{"id":1209,"date":"2024-03-07T13:45:09","date_gmt":"2024-03-07T21:45:09","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1209"},"modified":"2024-03-07T13:45:11","modified_gmt":"2024-03-07T21:45:11","slug":"phishing-from-3-5-2024-urgent-notice-your-ad-account-demands-immediate-action","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1209","title":{"rendered":"Phishing from 3\/5\/2024: &#8220;Urgent Notice: Your Ad Account Demands Immediate Action.&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>Meta for Business &lt;facebook[@]bussiness-support-team[.]com><br><strong>Subject:<\/strong> Urgent Notice: Your Ad Account Demands Immediate Action.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"712\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/03\/3070-24-meta-phish-1024x712.png\" alt=\"\" class=\"wp-image-1211\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/03\/3070-24-meta-phish-1024x712.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/03\/3070-24-meta-phish-300x208.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/03\/3070-24-meta-phish-768x534.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/03\/3070-24-meta-phish.png 1180w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice that the sender email address is facebook[@]bussiness-support-team[.]com. Legitimate account notification emails from Instagram or Facebook will come from @mail.instagram.com or @facebookmail.com.<\/li><li>Notice the false sense of urgency in language like &#8220;24-hour account restriction&#8221; and &#8220;implore you to initiate an immediate account review&#8221;. <\/li><li>The link does not go where you would expect. Always investigate links before clicking. Alternately, go to the known website of a company instead of clicking links in an email.<\/li><li>Notice the mailing address is in Ireland and is not the address of Meta&#8217;s headquarters.<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>Meta for Business &lt;facebook[@]bussiness-support-team[.]com><br><strong>Subject:<\/strong> Urgent Notice: Your Ad Account Demands Immediate Action. <\/p>\n\n\n\n<p>Your account is currently under review, and suspension is a possible outcome.<\/p>\n\n\n\n<p>Dear [<em>name removed<\/em>]<\/p>\n\n\n\n<p>I trust this message finds you well. We are reaching out to address a matter of utmost importance related to your recent advertising campaign. Our thorough analysis, fueled by valuable customer feedback, has uncovered significant policy violations that cannot be overlooked.<\/p>\n\n\n\n<p>In response to these concerns, we have implemented a 24-hour account restriction to facilitate a meticulous review. A summary of the customer feedback highlights several critical issues:<br>-Unauthorized use of prohibited images and content.<br>-Incorporation of non-copyrighted materials without proper authorization.<br>-Allegations of collecting personal information from individuals without explicit consent.<\/p>\n\n\n\n<p>To swiftly address and rectify any potential misunderstandings, we implore you to initiate an immediate account review by clicking the button below:<\/p>\n\n\n\n<p>Request Review [<em>link removed<\/em>]<\/p>\n\n\n\n<p>Your cooperation is pivotal in upholding the standards of our advertising platform. Failure to respond within the next 24 hours may regrettably result in a permanent account restriction. We genuinely appreciate your prompt attention to resolving these concerns.<\/p>\n\n\n\n<p>Best regards,<br>Meta Ads Support Team.<\/p>\n\n\n\n<p>This message was sent to [<em>username removed<\/em>]@pugetsound.edu. For security reasons, please refrain from forwarding this email.<\/p>\n\n\n\n<p>\u00a9 Meta Platforms Ireland Ltd., Attention: Community Operations, 4 Grand Canal Square, Dublin 2, Ireland.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: Meta for Business &lt;facebook[@]bussiness-support-team[.]com>Subject: Urgent Notice: Your Ad Account Demands Immediate Action. Tips for Detection Notice that the sender email address is facebook[@]bussiness-support-team[.]com. Legitimate account notification emails from Instagram or Facebook will come from @mail.instagram.com or @facebookmail.com. Notice the false sense of urgency in language like &#8220;24-hour account restriction&#8221; and &#8220;implore [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1211,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-1209","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1209"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1209\/revisions"}],"predecessor-version":[{"id":1212,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1209\/revisions\/1212"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1211"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}