Drooid Logo
Back to story perspectives

Full Breakdown

Vietnamese-Linked “AccountDumpling” Phishing Campaign Hijacks 30,000 Facebook Accounts

5/3/2026, 5:58:58 AM

Core Event

Guardio Labs uncovered a phishing campaign, codenamed AccountDumpling, that has compromised 30,000 Facebook accounts. Emails sent from the Google AppSheet address noreply@appsheet.com impersonate Meta Support, urging Business account owners to appeal or face deletion, and lead victims to fake login pages that harvest credentials and 2FA codes.

Operation Structure

Four clusters are used. Cluster A clones the Facebook Help Centre on Netlify to steal passwords and ID photos. Cluster B lures victims with fake Blue-Badge verification, using homoglyphs to bypass filters. Cluster C serves Google Drive-hosted PDFs that embed operator panels via Socket IO for credential capture. Cluster D sends fabricated job offers from Adobe, redirecting users to WhatsApp chats. A Canva PDF lists author “PHAM TÀI TÂN,” linked to phamtaitan.vn; Telegram channels run under the aliases “Big Bosss” and “@mansinblack.”

Scale and Victim Geography

Telegram channels tied to the first three clusters hold about 30,000 victim records. Approximately 68.6 % of compromised accounts are from the United States, with the United Kingdom, Canada, Italy, the Philippines, India, Spain, Australia, Brazil and Mexico also represented. Stolen data includes passwords, 2FA codes, government-issued ID images and browser screenshots captured via html2canvas.

Official Response and Criticism

Guardio Labs warned the campaign functions as a professional supply chain: one group steals Facebook accounts, another sells the access. Researchers noted the abuse of Google’s AppSheet infrastructure, where legitimate SPF, DKIM and DMARC checks let malicious emails appear authentic. The commoditization of stolen Facebook identities raises concerns about fraud, ad-spending abuse and user-trust erosion. Guardio advises scrutinizing unsolicited Meta-related messages, verifying URLs before entering credentials and reporting suspicious activity to platform security teams.

Conflicting Reports

All sources agree on ~30,000 compromised accounts, but victim-distribution details differ: one source gives a 68.6 % U.S. share, another lists many countries without percentages. The timeline beyond the April 2026 email is unclear.

Verbatim Quotes

  • “What we found wasn't a single phishing kit,” — Shaked Chen, Guardio Labs
  • “It was a living operation with real-time operator panels, advanced evasion, continuous evolution and a criminal-commercial loop that quietly feeds on the same accounts it helps steal back.” — Shaked Chen, Guardio Labs
  • “Taken together, they form a consistent picture of a large, Vietnamese-based, mega operation,” — Shaked Chen, Guardio Labs
  • “This campaign is bigger than a single AppSheet abuse. It's a window into the dark market around stolen Facebook assets, where access, business identity, ad reputation, and even account recovery have all become tradable commodities. Another entry in the pattern we keep surfacing: trusted platforms repurposed as delivery, hosting, and monetization layers.” — Shaked Chen, Guardio Labs

What’s Next

Guardio Labs will keep monitoring the Telegram channels for new victim uploads and track any evolution of the phishing lures. Users should enable login alerts, verify the sender domain of Meta-related emails and report suspicious communications to platform security teams.