Social Media Phishing and Impersonation Scams¶
Cybercriminals frequently target social media users through sophisticated phishing direct messages (DMs), fake copyright violation warnings, fake blue-badge verification offers, and compromised friend accounts. Recognizing common attack patterns prevents credentials and financial assets from being stolen.
Common Social Media Phishing Schemes¶
The Copyright Infringement Scam¶
- The Tactic: You receive an urgent DM or email claiming your account will be deleted within 24 hours for copyright infringement, directing you to click a link to appeal.
- The Reality: Platforms never issue copyright notices via DMs. Official notices appear exclusively in account security settings or system notifications.
Fake Brand Sponsorship and Influencer Deals¶
- The Tactic: Fraudsters contact creators offering lucrative brand sponsorships, requesting that you download a PDF media kit file or install software.
- The Reality: The downloadable file contains malware or session-stealing infostealers designed to hijack browser cookies and bypass 2FA.
The Compromised Friend Emergency DM¶
- The Tactic: A friend profile messages you saying: "Can you help me get back into my account? I need to send a code to your phone."
- The Reality: The friend account has been hacked. The code sent to your phone is actually your own 2FA password reset token, allowing the hacker to breach your account.
Immediate Steps If You Clicked a Phishing Link¶
- Change Account Passwords Immediately: Update your social media account password and primary email password from a secure device.
- Terminate Active Sessions: Log out of all active web browser sessions and mobile devices using the Security menu.
- Scan for Malware: Run a comprehensive anti-malware scan if you downloaded any file or opened suspicious attachments.
- Revoke OAuth App Approvals: Access account security settings and revoke access for any unfamiliar third-party applications.