Here’s a phish recently seen in the wild.
The email claims it is from Meta, owner of Facebook, warning about restrictions placed on the recipient’s Meta account due to recent activity seen on the account, which is seen as an “exploit” that could impact internal functions within the “Meta Business Suite”, used to manage a business’ Facebook, Instagram and WhatsApp for Business accounts. It claims that if an appeal is not filed within one day, the restrictions they have placed on the account could become permanent.
Looking at the headers of the email, it shows that the email was definitively sent from Salesforce servers.
The link in the email goes to a page on “salesforce-sites[.]com”, which redirects to a page on “metasystemschat[.]com”. The link existing on salesforce-sites[.]com tells me someone’s Salesforce account has been compromised and used to stage the phish and send the email.
The metasystemschat[.]com is a recently registered fraudulent lookalike domain, hosting what appears to be a Meta Business Support page. It asks for information about the account in question to open a chat. I entered completely bogus information and was not told I had entered invalid information.
–Matt