Skip to content

Security1 publisher2 min readPublished

Fake support accounts are answering airline complaints under the brand's verified posts

Check Point followed the chain from a reply under a verified airline post to a WhatsApp thread to a half-finished $500 transfer, and counted thousands of impersonation accounts with hundreds more appearing daily.

The Watch · Security desk

Photograph accompanying Fake support accounts are answering airline complaints under the brand's verified posts
Photo: bbc.com

What happened

  • Check Point's Exposure Management team documented a coordinated campaign in which scammers monitor public customer complaints, pose as support staff and approach the complainants directly.
  • The fake accounts reply to dissatisfied customers underneath verified brand posts, copying the phrasing legitimate customer service teams use, then ask to continue privately.
  • Researchers identified thousands of impersonation accounts on X, Facebook and Instagram posing as airlines, vacation brands, support teams and named representatives.
  • Engaging the accounts directly, researchers traced three variants of the fraud from the first reply through WhatsApp to payment and card-data collection.
  • Most of the accounts were created in 2024 or later, some predate 2024, and hundreds of new ones are being registered every day.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Scammers find their targets in the complaint threads under a brand's verified posts. Each thread is a queue of pre-qualified targets who have already published their grievance and are waiting for a support reply.
  • constraint Remediation runs through platform abuse desks, and at hundreds of registrations a day an account-by-account takedown list cannot hold the line for more than a couple of weeks.
  • decision Someone has to own brand mention monitoring. Check Point puts it under external attack surface management, which moves it off the marketing team's dashboard and onto a security budget.
  • contradiction The report's AI section describes what generative models could do for an operation like this while stating that no AI use was confirmed in the accounts examined, so the automation angle is a projection.

The profile is the only thing a customer can inspect before the thread leaves the platform. Some of the accounts Check Point examined used official brand logos, cover images and descriptions; others used names built around customer support, claims departments and help desks [5]. Once the customer replies, the account asks for a phone number and booking details, then moves the conversation to WhatsApp [6].

Researchers got the clearest look at the money stage. In one variation they supplied a full name, email address, booking details, complaint information and the cost of the trip, and were told the claim had been approved [8]. The investigation later turned up an unfinished $500 transfer tied to that information, and completing it required credit card details and further personal data [9]. A second variation promised $1,200 in compensation and pushed the researchers toward an international payment application [10]. A third sent them to a Google Form titled "COMPENSATION/REFUND APPLICATION" [11].

Check Point identified thousands of impersonation accounts across X, Facebook and Instagram [4] and says hundreds of new ones appear every day [12]. Scale decides how a defender responds. Read "hundreds" at its low end, 200 a day, and a sweep that removed 3,000 accounts would be back to 3,000 in about 15 days [18].

The account is single-sourced and comes from Check Point's own exposure management practice, which frames the finding as a growing external attack surface management problem because the exposure develops on public channels where brands talk to customers [17]. The report does not identify a named threat actor group or give a total for victim losses [19]. Some accounts predate 2024 and most were created in 2024 or later, but researchers could not confirm when the campaign began [13].

On the automation question the report is careful in a way the headline version of this story usually is not. Check Point wrote that researchers did not confirm AI use in the accounts they investigated [15]. The AI section describes what AI could do here: drafting customer-service-style messages, tailoring replies to a specific complaint, working in several languages, and keeping a support persona going across many conversations at once [16]. Check Point also says the three techniques it documented are probably a sample of what is in use [14].

What to watch

  • Platform-side numbers from X, Meta or WhatsApp on how many of these impersonation accounts get removed and how quickly they return.
  • An airline, a bank or a regulator publishing an actual victim loss total for support-account impersonation.
  • Researchers documenting the same complaint-thread-to-WhatsApp chain against non-travel brands such as telcos or retailers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories