Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Facebook users are targeted by a scam using a Google domain

Cybercriminals exploited Google AppSheet on May 26 to send phishing emails from a legitimate "noreply@appsheet.com" address targeting Facebook user accounts.

byKerem Gülen
May 27, 2025
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

Cybercriminals used Google AppSheet to send phishing emails from “noreply@appsheet.com” to bypass email protection, targeting Facebook accounts according to Techradar.

Cybersecurity researchers KnowBe4 discovered the attacks, which exploit a legitimate Google service to deliver emails straight to inboxes, mimicking Facebook to trick people into giving away login credentials and 2FA codes.

The emails, sent in bulk, bypassed Microsoft and Secure Email Gateways (SEGs) that rely on domain reputation and authentication checks (SPF, DKIM, DMARC), with each email being slightly different due to AppSheets’ unique ID generation.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The phishing emails claim the recipient infringed on someone’s intellectual property and their account will be deleted within 24 hours unless they submit an appeal through a provided button, leading to a landing page impersonating Facebook hosted on Vercel.

Victims are prompted to provide login credentials and 2FA codes, which are relayed to the attackers, with the first login attempt returning a “wrong password” result to confirm submission, and the provided 2FA codes being submitted to Facebook to obtain a session token for persistence.

Cybersecurity platform Keeper offers features like two-factor authentication, dark web monitoring, and breach alerts to protect against such threats, using zero-knowledge encryption to securely store and manage passwords and sensitive files.


Featured image credit

Tags: CybersecurityFacebookGoogle

Related Posts

Airloom to showcase roller coaster style wind turbines at CES 2026

Airloom to showcase roller coaster style wind turbines at CES 2026

January 2, 2026
Samsung unveils Freestyle+ projector ahead of CES 2026

Samsung unveils Freestyle+ projector ahead of CES 2026

January 2, 2026
OpenAI explores prioritizing sponsored ads in ChatGPT responses

OpenAI explores prioritizing sponsored ads in ChatGPT responses

January 2, 2026
Apple Fitness+ teases major 2026 plans in new Instagram Reel

Apple Fitness+ teases major 2026 plans in new Instagram Reel

January 2, 2026
Leaked Samsung 20000mAh battery test reveals major swelling

Leaked Samsung 20000mAh battery test reveals major swelling

January 2, 2026
OpenAI unifies teams to build audio device with Jony Ive

OpenAI unifies teams to build audio device with Jony Ive

January 2, 2026

LATEST NEWS

Airloom to showcase roller coaster style wind turbines at CES 2026

Samsung unveils Freestyle+ projector ahead of CES 2026

OpenAI explores prioritizing sponsored ads in ChatGPT responses

Apple Fitness+ teases major 2026 plans in new Instagram Reel

Leaked Samsung 20000mAh battery test reveals major swelling

OpenAI unifies teams to build audio device with Jony Ive

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.