← Blog
For businesses

When the Phishing Email Really Comes From Meta: The Business Account Attack

Explore an AI summary

Key takeaways

  • Attackers abused a legitimate Meta business feature so their phishing emails were actually sent from Meta's own address and landed straight in the inbox.

  • The emails impersonated the Meta Agency Partner Program and pushed recipients to a login page hosted outside Meta's systems.

  • Victims who signed in handed their credentials to the attackers, who exfiltrated them to Telegram and used them for account takeover, scam advertising spent on the victim's budget, and follow-on attacks against customers.

  • Because the sender was real, checking who sent the email did not help. The reliable tell was the fake login page itself, which lived on a domain that was not Meta.

  • Meta has since added guardrails that shut this specific campaign down, but the pattern (trusted delivery, fake page at the end) is here to stay.


The standard advice for spotting a phishing email is to check who sent it. In a campaign that recently targeted Meta Business accounts, that advice would have failed you completely. The emails genuinely came from Meta's own address, because the attackers had found a way to send them through Meta's real infrastructure.

For any business that runs Facebook and Instagram Pages, ad campaigns, or works with agencies, this one is worth understanding, because it shows how far attackers will go to defeat every trust signal except the last one. Here is how it worked, and the single step that still gave it away.


Keep your business safe from online threats

Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.

What happened

Security researchers at Huntress uncovered a phishing campaign that abused Meta's business account email infrastructure, reported by TechRadar.

Meta lets businesses set up accounts that can message one another, and those messages pass through Meta's own systems, so they show up as coming from Meta itself. Attackers turned that into a delivery channel: they sent phishing emails through the feature so the messages arrived from a genuine Meta address and dropped directly into victims' inboxes. Meta had even tried to blunt this by hardcoding a disclaimer noting that senders are not affiliated with Meta, and the attackers found ways around that too.

The emails impersonated the Meta Agency Partner Program, a real initiative that connects businesses with social media professionals. That framing is well chosen for the target: a business owner or marketing lead who works with agencies would not find a partner-program message unusual.


Why this attack was so hard to catch

Most phishing gives you a warning sign in the delivery. The sender address is slightly off, the domain is wrong, the email lands in spam. This campaign stripped those signs away.

The message really came from Meta. It passed the checks that a cautious person, or an email filter, would normally rely on. By the time you were reading it, the usual "is this actually from who it says" question had already been answered wrong, in the attacker's favor. That is what made it dangerous: it defeated the trust signals people are trained to look for, and left them with no obvious reason to doubt what came next.


Where the attack actually pays off

Here is the important part. However the email was delivered, the scheme still depended on one thing: getting you to enter your Meta Business login on a page the attacker controlled.

The phishing emails redirected victims to landing pages outside Meta's ecosystem, designed to look like the Meta Agency Partner Program. Anyone who did not spot the ruse would try to log in and, instead of reaching Meta, would simply hand their credentials to the attacker. Those credentials were then exfiltrated to a Telegram account under the attacker's control.

And a fake login page cannot be the real Meta. It has to live on a domain that is not Meta's. The delivery was flawless, but the destination was not, and could not be. That is the reliable tell.


What is at stake for a business

A hijacked Meta Business account is not a minor cleanup. Once attackers are in, they can:

  • Spend your advertising budget on scam or malicious ads run from your trusted account.

  • Take over the account entirely, changing the password and recovery methods so you cannot get back in.

  • Turn your account into a launchpad, sending more targeted attacks to your customers and followers using your own name and credibility.

For a business, that combines direct financial loss, brand damage, and a breach of the trust your audience places in your accounts. The researchers describe exactly this range of outcomes, from malvertising to full account takeover.


The moment that matters: the fake login page

When the email is genuinely from Meta, you cannot lean on the sender to protect you. When the landing page is a polished copy of a real Meta program, the branding will not protect you either. What is left is the web address of the page asking for your login, and under time pressure, on a page that looks right, that is exactly the detail people skip.

This is the moment a browser-security layer is built for. It does not care how convincing the email was or how the person arrived. It checks the page in front of them.


How Haven helps

Haven is designed to catch fake and impersonated login pages at the moment someone is about to enter credentials. It analyzes the actual page rather than trusting how it looks or how the person got there, so when a page imitates the Meta Agency Partner Program or a Meta Business login on a domain that is not Meta, Haven flags it as fraudulent before anything is typed.

That is precisely the coverage this attack calls for. The attackers won the delivery stage outright by sending from Meta's real address, so defenses that focus on the email had little to work with. Haven works at the page, the step where the credentials would actually be lost, so even a perfectly delivered message ending in a convincing fake page still gets flagged. If an employee is unsure about a link, they can also check it with Haven's free link checker before signing in.

To be clear about scope: Meta has already added guardrails that shut this particular campaign down, and Haven does not filter email or undo an account takeover after the fact. What Haven covers is the fake login page, the point of no return in this kind of attack, and that step recurs no matter how the next delivery trick is built.


What businesses should do

The specific campaign is closed, but the playbook behind it is not. A few controls address the pattern:

  • Treat any login request that arrives by message as suspect, even when the email genuinely comes from a trusted platform. Navigate to Meta Business Suite directly instead of following the link.

  • Turn on phishing-resistant MFA, such as passkeys or security keys, for everyone with access to business accounts and ad accounts.

  • Use role-based access and remove standing admin rights that are not needed, so one compromised login does not expose the whole account.

  • Monitor ad accounts for unexpected spend and new payment methods, which is often the first visible sign of takeover.

  • Add browser-layer detection of fake login pages, so an impersonated Meta program page is flagged for the employee before credentials are entered.

  • Give staff a fast, no-blame way to report a suspicious message, especially one that appears to come from a real platform.

No single control catches everything, which is why the attackers work to beat them one at a time. Pairing identity controls with a browser layer closes the gap between a trusted-looking email and the fake page it leads to.


About Haven

Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link or enter your password, flagging fake and impersonated login pages, suspicious links, and lookalike sites. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.

Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee, and Haven for MSP lets managed service providers deliver it across their clients. Haven is operated by MirrorTab, Inc.


FAQs

Can a phishing email really come from Meta's own address?

In this campaign, yes. Attackers abused a legitimate Meta business feature that routes messages between business accounts through Meta's own infrastructure, so the phishing emails were genuinely sent from a Meta address and landed directly in inboxes. Meta has since added guardrails to stop it, but it shows why the sender alone is not proof a message is safe.

What is the Meta Agency Partner Program, and how was it used in the scam?

The Meta Agency Partner Program is a real initiative that connects businesses with social media professionals. Attackers impersonated it in their phishing emails and built fake login pages, hosted outside Meta's systems, that copied its branding. The familiar, business-appropriate framing made recipients more likely to trust the message and sign in.

What happens if my Meta Business account is taken over?

Attackers can change your password and recovery methods to lock you out, spend your advertising budget on scam or malicious ads, and use your trusted account to send further attacks to your customers and followers. The result combines financial loss, brand damage, and risk to the people who trust your accounts.

How can I tell if a Meta Business login page is fake?

Check the web address before entering anything. A fake page has to live on a domain that is not Meta's, so an unfamiliar or slightly-off address is the clearest sign, even when the branding is perfect. Do not rely on how the page looks or on the fact that the email seemed to come from Meta. A browser-security tool like Haven can flag a fake Meta login page automatically.

How does Haven help against Meta Business account phishing?

Haven is a browser extension that detects fake and impersonated login pages and warns the user before they enter credentials. Because it analyzes the actual page rather than trusting how it looks or how the person arrived, it can flag a fake Meta Agency Partner Program or Meta Business login page even when the phishing email was delivered from Meta's real address. Haven is free for individual use, and Haven for Business extends this across a team.

Is Haven free?

Yes. Haven is free for individual use. Haven for Business and Haven for MSP extend browser-level protection to teams and managed service providers. Haven is operated by MirrorTab, Inc.