Security researchers at Malwarebytes have identified a phishing tactic in which scammers send people fabricated Facebook Marketplace listings that display their own names as sellers, hoping to provoke a response.
In a report published on October 6, Malwarebytes described messages sent through Apple’s iMessage service asking whether an item was still available for purchase. The messages included an image resembling a Marketplace listing, with the recipient’s name shown as the seller.
The approach is designed to create confusion rather than immediately request money or login credentials. Someone who has never listed the item might respond to correct the apparent mistake or investigate whether their identity is being misused.
Personal Information Makes the Scam More Convincing
In the example examined by Malwarebytes, the seller’s name matched the recipient’s, but the profile picture belonged to another Facebook user with the same name.
The researchers believe the sender may have used a list containing names and associated phone numbers to generate the personalized messages. Such information can be obtained from data breaches, although Malwarebytes did not establish where the details used in this case originated. AI tools can make it easier to produce large numbers of personalized messages, but there is no confirmation AI was involved in the observed attempt.
It wasn’t confirmed whether the messages were intended to steal Facebook accounts, distribute malicious links or support a longer-running fraud attempt. However, simply responding can confirm that a phone number is active, making it more useful for subsequent scams. A reply may also give the sender an opportunity to continue the conversation and attempt further manipulation.
What Facebook Users Should Do
Malwarebytes recommends ignoring unexpected Marketplace inquiries from unknown numbers, particularly when they refer to items the recipient has never advertised.
Anyone concerned that their Facebook account is being misused should open Facebook directly rather than following links supplied in the message. They can then check their Marketplace activity, recent account logins and security settings. If an impersonating profile exists, users can report it through Facebook’s reporting tools.
Receiving one of these messages doesn’t itself indicate that a Facebook account has been compromised. The fabricated listing could have been created using personal information obtained elsewhere.

Leave a Reply