TL;DR: Attackers are abusing Meta Business Manager partner requests to send genuine Meta emails that pass SPF, DKIM and DMARC, while the embedded link leads to credential harvesting, according to Prophet Security. The pattern shows why phishing defence now depends on intent, destination validation and deeper URL investigation rather than sender trust alone.
NHIMG editorial — based on content published by Prophet: Facebook phishing email campaign using Meta Business Manager partner requests
Questions worth separating out
Q: How should security teams handle phishing that arrives through trusted email infrastructure?
A: Treat trusted infrastructure as a delivery path, not a guarantee of legitimacy.
Q: Why do legitimate partner-request emails create more risk than standard phishing?
A: Because the message can pass normal trust checks while still moving the victim into a high-privilege approval path.
Q: What breaks when phishing investigations stop at SPF, DKIM and DMARC?
A: They miss attacks where the sender is genuine but the destination is hostile.
Practitioner guidance
- Validate partner-request destinations before approval Block or escalate any partner invitation whose URL, domain age or hosting does not align with the claimed brand.
- Treat delegated business access as privileged access Inventory who can approve external partners, what assets those approvals touch and how far those permissions propagate across business units or clients.
- Correlate email authenticity with page content Require analysts to compare sender branding, link destination and landing-page language before clearing reports as safe.
What's in the full article
Prophet's full article covers the operational detail this post intentionally leaves for the source:
- The full investigation chain from header analysis to page-content review and cross-tool correlation.
- The specific malicious domains, subdomain patterns and reputation pivots observed during triage.
- The analyst workflow used to classify the message in under seven minutes.
- The broader campaign context across multiple customers and similar trusted-platform phishing patterns.
👉 Read Prophet's analysis of Meta Business Manager partner-request phishing →
Meta Business Manager phishing: are your controls checking intent?
Explore further