Briefing

AccountDumpling: Vietnamese-Linked Operation Uses Google AppSheet as Phishing Relay

security
by [email protected] (The Hacker News) ·

Check for phishing emails sent via Google AppSheet and advise users to enable 2FA on Facebook.

What to do now

Check for phishing emails sent via Google AppSheet and advise users to enable 2FA on Facebook.

Summary

A Vietnamese-linked operation, codenamed AccountDumpling by Guardio, has been observed using a Google AppSheet as a phishing relay to distribute emails aimed at compromising Facebook accounts.

The scheme leverages the AppSheet platform to send bulk phishing messages that trick users into revealing credentials. Once credentials are harvested, the attackers sell the stolen accounts through an illicit storefront. Roughly 30,000 Facebook accounts have been reported compromised in this activity. The operation demonstrates how low‑cost, cloud‑based tools can be repurposed for large‑scale credential theft. Facebook users are urged to enable two‑factor authentication to mitigate the risk. The incident underscores the need for vigilance against phishing campaigns that use legitimate services as relays.

Key changes

  • Vietnamese-linked operation uses Google AppSheet as phishing relay
  • Distributes phishing emails targeting Facebook accounts
  • Stolen accounts sold via illicit storefront
  • Roughly 30,000 Facebook accounts compromised

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting