← All news

phishing

The Facebook Verified Badge Scam That Ran for Seven Months

2026-07-09

For roughly seven months, from November 2025 until Meta pulled the plug in June 2026, a phishing crew ran a patient, well-built scam against Facebook business users. The bait was the one thing plenty of small brands genuinely want: a verified badge.

The emails looked like they came from a legitimate Facebook Business address, offering to 'protect the brand' with verification. According to researchers at Huntress, the messages glided past inbox security checks because the sending infrastructure was, technically, real. Click through and you arrived at a convincing login page that scooped up usernames, passwords and MFA codes in a single motion.

The chatbot did the heavy lifting

The interesting part came after the login. Victims were handed off to a Messenger chatbot called 'AI Strategic Partner', which walked them through a second round of 'verification'. Another login. Another MFA prompt. And then, to really nail down identity, a request to upload a passport, driver's licence or national ID.

By the end of that little conversation, the attackers had the credentials, the MFA bypass, and a photo of a government document. A tidy set of ingredients for pretty much any downstream fraud you can imagine.

What happens to a hijacked business account

Huntress' Andrew Brandt pointed out that once a business account is under someone else's control, the options are broad:

  • Burn through the victim's ad budget running scam campaigns to a wider audience.
  • Swap recovery email and phone details, locking the real owner out of their own page.
  • Use the trusted account to phish the business' customers and followers, who have no reason to be suspicious of a message from a brand they already follow.

The passport photo has a life of its own too. Government ID scans are useful for opening accounts elsewhere, bypassing KYC checks, and building convincing synthetic identities.

The tells were all there

The signs were the usual ones. Odd grammar. Broken formatting. Links that did not quite match. And the small structural detail that Facebook's actual verification is a paid service you sign up for from inside the platform. It does not turn up unsolicited in your inbox with a free offer attached.

What makes the campaign worth studying is not the sophistication of any single step. Each individual piece, the lookalike email, the credential harvester, the chatbot, the ID upload, is old news on its own. Stitched together into a single guided journey, with a chatbot playing the role of helpful support agent, they add up to something a lot of otherwise cautious users walked straight through.

Seven months is a long time to run a campaign like this before it gets shut down. Long enough to suggest that when the offer is desirable enough and the wrapper looks official enough, a surprising number of business owners will hand over the keys, the spare set, and a photo of their passport on the way out.

The Facebook Verified Badge Scam That Ran for Seven Months | RiskSense