temptation. “Get your free blue Facebook badge,” the emails promised. No need to pay for a Meta Verified subscription, just jump through a few fake CAPTCHA and contact detail hoops, before entering a password and a few rounds of 2FA codes. The evasion stack used by the attackers for this particular lure was “the most layered we saw at the email stage.”Sender display names padded with spaces using Unicode invisible characters, body text with words broken halfway through to confuse contextual text detection and even Cyrillic homoglyphs in the footer Meta branding that looked identical to Latin characters.

I have reached out to Meta for a statement regarding the new attack campaign report and advice for Facebook users. In the meantime, however, there’s a useful support page at the Meta Help Center on how to avoid scams and phishing attempts that I recommend you refer to.

ForbesGmail Accounts Under Persistent Hacking Attacks—‘Always Be Wary’By Davey Winder