Key takeaways
The scam email claims your Facebook Page is eligible for an official blue verification badge, then pressures you to act within 24 hours.
The link leads to a fake page that imitates Meta Accounts Centre and collects your Facebook login, your MFA codes, and identity documents across several steps.
Because it asks for ID and repeat security codes, the goal is full Page and business account takeover, not just a stolen password.
The reliable tell is the page itself: it lives on a lookalike domain, not a genuine Facebook or Meta address.
The fake Meta sign-in page is the step Haven is built to catch, before you enter anything.
An email arrives saying your Facebook Page qualifies for the blue verification badge. All you have to do is confirm a few details to activate it, and you have 24 hours before the offer expires. It feels like good news. It is a scam, and it is built to walk you through a fake verification process that hands over your login, your security codes, and even a photo of your ID.
Unlike the usual "your account will be suspended" threat, this one opens with a reward. That is what makes it effective. Here is how Meta verification phishing works, and the one thing that reliably gives it away.
What's happening
Hornetsecurity's Threat Intelligence Lab analyzed a phishing campaign impersonating Facebook and Meta and aimed at Facebook Page owners and administrators, detailed in their report. Rather than a crude password form, it runs as a staged verification workflow, and it was spread partly by abusing a legitimate Google service so the emails looked more trustworthy on arrival.
The lure is the blue badge. For a small business, creator, or marketing team, verification signals credibility and visibility, so an offer to grant it feels valuable rather than suspicious. Then the message adds a deadline, warning that the Page will lose reach or benefits if you do not act within 24 hours. Trust, reward, and pressure, stacked together.
Why this is more than a stolen password
Most phishing stops once it has your password. This kit keeps going.
After the fake login, it prompts again for credentials and MFA codes, which suggests it is trying to work around failed logins or account-recovery checks in real time. Then it asks for identity verification documents. That last request is the giveaway that the goal is bigger than one account: an ID can support account-recovery abuse, impersonation, and identity fraud. For a business, a taken-over Facebook Page can lead to brand abuse, advertising fraud run on your payment methods, and real reputational damage with your customers.
The kit also quietly collects your IP address and location before you submit anything, and it stages what it gathers in your browser's local storage in encrypted form before sending it to the attacker. It is engineered as a structured data-collection tool, and it supports more than a dozen languages, which points to a reusable, phishing-as-a-service style operation that can be pointed at any market.
The moment that matters: the fake Meta page
Here is the reassuring part. However convincing the email and the workflow are, the whole scheme depends on one thing: getting you to enter your details on a fake page that imitates Meta Accounts Centre. And a fake page cannot be the real Meta. It has to live on a lookalike domain, not a genuine Facebook or Meta address. That is the dependable tell.
The problem is that a lookalike domain is easy to miss when the page looks right, the branding is right, and a countdown is ticking. The logo checks out, the layout checks out, and you are focused on the badge. Most people glance and type. That is exactly the moment a browser-security tool is built for.
How Haven helps
Haven is designed to catch fake and impersonated login pages at the moment you are about to enter your credentials. It analyzes the actual page in front of you, not just how it looks or how you arrived, so when a page imitates the Meta or Facebook sign-in on a lookalike domain, Haven flags it as fraudulent and warns you before you type your password or a security code.
That matters here because the attackers work hard to get the link past earlier checks, routing it through a redirector and a trusted service so it looks clean in your inbox. Haven works at the page itself, the step where the theft actually happens, so a disguised link and a polished fake page still get flagged. If you are unsure about a link, you can also paste it into Haven's free link checker before you click.
To be precise about scope: this kit also tries to capture MFA codes in real time, so the strongest protection is not entering anything on the fake page in the first place. That is Haven's job, flagging the impersonated Meta page before a single credential is typed. We would rather be clear about that than overclaim.
How to protect yourself and your Page
A few habits stop this kind of attack:
Treat any unexpected "you qualify for verification" message with suspicion, even when it looks polished and uses real Meta branding.
Do not act on the deadline. The 24-hour countdown exists to rush you. A real badge offer does not evaporate because you paused to check.
Never enter your Facebook password, security codes, or ID through a link in an email. Check your Page's status directly in the Facebook app or by typing the address yourself.
Never send identity documents to a verification page you reached from a message. Legitimate verification does not work that way.
Turn on a passkey or a phishing-resistant second factor, and if you manage a business Page, use role-based access so one compromised login does not hand over everything.
Add a browser-security layer that flags fake login pages, so a convincing Meta lookalike cannot quietly take your credentials.
The lure changes, but the core move is always the same: borrow a trusted brand, offer something you want, and rush you onto a fake page. Slow down at that page, and the whole thing falls apart.
About Haven
Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link or enter your password, flagging fake and impersonated login pages, suspicious links, and lookalike sites. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.
Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee, and Haven for MSP lets managed service providers deliver it across their clients. Haven is operated by MirrorTab, Inc.
FAQs
Is the Facebook verification badge email real or a scam?
If you did not request verification and the message pressures you to act within a short window, treat it as a scam. Meta verification phishing offers a blue badge to lure Page owners into a fake verification workflow that steals credentials, MFA codes, and identity documents. Check your Page status directly in the Facebook app, not through a link in the email.
How does Meta verification phishing work?
You receive an email claiming your Facebook Page is eligible for an official verification badge, with a 24-hour deadline. The link routes you through a redirector to a page that imitates Meta Accounts Centre. Across several steps, the page collects your Page details, Facebook login, MFA codes, and identity documents, which the attacker uses to take over the Page and business account.
Why does the scam ask for my ID?
Requesting identity documents points to goals beyond a stolen password. An ID can be used for account-recovery abuse, impersonation, and identity fraud, and it helps an attacker hold onto a hijacked account. A legitimate verification process never asks you to upload your ID through a link in an unsolicited email.
How can I tell if a Meta or Facebook login page is fake?
Check the web address before entering anything. The scam has to use a lookalike domain, not a genuine Facebook or Meta address, so an unusual or slightly-off address is the clearest sign. Do not rely on the logo or layout, which are easy to copy. A browser-security tool like Haven can flag a fake Meta login page automatically.
What should I do if I entered my details on a fake verification page?
Change your Facebook password immediately from the real app or site, review active sessions and remove any you do not recognize, and confirm your recovery email and phone number are still yours. Turn on a passkey or phishing-resistant MFA, check for unfamiliar admins on your Page, and report the compromise to Meta. If you uploaded an ID, watch for identity-fraud attempts.
How does Haven help against Meta verification phishing?
Haven is a browser extension that detects fake and impersonated login pages and warns you before you enter your credentials. Because it analyzes the actual page rather than trusting how it looks or how you arrived, it can flag a fake Meta Accounts Centre page on a lookalike domain even when the link was disguised and routed through a trusted service. Haven is free for individual use.
Is Haven free?
Yes. Haven is free for individual use. Haven for Business and Haven for MSP extend browser-level protection to teams and managed service providers. Haven is operated by MirrorTab, Inc.