
the WORST phishing email i've ever seen
Source: YouTube · John Hammond · published Apr 24, 2026 · 21:07
Scammers are sending highly convincing Facebook phishing emails that use legitimate Meta domains but embed the attacker's business name in the account lockout warning text 0:00-0:51.
Key Takeaways:
• The phishing emails originate from actual Facebook addresses (like [email protected]) and link to legitimate business.facebook.com URLs, making them appear completely authentic 0:00-0:25.
• The scam relies on a "business manager partner request" subject line to trick users into taking immediate action 0:11-0:19.
• The clever gimmick is a threat that your account "will be locked in 24 hours" for not being "affiliated with Meta," where the unverified reason string is actually the attacker's business name 0:27-0:51.
Always carefully inspect the context of account warnings, even if the sender domain and links appear completely legitimate.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I have been getting a handful of fishing emails from Facebook. Literally, it is from Facebook, right? You can see this is no reply at facebook.com business.fas.com. It's legitimately Facebook. You can see the subject line here. Hey, you've received a business manager partner request. And this is an official email sent from Facebook, even with a button to view the request pointing to business.fas.com. But here's the clever trick here. You might have actually seen it. Your account will be locked in 24 hours. Reason is not part of or affiliated with Meta. Usual boilerplate blurb for okay like an unverified account. So you see the gimmick is that this your account will be locked in 24 hours reason that string is the business name as something that is doing this outreach and triggering this not…