Summary
A sophisticated phishing campaign exploited a genuine Meta business feature to send scam emails appearing to originate from Meta's own address, tricking victims into revealing credentials for account takeover and fraudulent advertising. Cybersecurity firm Huntress uncovered the scheme, which Meta has since mitigated with new guardrails.