There is a new Meta phishing email making the rounds that is easy to dismiss at first glance, until you look a little closer at how it works. The message may arrive with the familiar Meta or Facebook branding, a subject such as “You’ve received a Business Manager partner request,” and links that appear to take you into Meta Business Manager. For someone who manages a Facebook Page, runs advertisements for clients, or works inside Meta Business Suite every day, receiving a message like this does not immediately look unusual.
That is exactly what makes this particular scam so clever. In some versions reported during 2026, the email itself is not a fake email in the traditional sense. Criminals are abusing Meta’s legitimate Business Manager systems to generate authentic partner-request notifications, meaning the message can come through Meta’s own infrastructure and pass normal email authentication checks. The problem is the person or business behind the partner request, and the malicious information they manage to place inside that legitimate notification.
So if you have received a Meta Business Manager phishing email, a Facebook partner request scam, or an email claiming that your business account will be restricted unless you verify something immediately, don’t assume that a genuine-looking sender automatically means the request is safe. There is a very important difference between an email genuinely sent by Meta and a legitimate Meta notification being manipulated by someone who wants to trick you.
What Is the Meta Business Phishing Email?
The current scam revolves around the Business Manager partner request feature. This feature itself is legitimate. Businesses can use Meta’s business tools to work with agencies, advertisers, contractors and other companies by giving them access to particular business assets. That makes receiving a partner request perfectly normal for someone who runs a business on Facebook or Instagram.
The scammers take advantage of that normal process. They create their own Meta business account and give it a name designed to frighten or confuse the recipient. Instead of simply appearing as an unfamiliar company, the business name may contain language suggesting that the recipient’s account has been approved, restricted, threatened with closure, or needs to be verified within a short period. Reports published in 2026 describe attackers putting the phishing lure directly into the name or information associated with the fraudulent business account. Meta then sends the resulting partner-request notification through its own system.
This is the part that catches people off guard. Traditional phishing advice often tells people to look for a suspicious sender address or a fake website pretending to be Facebook. Those checks are still useful, but they are not enough against this campaign. Security researchers have documented examples where the notification genuinely came through Facebook’s infrastructure, with authentication such as SPF, DKIM and DMARC passing successfully. In other words, asking “Did this email really come from Facebook?” can produce the wrong conclusion. The email may really have come from Facebook while the partner request itself is malicious.
How the Meta Business Manager Partner Request Scam Works
The scam begins with the attacker creating or controlling a business account within Meta. Rather than sending a conventional phishing email from a newly registered domain, the attacker uses Meta’s own Business Manager functionality to send a partner request to a target business.
The request may be dressed up to look like something connected to Meta’s agency or partner programs. The name can include urgent wording such as an account-lock warning, verification demand or another reason for the recipient to act quickly. In some reported examples, the requester’s name or description contains a Messenger link or an external website that has nothing to do with Meta. Other versions have used hosted pages such as Google Sites as the next step in the phishing process.
Once the recipient follows the lure, the goal is generally to move them away from the safety of Meta’s genuine interface and toward a page controlled by the attacker. That page may imitate Facebook or Meta Business and ask for an email address, password, business account information or a two-factor authentication code. Meta itself warns that fake support scams can use convincing messages to push people toward phishing websites and ask for login credentials or two-factor authentication information. Once those details are handed over, criminals can potentially take control of the account and use it for further fraud, unauthorized advertising or access to business assets.
For somebody who depends on Facebook advertising for their income, this is considerably more serious than losing access to an ordinary social media profile. A compromised business account can be connected to Pages, advertising accounts, pixels, payment arrangements and other assets. That is why a fake Meta Business Manager request deserves more attention than a random spam email that can simply be deleted.
Why This Meta Phishing Email Looks So Real
This is where the scam becomes genuinely interesting. Most people have been trained to inspect the sender address first, and that is still sensible advice. The problem is that this particular attack can get around the most obvious test.
Security researchers examining the campaign found cases in which the notification came from a genuine Facebook address and used real Meta links. One investigation described partner-request emails that passed SPF, DKIM and DMARC and were delivered through Facebook’s actual mail infrastructure. Another analysis found that attackers were effectively using Meta as the delivery mechanism: they created the malicious business, initiated the request, and allowed Meta to generate the notification.
That means the familiar Facebook logo, authentic formatting and legitimate-looking footer are not enough to establish that the request is trustworthy. Even a genuine business.facebook.com link does not mean that every piece of information surrounding the request is legitimate. A genuine link can simply lead you into Meta’s real Business Manager interface where an attacker-controlled partner request is waiting.
This is also why screenshots of these emails can be misleading. Someone can look at an image and say, “The sender is Facebook, so it must be real,” when the more important question is, “Do I know and trust the business that is asking to become my partner?”
Is the Meta Business Partner Request a Scam?
The Business Manager partner request feature is not a scam. It is a legitimate Meta business function used by companies and agencies to collaborate. The problem is that scammers are abusing the feature to make phishing attempts appear more credible.
So if you receive a message saying that you have received a Business Manager partner request, don’t automatically assume that every such notification is fraudulent either. You need to look at whether the request was expected and who actually initiated it.
If your advertising agency told you yesterday that they were going to request access to your business, for example, a partner request from that agency makes sense. If you have never heard of the company, never contacted an agency, and suddenly receive an urgent request claiming that your account needs to be verified within 24 hours, there is no good reason to accept it simply because the notification arrived through Meta.
Meta specifically advises users to be cautious with unexpected requests and says people should verify suspicious emails rather than clicking links or attachments. Its scam-prevention guidance also recommends enabling alerts for unrecognized logins and using two-factor authentication.
The “Your Account Will Be Locked” Part Is Designed to Make You Panic
The wording used in these scams matters because it is intended to interfere with your judgment. A message that simply says an unknown business would like to connect with your company is easy to ignore. Add a statement suggesting that your Facebook Page, advertising account or business portfolio could be disabled within 24 hours, and suddenly the same request feels urgent.
That is a familiar phishing technique, but it works especially well with business owners because their Facebook and Instagram accounts can be financially important. If you depend on Meta ads for customers, the thought of losing your advertising account can be enough to make you click before you stop and investigate.
The safer approach is to separate the claim from the actual account status. An email saying that your account is about to be suspended is only making a claim. It is not proof that Meta has actually restricted your account. Instead of following the instructions in the email, open Meta Business Suite or the relevant Meta business area directly and check whether there is a genuine restriction, request or notification waiting for you.
That small change in habit makes these emails much less effective because the scammer no longer controls the path you take to verify the problem.
What About the “View Request” Button?
The “View Request” or similar button deserves some attention because it can make the email feel especially convincing. In some documented campaigns, the initial link really does take the recipient to a legitimate Meta page. That is one of the reasons it is dangerous to judge the entire message simply by hovering over one Facebook link and seeing facebook.com.
The malicious content may instead be contained in the partner information, requester name, Messenger contact or subsequent external link. Researchers have documented versions where the attacker uses a genuine Meta partner-request email to introduce a malicious external destination later in the interaction.
For that reason, my preference would be not to interact with an unexpected partner request from the email at all. If the request might be legitimate, open your browser separately, go to Meta’s business tools yourself and look for the request there. You can then inspect the requesting business without giving the email a chance to dictate where you go next.
How to Check a Suspicious Meta Business Email
The safest way to investigate a questionable Meta Business phishing email is to stop treating the email as your source of truth. Don’t use the email’s urgency to decide what happens next. Instead, sign in to Meta through the normal website or app you already use and check your Business Manager or Business Suite notifications directly.
Pay particular attention to the identity of the requesting business. Do you recognize it? Have you spoken with anyone from that company? Were you expecting a partner request? Does the business have a legitimate reason to need access to your Page, advertising account or other assets? If the answer to those questions is no, there is little reason to accept the request.
It is also worth remembering that a legitimate Meta email address does not make an unexpected business request safe. Meta’s own safety guidance tells users to verify suspicious communications and avoid clicking links or attachments in questionable messages.
And if the email takes you to a site asking for your Facebook password or two-factor authentication code, stop there. You should never provide those details simply because a page uses Meta’s logo or tells you that your account is about to be disabled.
What Domains Does Meta Use for Legitimate Emails?
Meta does send legitimate communications, and its official guidance provides information about recognizing correspondence from Meta. Commonly associated domains include fb.com, facebook.com, facebookmail.com, instagram.com, meta.com and metamail.com.
But this particular scam is a good example of why domain checking should be treated as one part of the verification process rather than the final answer. Researchers have found authentic Meta-generated emails being used to deliver malicious partner requests.
In practical terms, that means you can receive an email from a real Meta address and still be looking at a scam attempt. The legitimate part is the notification system. The fraudulent part is what the attacker is trying to get you to do with the request.
What If You Already Clicked the Meta Phishing Link?
If you clicked a suspicious link but did not enter your password or other information, don’t panic. Close the suspicious page and avoid interacting with it further. Then access your Meta account independently and review recent login activity, business permissions, partner access and other security settings.
If you entered your password into a page you now believe was fake, change the password immediately through the official Meta interface. If that password is reused elsewhere, change it on those accounts as well. You should also review two-factor authentication and account recovery settings and look for unfamiliar business users, partners, administrators or other changes.
The situation becomes more urgent if you entered a two-factor authentication code. A one-time code should not be treated as harmless information; it can be exactly what an attacker needs to complete an account takeover attempt. Meta’s own scam-prevention material specifically warns that phishing attacks can request both passwords and two-factor authentication codes before taking control of accounts.
If you manage a business account for a company or client, I would also check the connected Pages, advertising accounts and business permissions rather than assuming that changing the password has solved everything.
How to Report a Meta Phishing Email
Suspicious Meta-related phishing attempts can be reported through Meta’s reporting and security channels. Do not reply to the scammer or continue communicating with a suspicious requester simply because you want to find out what they are trying to do.
Meta also recommends reporting scams and suspicious activity through its platform resources. If the message is part of a broader attack against your business account, keeping a copy of the email and documenting what happened can also be useful when securing the account or communicating with Meta support.
This Meta Business Email Scam Is More Sophisticated Than It Looks
The biggest takeaway from the current Meta Business phishing email scam is that “the email came from Facebook” is no longer a strong enough answer to the question of whether the request is safe. In this campaign, attackers are abusing a legitimate Meta Business Manager feature to make their phishing attempts look authentic, and researchers have documented cases where the resulting notifications genuinely came through Meta’s own systems.
That does not mean every Business Manager partner request is fraudulent, and it does not mean Meta’s email system has somehow become useless. It means you have to look at the requester and the action being requested, not just the branding and sender address.
For me, the simplest rule is this: if you were not expecting a Meta Business Manager partner request, don’t accept it just because the email looks official. Open Meta Business Suite yourself, check the request there, and verify the business independently before giving anyone access to your business assets. And if the message starts threatening account deletion, suspension or a short verification deadline, that is even more reason to slow down rather than click.
The criminals behind this campaign have figured out something that makes phishing considerably harder to spot: sometimes they don’t need to fake Meta at all. They can use Meta’s legitimate systems to make the first message for them. That is why the safest response to an unexpected Meta Business email is not to ask whether the logo looks right or whether the email feels authentic. Ask whether you were actually expecting the request in the first place.
Checkout The Back Taxes Scam Call, I talked about earlier.