Skip to content

Security1 publisher2 min readPublished

Fake Facebook Marketplace listings name the target as seller to bait a reply

Scammers text people a fake Facebook Marketplace listing naming them as seller to provoke a 'that isn't me' reply, Malwarebytes reports. Any answer tells a sender who likely already has the name and number that the line is live.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Fake Facebook Marketplace listings name the target as seller to bait a reply
Generated illustration

What happened

  • The lure arrives over iMessage with a fabricated listing attached and one line of text: "Is this still available for purchase?"
  • The name-and-number pairs could come from any of many data breaches, according to Malwarebytes, and such data is bought and sold on the dark web.
  • Malwarebytes argues that an AI agent working through a breached list makes the tailored lure relatively easy to send at scale.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Leaked data sets the target list: anyone whose name and phone number sit together in a breach can get a lure that names them.
  • cost One reply raises the number's value to scammers; Malwarebytes says it can then be resold or used for malware, relationship fraud or Facebook account takeover.
  • constraint Defenders cannot yet say what payload follows a reply, because Malwarebytes says the motive is hard to establish without engaging the sender.

Malwarebytes calls the matching seller name a conversation lure. It makes the message look legitimate and gives the recipient a second reason to answer [3]. The post says the screenshot plays on curiosity, reputational concern and the urge to correct an apparent mistake [9]. Many recipients, it expects, will decide a scammer is impersonating them on Marketplace and write back "That isn't me" [10].

The photo tells more. A seller picture borrowed from a stranger with the same name [4] fits an attacker who started with a name and a number, searched Facebook for the name and took whichever profile photo came up [15]. Malwarebytes states the narrower version: the attacker likely had a phone number associated with a name [5]. On that reading, the recipient's own Facebook profile was never an input. Malwarebytes' general advice to limit what you share publicly on social media [14] does little against this particular lure [15].

The evidence is thin. It consists of user reports and the one sample Malwarebytes examined [1][4]. The post does not give message volumes or tie the texts to a named operator or campaign. Its point about AI-driven scale is an assessment of what is feasible [16].

Malwarebytes' first defence is not to answer [11]. It advises against replying to unsolicited messages from unknown senders. It also advises against clicking links, calling numbers supplied in the conversation, scanning QR codes or sharing one-time codes [11]. A recipient worried about real impersonation can check without engaging. Open Facebook directly, review Marketplace activity, recent logins and recovery settings, and use facebook.com/hacked if anything looks wrong [12]. A genuine impersonating profile can be reported through Facebook's own process, and Facebook says such profiles violate its standards [13].

What to watch

  • Reports of what senders do after a 'that isn't me' reply, which would settle the motive Malwarebytes could not establish.
  • Any attribution of the texts to a specific operator or breach dataset, which would turn a circulating technique into a tracked campaign.
  • Samples where the fake seller photo matches the recipient's own profile, which would mean attackers are pulling from the target's account as well as breach lists.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories