www.malwarebytes.com 6 Oct 2026, 12:11 UTC

Facebook Marketplace Scam Uses Your Name to Make Fake Listings Convincing

Facebook Marketplace Scam Uses Your Name to Make Fake Listings Convincing
CyberSIXT Evidence Panel Source marked as original reporting

FACEBOOK users are being targeted by a new Marketplace scam that personalises a fake listing with the recipient’s name. The attacker sends a message (for example via iMessage) asking if an item is still available and attaches a counterfeit Facebook Marketplace listing. The trick is that the listing shows the recipient’s own name as the seller, which can make the message seem legitimate, even though the profile picture in the listing belongs to a different person with the same name.

The scheme appears to rely on data harvested from breaches: the attacker uses a name and a phone number to construct the fake listing, then may enrich it with an image sourced from another person who shares the same name. Malwarebytes notes that this kind of personalised lure is more effective when amplified by AI agents and a pool of breached data, enabling scalable, convincing impersonation.

Responding to the message (for instance, asking the sender to confirm via a different channel) can reveal the number is active and may raise the number’s value on the dark web or be leveraged for further crimes, such as malware delivery, account takeover, or other fraud.

Practical steps to stay safe include limiting public sharing of personal details, avoiding replies to unsolicited messages, verifying sender identity through separate channels, and independently checking Facebook activity or compromised accounts via Facebook’s hacked resources. If impersonation is suspected, preserve the profile URL and report it. Malwarebytes also points to its Scam Guard tool for assistance in distinguishing real from fake messages.

View full article

Article by CyberSIXT