Security1 publisher2 min readPublished
Fake Facebook Marketplace listings name the target as seller to bait a reply
Scammers text people a fake Facebook Marketplace listing naming them as seller to provoke a 'that isn't me' reply, Malwarebytes reports. Any answer tells a sender who likely already has the name and number that the line is live.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The lure arrives over iMessage with a fabricated listing attached and one line of text: "Is this still available for purchase?"
- The name-and-number pairs could come from any of many data breaches, according to Malwarebytes, and such data is bought and sold on the dark web.
- Malwarebytes argues that an AI agent working through a breached list makes the tailored lure relatively easy to send at scale.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Leaked data sets the target list: anyone whose name and phone number sit together in a breach can get a lure that names them.
- cost One reply raises the number's value to scammers; Malwarebytes says it can then be resold or used for malware, relationship fraud or Facebook account takeover.
- constraint Defenders cannot yet say what payload follows a reply, because Malwarebytes says the motive is hard to establish without engaging the sender.
Malwarebytes calls the matching seller name a conversation lure. It makes the message look legitimate and gives the recipient a second reason to answer [3]. The post says the screenshot plays on curiosity, reputational concern and the urge to correct an apparent mistake [9]. Many recipients, it expects, will decide a scammer is impersonating them on Marketplace and write back "That isn't me" [10].
The photo tells more. A seller picture borrowed from a stranger with the same name [4] fits an attacker who started with a name and a number, searched Facebook for the name and took whichever profile photo came up [15]. Malwarebytes states the narrower version: the attacker likely had a phone number associated with a name [5]. On that reading, the recipient's own Facebook profile was never an input. Malwarebytes' general advice to limit what you share publicly on social media [14] does little against this particular lure [15].
The evidence is thin. It consists of user reports and the one sample Malwarebytes examined [1][4]. The post does not give message volumes or tie the texts to a named operator or campaign. Its point about AI-driven scale is an assessment of what is feasible [16].
Malwarebytes' first defence is not to answer [11]. It advises against replying to unsolicited messages from unknown senders. It also advises against clicking links, calling numbers supplied in the conversation, scanning QR codes or sharing one-time codes [11]. A recipient worried about real impersonation can check without engaging. Open Facebook directly, review Marketplace activity, recent logins and recovery settings, and use facebook.com/hacked if anything looks wrong [12]. A genuine impersonating profile can be reported through Facebook's own process, and Facebook says such profiles violate its standards [13].
What to watch
- Reports of what senders do after a 'that isn't me' reply, which would settle the motive Malwarebytes could not establish.
- Any attribution of the texts to a specific operator or breach dataset, which would turn a circulating technique into a tracked campaign.
- Samples where the fake seller photo matches the recipient's own profile, which would mean attackers are pulling from the target's account as well as breach lists.