
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with real ad history can run scam ads more easily and sell for a premium. Once attackers get in, they often lock out the real owner by changing admin roles, making recovery slow and costly.
Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms rather than obviously malicious infrastructure. According to the findings, about one in three detections arrived through Salesforce infrastructure, and another quarter came through Google Workspace mail-merge tools and SharePoint-hosted links. A typical lure impersonates Meta Business Support or Google Ads, warning the recipient of an account issue and pushing them to click a link and sign in, which harvests their credentials.
The core reason this works is trust transference. Sending through Salesforce, Google Workspace, or SharePoint means the sending IP, domain, and authentication records like SPF and DKIM all pass checks that would normally reject an unknown domain. As the reporting puts it, threat actors have moved away from purpose-built malicious infrastructure and toward legitimate, high-reputation sending platforms that email security tools are configured to trust. Once the delivery problem is solved, the attacker's only remaining task is making the message content convincing enough to prompt a click.
Beyond the ad spend sitting in a compromised account, attackers specifically prize accounts with real history because aged, active accounts can serve ads that pass platform safety checks more easily. This is why stolen Meta Business Manager accounts and high-risk-sector Google Ads accounts show up for sale, with pricing reflecting how established and trusted the account appears.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Aged, active accounts with real ad history can pass platform safety checks more easily, making them valuable for running scam ads. Stolen Meta Business Manager accounts have reportedly sold for about $15 to $340, and some Google Ads accounts for $200 to $270.
They send phishing through trusted platforms like Salesforce, Google Workspace mail-merge tools, and SharePoint-hosted links, since these services carry sending reputations that bypass reputation-based email filtering.
Attackers often add themselves as admins and downgrade the legitimate owner's permissions, which can make reclaiming the account and rebuilding platform standing take months.
Avoid signing in through links in account notices, go directly to Meta or Google Ads instead, limit and regularly review who has admin access, and monitor for unfamiliar admin changes.
Your Meta Business or Google Ads account can sell for up to a few hundred dollars on Telegram, phishers want it more than your password vault. The trick: a “Meta Business account needs verification” email that really comes through Salesforce, or a “Google Ads alert” blasted via Google Workspace mail-merge with a SharePoint link. You click, sign in, they steal your ad account and quietly add themselves as admin. Here’s the aha: these emails sail past filters because they ride on trusted systems, Salesforce, Google Workspace, SharePoint, so SPF and DKIM all look perfect. The only giveaway is the path: Meta support should not be sending you through a random hosted link to sign in. If you get any Meta or Google Ads account alert, ignore the link. Type business.facebook.com or ads.google.com yourself or use your bookmark, and check for issues only inside the real dashboard.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…