A newly discovered Vietnamese-linked operation has been observed using a Google AppSheet as a "phishing relay" to distribute phishing emails with an aim to compromise Facebook accounts. The activity involves a scheme selling the stolen accounts back through an illicit storefront run by the threat actors. In all, roughly 30,000 Facebook accounts are estimated to have been hacked as part of the campaign.
The findings are just the latest example of how Vietnamese threat actors continue to embrace various tactics to gain unauthorized access to victims' Facebook accounts, which are then sold on underground ecosystems for monetary gain.
The activity has been codenamed AccountDumpling by Guardio.
The starting point of the latest attacks is a phishing email targeting Facebook Business account owners, claiming to be from Meta Support and urging them to submit an appeal, or risk getting their account permanently deleted. The emails are sent from a Google AppSheet address ("noreply@appsheet.com"), allowing them to bypass spam filters.
This false sense of urgency is used to direct users to a fake web page designed to harvest their credentials. It's worth noting that a similar campaign was reported by KnowBe4 in May 2025.
Over the past few weeks, these campaigns have adopted various kinds of lures designed to induce a "Meta-related panic." These range from account disablement and copyright complaints to verification review, executive recruitment, and Facebook login alerts.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




