A Reader wrote to us:

I would like to warn you about a new method scammers are using on Facebook: they break into a user’s account and then change its name so that it looks like Facebook support.

They added:

Then they send messages with a link, clicking which results in data leakage.

Zrzut ekranuZrzut ekranu • Photo author: Czytelnik

Why is this definitely not a genuine message from Meta/Facebook?

The most important red flags visible in the screenshot:

  1. Meta/Facebook does NOT send PDFs for “account verification” via Messenger
    Official notifications about violations are sent:
    • in the Help Center / Support Inbox on Facebook
    • or by email from the @facebookmail.com
      Never as a PDF attachment in a chat.
  2. Threat of a 12-hour block
    This is a classic phishing technique: creating time pressure so the user acts without thinking.
  3. Factual errors
    • “cookies in posts and photos” – this makes no technical sense
    • “MetaProtect received a report” – there is no such official mechanism in this context
  4. Fake name and style
    • “Meta Mess” instead of “Meta” / “Facebook”
    • Message style inconsistent with Meta’s official language
    • Excessive use of emojis and warning icons
  5. PDF attachment
    • These types of PDFs usually contain:
      • a link to a fake login page
      • or malicious macros / scripts
    • File name → classic phishing.