AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts) — Threadlinqs Intelligence
As of 2026-05-30, AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts) is a high-severity phishing threat attributed to AccountDumpling Operators (Vietnam), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0453 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: AccountDumpling Operators · Vietnam · FINANCIAL
AccountDumpling is a long-running, Vietnamese-linked phishing operation tracked by Guardio Labs that abuses Google AppSheet's notification system to deliver SPF/DKIM/DMARC-authenticated emails
AccountDumpling is an industrial-scale, Facebook-focused phishing operation publicly disclosed by Guardio Labs (Shaked Chen) on 2026-05-03 and corroborated by Malwarebytes Labs on 2026-05-04. The operation has compromised approximately 30,000 Facebook accounts to date, with disproportionate impact on Facebook Business and advertiser profiles managed by SMBs, marketing agencies, brands, creators, and influencers across the United States, Italy, Canada, the Philippines, India, Spain, Australia, the United Kingdom, Brazil, and Mexico.
The operation's signature TTP is the abuse of Google AppSheet — Google's no-code app and workflow notification platform — as an authenticated phishing relay. Phishing emails are emitted from noreply@appsheet.com via the appsheet.bounces.google.com return path, inheriting Google's sender reputation and passing SPF, DKIM, and DMARC checks. The lures are uniformly Meta-themed urgency narratives: alleged Facebook policy violations, copyright complaints, account deletion notices, blue badge verification offers, suspicious login alerts, and recruiter outreach impersonating Meta, WhatsApp, Adobe, Pinterest, Apple, and Coca-Cola.
Guardio Labs documented four operational clusters. Cluster 1 directs victims to Netlify-hosted clones of the Facebook Help Center, with per-victim subdomains used to defeat URL blocklists, harvesting credentials, dates of birth, phone numbers, and government-issued ID photos. Cluster 2 runs on Vercel under names such as 'Security Check' or 'Meta | Privacy Center', preceded by a fake CAPTCHA gate, and intentionally rejects the first password attempt to force a retry that confirms credentials. Cluster 3 distributes Canva-generated PDFs hosted on Google Drive that masquerade as Meta verification instructions and chain to phishing pages with Socket.IO/WebSocket-driven operator panels capable of requesting additional 2FA codes, ID photos, and browser screenshots from victims in real time. Cluster 4 uses direct social engineering, with operators posing as recruiters from major brands to build trust before pivoting victims to attacker-controlled channels.
Stolen data — credentials, 2FA codes, recovery information, ID documents, and session tokens — flows in real time to private Telegram bots and channels, allowing operators to attempt account takeover before victims realize they have been phished. The phishing kits employ multiple evasion techniques including invisible Unicode characters, Cyrillic homoglyphs, mid-word text breaking, anti-debugging logic, encrypted localStorage, shortened URL chains, and full-screen iframe hiding. Vietnamese attribution is supported by Canva PDF metadata listing the author 'PHẠM TÀI TÂN' and OSINT links to Vietnamese-language digital marketing front sites; Guardio's researchers describe the body of evidence as 'a consistent picture of a large, Vietnamese-based, mega operation' though not a formal law enforcement attribution. Compromised accounts are monetized through fraudulent advertising, payment-method abuse, page resale in underground markets, brand impersonation against followers, and bogus 'account recovery' services upsold back to victims.
Weaknesses (CWE)
CWE-290, CWE-294, CWE-308, CWE-345, CWE-451, CWE-1021
Target sectors: marketing-agencies, small-and-medium-business, ecommerce, media-and-publishing, creators-and-influencers, advertising, retail, consumer-brands
Target regions: North America, Europe, Asia-Pacific, Latin America, United States, Canada, United Kingdom, Italy, Spain, Australia, Philippines, India
Related threats
- 2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad)
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)
- FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery (CTM360, May 2026)
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1589.002, T1583.006, T1583.001, T1585.001, T1587.001, T1608.002, T1566.002, T1566.001, T1566.003