Scam Watch

How can you recognize Instagram 'fan support' / verification phish hijacking creator accounts?

TLDR

Attacker DMs creators posing as Meta Verified support: 'we detected suspicious activity, click link to verify or your account will be deleted'. Phish page asks login + 2FA TOTP code (relay attack). Often hits influencers, small businesses,...

How it works

Attacker DMs creators posing as Meta Verified support: 'we detected suspicious activity, click link to verify or your account will be deleted'. Phish page asks login + 2FA TOTP code (relay attack). Often hits influencers, small businesses,...

Red flags

  • Urgent pressure to click, pay, or share codes immediately.
  • A link or sender that does not match the official organization.
  • Requests for card data, passwords, OTPs, wallet signatures, or bank transfers.

What to do

  1. 1Attacker DMs creators posing as Meta Verified support: 'we detected suspicious activity, click link to verify or your account will be deleted'.
  2. 2Tells: 1) DM comes from non verified Meta lookalike (no blue check); 2) urgency + threat of deletion; 3) link is meta verify help.com etc (typo squat); 4) site asks 2FA code immediately after login (real Instagram doesn't on familiar device).
  3. 3DO: only manage account via the official Instagram app; report DMs as phishing; enable hardware key 2FA.

Source

Meta-Adversarial-Threat-Report

Source reviewed by Mythos Forensic Team

https://about.fb.com/news/category/security/

FAQ

Is Instagram 'fan support' / verification phish hijacking creator accounts a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

Urgent pressure to click, pay, or share codes immediately.; A link or sender that does not match the official organization.; Requests for card data, passwords, OTPs, wallet signatures, or bank transfers.

What should I do first?

Attacker DMs creators posing as Meta Verified support: 'we detected suspicious activity, click link to verify or your account will be deleted'.; Tells: 1) DM comes from non verified Meta lookalike (no blue check); 2) urgency + threat of deletion; 3) link is meta verify help.com etc (typo squat); 4) site asks 2FA code immediately after login (real Instagram doesn't on familiar device).; DO: only manage account via the official Instagram app; report DMs as phishing; enable hardware key 2FA.

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.