The AccountDumpling campaign targets Facebook Business account owners with emails impersonating Meta Support, creating a false sense of urgency to prompt users to click on links leading to fake credential harvesting pages.
Commercial spam now constitutes 46% of all spam globally, with a significant portion originating from compromised accounts and free email services, according to VIPRE Security Group's Q1 2026 Email Threat Trends Report.
HackRead reports that the newly emergent Bluekit phishing-as-a-service kit has been enabling extensive platform targeting with its over 40 counterfeit website templates for Outlook, Gmail, iCloud, GitHub, and Ledger, while evading multi-factor authentication through adversary-in-the-middle techniques, further lowering the barrier to cybercrime.
These financially-motivated attackers, closely aligned with Scattered Spider, use voice-phishing and social engineering to breach victims' identity platforms and traverse SaaS environments, according to a report by CrowdStrike.