Researchers reported two large phishing operations that abused trusted platforms to improve delivery and evade defenses. Guardio said the AccountDumpling campaign used Google AppSheet to send emails from legitimate Google infrastructure while impersonating Meta Support and recruiters, luring Facebook Business users with fake account disablement notices, copyright complaints, and job offers. The operation compromised about 30,000 Facebook accounts across roughly 50 countries, stealing credentials, 2FA codes, personal data, and government ID images; the stolen information was often funneled through Telegram channels, and the hijacked accounts were later sold or monetized through fraudulent advertising and scams. Evidence in generated PDF metadata linked the activity to Vietnam-based operators, including an individual identified as PHẠM TÀI TÂN.
Microsoft separately disclosed an adversary-in-the-middle phishing campaign that used fake workplace compliance notices to target more than 35,000 users at 13,000 organizations in 26 countries, with most activity concentrated in the United States. Attackers posed as internal HR and compliance teams, sent urgent messages with attached PDFs, and pushed victims through redirects, CAPTCHA checks, and a counterfeit Microsoft sign-in page designed to steal session tokens rather than just passwords, allowing account access without the victim's second factor. The incidents show how attackers are increasingly relying on legitimate cloud services and convincing enterprise-themed lures to bypass spam controls, defeat traditional authentication protections, and accelerate account takeover at scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Defender Research publicly detailed the April phishing campaign, explaining its use of PDFs, redirects, CAPTCHA checks, and fake Microsoft sign-in pages to capture session tokens and bypass passwords and second-factor prompts. Microsoft also issued mitigations including phishing-resistant MFA, Defender for Office 365 protections, and user awareness measures.
Guardio reported evidence tying the AccountDumpling operation to Vietnamese threat actors, including metadata from generated PDFs and infrastructure associated with an individual named PHẠM TÀI TÂN. The reporting also described exfiltration via Telegram channels and the resale of hijacked Facebook accounts on illicit marketplaces.
An ongoing phishing operation dubbed AccountDumpling targeted Facebook Business and advertiser account owners by impersonating Meta support and recruiters, abusing trusted services including Google AppSheet to deliver lures and harvest credentials. The campaign reportedly compromised about 30,000 Facebook accounts across roughly 50 countries, with stolen data and access monetized through scams, ad abuse, and illicit account sales.
A separate adversary-in-the-middle phishing campaign operated from April 14 to April 16, 2026, using fake workplace compliance and HR notices to steal Microsoft account session tokens. It targeted more than 35,000 users across 13,000 organizations in 26 countries, primarily in the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.