{"id":8388,"date":"2025-11-12T10:00:35","date_gmt":"2025-11-12T10:00:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/12\/new-phishing-attack-targeting-meta-business-suite-users-to-steal-login-credentials\/"},"modified":"2025-11-12T10:00:35","modified_gmt":"2025-11-12T10:00:35","slug":"new-phishing-attack-targeting-meta-business-suite-users-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/12\/new-phishing-attack-targeting-meta-business-suite-users-to-steal-login-credentials\/","title":{"rendered":"New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials"},"content":{"rendered":"<p>    New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A large-scale phishing campaign has emerged, exploiting Meta\u2019s Business Suite to compromise credentials across thousands of small and medium-sized businesses worldwide.<\/p>\n<p>Check Point security researchers identified approximately 40,000 phishing emails distributed to more than 5,000 customers, primarily targeting industries including automotive, education, real estate, hospitality, and finance across the U.S., Europe, Canada, and Australia.<\/p>\n<p>The sophisticated attack leverages legitimate Meta infrastructure, making detection substantially more difficult than traditional phishing attempts.<\/p>\n<p>The campaign demonstrates a troubling evolution in threat tactics. Rather than relying on spoofed domains and fake infrastructure, attackers have weaponized Meta\u2019s native Business invitation feature to establish credibility.<\/p>\n<p>This approach exploits user trust in established platforms and circumvents conventional <a href=\"https:\/\/cybersecuritynews.com\/email-security-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener\">email security filters<\/a> that typically flag suspicious sender addresses.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiLTUCi88ndpEswyjw5lTu4QadSUPRry0HgelRxZEdcT7gu3Q7vSG1DTxEHxJWdZ0a9JWnTTZvOsMhyphenhyphenECzJkIG7yxcU0G9me4E5YeJUcTpGu6_ZbET9iSH4kh7D6pjMFULi8y9pDZLxoK4dBK1a2qdYFC0T8huVkkZrJvXCq0Yt79g6q67RSPu2__CbZaI\/s16000\/Example%2520of%2520a%2520real%2520phishing%2520email%2520we%2520caught%2520%28Source%2520-%2520Check%2520Point%29.webp?ssl=1\" alt=\"Example of a real phishing email we caught (Source - Check Point)\"><figcaption class=\"wp-element-caption\">Example of a real phishing email we caught (Source \u2013 Check Point)<\/figcaption><\/figure>\n<\/div>\n<p>By originating from the legitimate facebookmail.com domain, these messages appear authentic and indistinguishable from genuine Meta notifications.<\/p>\n<p>Check Point security analysts <a href=\"https:\/\/blog.checkpoint.com\/email-security\/new-phishing-campaign-exploits-meta-business-suite-to-target-smbs-across-the-u-s-and-beyond\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the campaign after observing repetitive patterns in email subjects and structure consistent with template-driven mass distribution.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-new-phishing-attack\"><strong>New Phishing Attack<\/strong><\/h2>\n<p>The attackers created fraudulent Facebook Business pages adorned with official Meta branding and logos, then deployed these fake pages to send Business Portfolio invitations containing embedded malicious links.<\/p>\n<p>Recipients were redirected to credential harvesting pages hosted on domains such as vercel.app, where sensitive information was extracted and intercepted.<\/p>\n<p>The infection mechanism relies on social engineering and domain trust exploitation. Emails utilized urgent language such as \u201cAction Required,\u201d \u201cYou\u2019re Invited to Join the Free Advertising Credit Program,\u201d and \u201cAccount Verification Required,\u201d compelling users to click embedded links.<\/p>\n<p>The messages perfectly mimicked legitimate Meta notifications, including proper formatting and branding elements.<\/p>\n<p>Once victims clicked the links, they were redirected to phishing websites designed specifically to capture login credentials and other sensitive account information.<\/p>\n<p>Organizations should implement <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-factor<\/a> authentication to prevent unauthorized access even when credentials are compromised.<\/p>\n<p>Additionally, employees must receive training emphasizing credential verification and cautious link evaluation, regardless of sender legitimacy.<\/p>\n<p>Advanced email <a href=\"https:\/\/cybersecuritynews.com\/best-security-solutions-for-marketers\/\" target=\"_blank\" rel=\"noreferrer noopener\">security solutions<\/a> incorporating behavioral analysis and artificial intelligence-driven detection provide enhanced protection against this evolving threat landscape.<\/p>\n<p>Direct navigation to official Meta accounts rather than clicking email links represents another crucial defensive measure against these sophisticated credential theft attempts.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-targeting-meta-business-suite\/\">New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-targeting-meta-business-suite\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials A large-scale phishing campaign has emerged, exploiting Meta\u2019s Business Suite to compromise credentials across thousands of small and medium-sized businesses worldwide. Check Point security researchers identified approximately 40,000 phishing emails distributed to more than 5,000 customers, primarily targeting industries including automotive, education, real [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8388","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8388"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8388"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8388\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}