A Reader wrote to us:
I would like to warn you about a new method scammers are using on Facebook: they break into a user’s account and then change its name so that it looks like Facebook support.
They added:
Then they send messages with a link, clicking which results in data leakage.
Why is this definitely not a genuine message from Meta/Facebook?
The most important red flags visible in the screenshot:
- Meta/Facebook does NOT send PDFs for “account verification” via Messenger
Official notifications about violations are sent:- in the Help Center / Support Inbox on Facebook
- or by email from the
@facebookmail.com
Never as a PDF attachment in a chat.
- Threat of a 12-hour block
This is a classic phishing technique: creating time pressure so the user acts without thinking. - Factual errors
- “cookies in posts and photos” – this makes no technical sense
- “MetaProtect received a report” – there is no such official mechanism in this context
- Fake name and style
- “Meta Mess” instead of “Meta” / “Facebook”
- Message style inconsistent with Meta’s official language
- Excessive use of emojis and warning icons
- PDF attachment
- These types of PDFs usually contain:
- a link to a fake login page
- or malicious macros / scripts
- File name → classic phishing.
- These types of PDFs usually contain:
