Phish of the Week
June 22, 2026

Phish of the Week 22nd of June

Phish of the Week 22nd of June
# Phish of the Week
# Phishing

Meta Business Manager Partner Request – Third-Party Service Misuse

Mette Luntama
Mette Luntama
Phish of the Week 22nd of June

Phish of the Week: Meta Business Manager Partner Request – Third-Party Service Misuse

This week's Phish of the Week features an attack that abuses Meta's own Business Manager Partner Request notification to deliver a malicious link ultimately leading to a credential harvester. Meta for Business is one of the most widely used advertising and business management platforms globally, making it an attractive vehicle for abuse. What makes this attack particularly effective is that the email itself is genuine — it is a real Facebook system notification, not a spoofed message. The attacker has simply found a way to smuggle a malicious link into it.

How the attack works:

The recipient receives a notification email from  [email protected] , a real Facebook sender address, informing them that their business qualifies for a Business Manager partnership. The email uses official Meta for Business branding and mirrors exactly how a genuine partner request notification looks — because it is one.
ďťż
The attacker has registered a Facebook business account and manipulated two separate fields to deliver the attack. The business name field contains a malicious URL, placed where the partner's name would normally appear. A second account name field carries explicit instructions designed to make sure the recipient acts on it: "Meta : Please access the link at the top of the page to view the collaboration proposal."
The malicious link leads to an external page, with no connection to any official Facebook or Meta property.
ďťż
The landing page presents what appears to be a Meta Verified promotion, using real Meta branding. The topic has shifted entirely from the partner request in the original email, but the familiar Meta visual identity keeps the page feeling credible. Clicking the "Get Verified" button leads to a credential harvester designed to capture the recipient's Meta account credentials.

Why the attack works:

The most significant trust signal in this attack is that the notification is real. It originates from an official Facebook sending domain, carries authentic Meta for Business branding, and is structured identically to how a legitimate partner request looks.
The injection mechanism is subtle. The malicious link and instructions appear in attacker-controlled account name fields. The surrounding content is so familiar that the injected text can easily be read as part of the notification rather than as something out of place.
The topic shift to Meta Verified on the landing page could raise suspicion, but for anyone less familiar with how Meta partner requests actually work, the two separate topics may even feel connected. The page itself closely mimics what a real Meta Verified promotion looks like, giving a recipient who has made it this far little reason to stop.

How to spot similar attacks:

  • The email contains a URL or phone number embedded in an unusual position, suggesting injected content rather than system-generated text
  • The email instructs the recipient to follow a link that appears as plain text rather than an official button generated by the platform
  • The link destination does not match any official Meta or Facebook domain
  • The landing page presents a topic unrelated to the one described in the original email
  • You land on a website that requires immediate account sign-in with no other options available
If you receive an unexpected notification that prompts you to follow a link, navigate directly to the platform through your browser or app to verify it — do not follow links embedded in the email.

What is Phish of the Week?

Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.
Comments (0)
Popular
avatar
ďťż
Dive in

Related

Content
Phish of the Week 29th of June
By Mette Luntama • Jun 29th, 2026 • Views 14
Content
Phish of the Week 8th of June
By Mette Luntama • Jun 8th, 2026 • Views 39
Content
Phish of the Week 15th of June
By Mette Luntama • Jun 15th, 2026 • Views 104
Content
Phish of the Week 11th of June
By Mette Luntama • Jun 11th, 2026 • Views 26
Content
Phish of the Week 29th of June
By Mette Luntama • Jun 29th, 2026 • Views 14
Content
Phish of the Week 15th of June
By Mette Luntama • Jun 15th, 2026 • Views 104
Content
Phish of the Week 11th of June
By Mette Luntama • Jun 11th, 2026 • Views 26
Content
Phish of the Week 8th of June
By Mette Luntama • Jun 8th, 2026 • Views 39
Privacy Policy
Your Privacy Choices