Cybercriminals exploit Google AppSheet (a legitimate Google service) to send phishing emails from @appsheet.com addresses, easily bypassing security checks (SPF, DKIM, DMARC) and making the emails look legitimate.
The fake email content announces copyright infringement, threatens to lock the Facebook account within 24 hours, and includes a "Submit an Appeal" button. When clicked, the victim is redirected to a fake Facebook login page hosted on the reputable Vercel platform, further increasing its credibility.

Pay particular attention to phishing emails from @appsheet.com saying "Facebook account lockout warning."
Notably, this fake website was hosted on Vercel, a reputable platform, further increasing the credibility of the entire scam.
Here, if the user enters their login information and two-factor authentication (2FA) code, all this data will be sent directly to the attacker.
Specifically, this scam involves reporting an "incorrect password" the first time, prompting the victim to re-enter the information to verify it. At that moment, the hacker collects all login information and 2FA authentication codes, then immediately gains access.
Experts say the danger lies in the fact that hackers can also steal session tokens (login session codes), allowing them to maintain access even after users have changed their passwords.
- To avoid losing your Facebook account to this sophisticated scam, users are advised to :
- - Absolutely do not click on any appeal links in unfamiliar emails.
- Always double-check the website address before logging in.
- - Activate additional security alerts on Facebook and other social media platforms.
- If you suspect anything, change your password and log out of all devices.
Source: https://khoahocdoisong.vn/chieu-moi-hack-facebook-bat-chap-ma-bao-mat-2-lop-post1555128.html






Comment (0)