Caught in the Wild: Real Facebook
Recent reporting describes a scam breaking the "check the sender" rule
The phishing email that came from a real Facebook address
Here's a scam that breaks the "check the sender" rule. For eight months, attackers sent phishing emails from noreply@business.facebook.com. Not a lookalike. The real address.
Huntress researchers found they'd abused a legitimate Meta feature — the one that lets businesses invite outside social media managers. Because the invites come from Meta's own servers, they passed every filter. The email offered a blue verification badge to "protect your brand," then walked victims (lately via a fake Messenger chatbot) to a near-perfect replica of Meta's verification page. It asked for your password. Then your 2FA code. Then a photo of your ID. All of it went to the attackers' Telegram channel.
The tell? The fake page was framed inside another site to hide its address — invisible to the eye. But the browser's "save password" prompt showed the real domain, not facebook.com, and gave the game away. The human saw Facebook. The password tooling saw the truth.
For small business owners
If you run your company's Facebook page, you're the target — attackers who take it can burn your ad budget on scam ads, lock you out, or phish your own customers from your page. Real Meta verification is a paid process that starts inside Facebook. It never arrives free in your inbox. And check Business Settings for "partners" you don't recognize.
Where SAFE Portal fits: It fills your Facebook password on Facebook's real domain and nowhere else. On a pixel-perfect fake, it stays silent — and that silence is your alarm. Don't type it in by hand. Close the tab.
What it won't do: It can't stop you from manually entering a 2FA code or uploading your ID once you're convinced. It catches the first step. Knowing the playbook — that's this newsletter's job.
SAFE Portal is free to download and takes about two minutes to set up — no IT team required. Get it at SAFEPortal.to.