AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts)

AccountDumpling (TL-2026-0453), also tracked as AccountDumpling, is a high-severity phishing campaign, first published 2026-05-04. It is attributed to AccountDumpling Operators (Vietnam) with medium confidence, affects Meta Platforms Facebook (consumer accounts), maps to 30 MITRE ATT&CK techniques (T1027, T1027.006, T1036), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0453

Threat ID
TL-2026-0453
Also known as
AccountDumpling, AppSheet Facebook Phishing Wave, Vietnamese Facebook Account Hijacking Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-05-04
Last reviewed
2026-05-04
Attribution
AccountDumpling Operators
Attribution confidence
MEDIUM
Nation-state nexus
Vietnam
Motivation
FINANCIAL
Target sectors
marketing-agencies, small-and-medium-business, ecommerce, media-and-publishing, creators-and-influencers, advertising, retail, consumer-brands
Target regions
North America, Europe, Asia-Pacific, Latin America, United States, Canada, United Kingdom, Italy, Spain, Australia, Philippines, India
Detection rules
9
Indicators of compromise
20

Malware and tooling in AccountDumpling

Malware and tooling: Socket.IO / WebSocket operator panel, Telegram bots and private channels

AccountDumpling is a long-running, Vietnamese-linked phishing operation tracked by Guardio Labs that abuses Google AppSheet's notification system to deliver SPF/DKIM/DMARC-authenticated emails impersonating Meta. The campaign has compromised ~30,000 Facebook accounts — primarily business and advertiser profiles — by harvesting credentials, 2FA codes, government IDs, and session tokens through Netlify/Vercel/Google Drive-hosted phishing flows backed by real-time Telegram operator panels.

How AccountDumpling works

AccountDumpling is an industrial-scale, Facebook-focused phishing operation publicly disclosed by Guardio Labs (Shaked Chen) on 2026-05-03 and corroborated by Malwarebytes Labs on 2026-05-04. The operation has compromised approximately 30,000 Facebook accounts to date, with disproportionate impact on Facebook Business and advertiser profiles managed by SMBs, marketing agencies, brands, creators, and influencers across the United States, Italy, Canada, the Philippines, India, Spain, Australia, the United Kingdom, Brazil, and Mexico.

The operation's signature TTP is the abuse of Google AppSheet — Google's no-code app and workflow notification platform — as an authenticated phishing relay. Phishing emails are emitted from noreply@appsheet.com via the appsheet.bounces.google.com return path, inheriting Google's sender reputation and passing SPF, DKIM, and DMARC checks. The lures are uniformly Meta-themed urgency narratives: alleged Facebook policy violations, copyright complaints, account deletion notices, blue badge verification offers, suspicious login alerts, and recruiter outreach impersonating Meta, WhatsApp, Adobe, Pinterest, Apple, and Coca-Cola.

Guardio Labs documented four operational clusters. Cluster 1 directs victims to Netlify-hosted clones of the Facebook Help Center, with per-victim subdomains used to defeat URL blocklists, harvesting credentials, dates of birth, phone numbers, and government-issued ID photos. Cluster 2 runs on Vercel under names such as 'Security Check' or 'Meta | Privacy Center', preceded by a fake CAPTCHA gate, and intentionally rejects the first password attempt to force a retry that confirms credentials. Cluster 3 distributes Canva-generated PDFs hosted on Google Drive that masquerade as Meta verification instructions and chain to phishing pages with Socket.IO/WebSocket-driven operator panels capable of requesting additional 2FA codes, ID photos, and browser screenshots from victims in real time. Cluster 4 uses direct social engineering, with operators posing as recruiters from major brands to build trust before pivoting victims to attacker-controlled channels.

Stolen data — credentials, 2FA codes, recovery information, ID documents, and session tokens — flows in real time to private Telegram bots and channels, allowing operators to attempt account takeover before victims realize they have been phished. The phishing kits employ multiple evasion techniques including invisible Unicode characters, Cyrillic homoglyphs, mid-word text breaking, anti-debugging logic, encrypted localStorage, shortened URL chains, and full-screen iframe hiding. Vietnamese attribution is supported by Canva PDF metadata listing the author 'PHẠM TÀI TÂN' and OSINT links to Vietnamese-language digital marketing front sites; Guardio's researchers describe the body of evidence as 'a consistent picture of a large, Vietnamese-based, mega operation' though not a formal law enforcement attribution. Compromised accounts are monetized through fraudulent advertising, payment-method abuse, page resale in underground markets, brand impersonation against followers, and bogus 'account recovery' services upsold back to victims.

MITRE ATT&CK techniques used in TL-2026-0453

Defense Evasion

T1027 Obfuscated Files or Information; T1027.006 Obfuscated Files or Information: HTML Smuggling; T1036 Masquerading; T1684.001 Impersonation

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service; T1102.002 Web Service: Bidirectional Communication

Initial Access

T1078 Valid Accounts; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Discovery

T1087 Account Discovery

Collection

T1113 Screen Capture

Execution

T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Impact

T1531 Account Access Removal; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1608.002 Stage Capabilities: Upload Tool

Reconnaissance

T1589 Gather Victim Identity Information; T1589.002 Gather Victim Identity Information: Email Addresses

Affected products and versions in AccountDumpling

  • Meta Platforms — Facebook (consumer accounts)
    Vulnerable versions: all
  • Meta Platforms — Facebook Business / Pages / Meta Business Suite
    Vulnerable versions: all
  • Meta Platforms — Instagram (connected accounts)
    Vulnerable versions: all
  • Google — AppSheet (notification/email relay abused)
    Vulnerable versions: current
  • Netlify — Netlify hosting (phishing page hosting abuse)
    Vulnerable versions: current
  • Vercel — Vercel hosting (phishing page hosting abuse)
    Vulnerable versions: current
  • Google — Google Drive (PDF lure hosting abuse)
    Vulnerable versions: current
  • Canva — Canva (PDF lure generation abuse)
    Vulnerable versions: current
  • Telegram — Telegram bots and channels (exfiltration abuse)
    Vulnerable versions: current

Remediation for AccountDumpling

Immediate actions

  • Block or quarantine inbound mail from noreply@appsheet.com unless an explicit business need exists; tag remaining AppSheet mail with external-banner and high-risk warnings
  • Deny-list or sandbox links to per-victim Netlify (*.netlify.app) and Vercel (*.vercel.app) subdomains arriving in Meta/Facebook-themed messages
  • Inspect Google Drive PDFs delivered via email that claim to be Meta or Facebook verification notices; treat Canva-generated PDF metadata as a strong phishing signal
  • Force password reset, MFA re-enrollment, and session revocation for any Meta Business Suite, Facebook, or Instagram administrator who interacted with an AppSheet-originated Meta-themed email
  • Audit Meta Business Manager admin lists, payment methods, ad spend, page roles, and connected Instagram accounts for unauthorized changes in the last 90 days
  • Submit confirmed phishing pages and Telegram bot handles to takedown channels (Netlify abuse, Vercel abuse, Google AppSheet abuse, Telegram abuse, Meta security)

Workarounds

  • Establish an enterprise rule that Facebook account warnings are never resolved from email links — only by navigating directly to business.facebook.com or accountscenter.facebook.com
  • Require a help-desk-verified out-of-band check before any Meta Business administrator submits ID documents in response to a verification request
  • Restrict AppSheet receipt to allow-listed internal senders only, where business processes permit

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn passkeys) on all Meta Business administrator accounts to defeat 2FA interception
  • Adopt a security-aware secure email gateway that scores message intent and brand impersonation independently of SPF/DKIM/DMARC verdicts
  • Treat Facebook, Instagram, and Meta Business assets as Tier-1 operational accounts in identity governance, with least-privilege admin roles and mandatory quarterly access reviews
  • Add social media account takeover playbooks (Meta proof-of-ownership, ad spend freeze, recovery contacts) to the incident response plan
  • Run continuous user-awareness training featuring authenticated-but-malicious email examples, including the AppSheet abuse pattern
  • Monitor for Canva-generated PDF metadata and AppSheet-originated Meta-themed traffic in DLP/CASB telemetry
  • Subscribe to threat intelligence feeds covering trusted-platform phishing abuse and brand impersonation

Weaknesses (CWE) in AccountDumpling

CWE-290, CWE-294, CWE-308, CWE-345, CWE-451, CWE-1021

Timeline of AccountDumpling

  • Guardio Labs describes the operation as long-running; ~30,000 victim records aggregated by the time of disclosure imply campaign activity over multiple prior months.
  • Guardio Labs (Shaked Chen) actively investigates four distinct phishing clusters using AppSheet, Netlify, Vercel, Google Drive, Canva, and Telegram.
  • AnalyticsInsight and DigitalWarfare publish secondary coverage of the AccountDumpling campaign with technical breakdowns of the AppSheet abuse and Telegram exfiltration chain.
  • Guardio Labs publishes the AccountDumpling research, naming the operation, attributing it to Vietnamese-linked operators, and documenting the four-cluster architecture and ~30,000 compromised Facebook accounts.
  • Researchers note the operation remains active at time of disclosure, with phishing infrastructure still observed in the wild.
  • Threadlinqs Intelligence ingests AccountDumpling as TL-2026-0453 for tracking, detection engineering, and simulation.
  • Malwarebytes Labs publishes a consumer-facing analysis warning about AppSheet-relayed Meta-themed phishing emails and the live Vietnamese operation.
  • As of 2026-05-29, AccountDumpling remains an active, undisrupted Vietnamese-linked phishing operation: Kaspersky reported ongoing AppSheet-relayed account-hijacking on 2026-05-27, and Google has issued no fix since the abused platforms (AppSheet, Netlify, Vercel, Telegram) are legitimate. No CVE to patch, no takedown or arrests, and the abuse vector stays fully viable.

Sources cited for AccountDumpling

Threats related to AccountDumpling

Detection coverage for TL-2026-0453

As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0453 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats