- Aug 15, 2024
- 596
- 254
A couple of days ago, I launched a Facebook ad campaign just as a test — and the very next day, I started getting phishing emails.
Let me show you a few examples.
The first email came from a sketchy domain, claiming my ad violated some policy. The link pointed to a fake site hosted on a verсel_app subdomain. My browser wouldn’t even open it — probably blocked for being dangerous.
The second email was even worse — it came from a plain Gmail address, and also led to another verсel_app phishing page.
But the most interesting one came today. It looked like it was from a real law firm, claiming I had violated copyright by using music in my ad (which I didn’t — there’s no music in it). The email also came from Gmail, but the phishing page was a bit more advanced.
It started with a fake Meta CAPTCHA screen, and then loaded what looked like a real Facebook login window — all done with JavaScript, trying to steal my credentials.
Be careful out there. These guys are quick.
Let me show you a few examples.
The first email came from a sketchy domain, claiming my ad violated some policy. The link pointed to a fake site hosted on a verсel_app subdomain. My browser wouldn’t even open it — probably blocked for being dangerous.
The second email was even worse — it came from a plain Gmail address, and also led to another verсel_app phishing page.
But the most interesting one came today. It looked like it was from a real law firm, claiming I had violated copyright by using music in my ad (which I didn’t — there’s no music in it). The email also came from Gmail, but the phishing page was a bit more advanced.
It started with a fake Meta CAPTCHA screen, and then loaded what looked like a real Facebook login window — all done with JavaScript, trying to steal my credentials.
Be careful out there. These guys are quick.







