Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller.
It works like this. You receive a message (in this case iMessage) asking “Is this still available for purchase?” Attached to the message is a fabricated Facebook Marketplace listing.

Tapping on the picture, you might notice that the seller’s name is the same as your name. This is known as a conversation lure, adding legitimacy to a message and giving you an additional reason to reply.

Interestingly in the example we received, even though the name of the seller matched the person who received the message, the profile picture did not. When I researched the profile picture, it turned out that it belongs to another Facebook user with the exact same name.
This likely means the attacker had a phone number associated with a name that they used to create the fake Marketplace listing. Receiving a message like that is very likely to provoke the natural corrective response: “That isn’t me.” Such a message will probably have a lot of receivers think that they are being impersonated by a scammer on Marketplace.
This method of approach may seem like a lot of work with a low chance of success, and this would have been true a few years ago. But with an AI agent and a list of matching names and phone numbers from a breach, this can be done relatively easy at scale. And that changes the return on time invested dramatically.
The name and phone number combination could come from any number of data breaches. On the dark web, cybercriminals buy and sell personal data for such purposes.
“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”
The personalized screenshot would work very well as a reply trigger. Its psychological function is well thought out and likely very effective: it combines curiosity, reputational concern, and the recipient’s impulse to correct an apparent mistake.
But when you reply to a phishing text you are telling a scammer that this is a live number. Your phone number then increases in value for the scammer and can be resold to other scammers. Or it can be used in other cybercrimes, to download malware, to begin a relationship that leads to fraud, to take over your Facebook account, or many other reasons.
How to stay safe
While the exact motive behind this text is hard to establish without engaging, there are a few things you can do:
- Limit what you share publicly on social media. Scammers can use information about you to increase the credibility of their attempts.
- Do not respond to unsolicited messages of any kind when they come from people you don’t know.
- If you do know the sender, but don’t trust the message, double check with them via a different channel that it was them who sent it.
- Don’t click a link, call a number supplied in the conversation, scan a QR code, or share a one-time code or screenshot of a security message.
- Open Facebook independently and inspect Marketplace activity, recent logins, messages, email addresses, phone numbers, and recovery settings. Use facebook.com/hacked if you find any signs of compromise.
- If you find a profile truly impersonating you, preserve its URL and report the profile. Facebook says impersonating profiles violate its standards and provides an impersonation-reporting process.
- If you’re unsure whether a message is a scam, use Malwarebytes Scam Guard. It will assist you in determining if it’s real or fake, and advise you on follow-up steps.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Article Link: https://www.malwarebytes.com/blog/threat-intel/2026/10/facebook-marketplace-phish-uses-your-name-and-number