March 19, 2019 By David Bisson 2 min read

Security researchers discovered that attackers are using fake copyright infringement notifications to hack Instagram influencer accounts.

Detected by Kaspersky Lab, the Instagram hacking campaign involves threat actors sending Instagram influencers fraudulent emails claiming that the social media network intends to permanently delete their account for copyright infringement. The attack email uses the social networking service’s official header and logo to deceive victims. It even originates from an email address — [email protected] or [email protected] — that looks similar to Instagram’s actual support email, [email protected].

Using these disguises, the email notifies targeted users that they have 24 hours to verify their account before it is deleted. Clicking on the email’s “Review complaint” button redirects users to a phishing page where they can supposedly appeal the decision to delete their profile.

At that point, users can proceed by clicking an “Appeal” link and submitting their Instagram credentials to the attackers. The scam then asks users to verify their email address by choosing their email provider and entering the login credentials for their account.

Just the Latest Instagram Hacking Attack

This is just the latest scam to target Instagram users. Back in August 2018, for instance, Mashable reported on a string of hacks in which threat actors took over users’ accounts and added a .ru email address to their profiles. News of another attack wave came a month later when Motherboard reported that attackers had hijacked at least four high-profile Instagrammers’ accounts and extorted them for money.

Most recently, Trend Micro detected yet another scam operation in February 2019 in which fraudsters targeted Instagram users with the false promise of a “verified” badge for their accounts.

How to Defend Against Phishing Attacks

Security professionals can help defend their organizations against phishing attacks by using ahead-of-threat detection to block potential phishing domains, even those that threat actors have cloned to look like legitimate websites.

Security teams should also test their phishing defenses by conducting a simulated phishing engagement. Organizations can then use this exercise to identify employees who need more training on social engineering attacks as well as to conduct follow-up testing for the entire workforce.

More from

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

AI cybersecurity solutions detect ransomware in under 60 seconds

2 min read - Worried about ransomware? If so, it’s not surprising. According to the World Economic Forum, for large cyber losses (€1 million+), the number of cases in which data is exfiltrated is increasing, doubling from 40% in 2019 to almost 80% in 2022. And more recent activity is tracking even higher.Meanwhile, other dangers are appearing on the horizon. For example, the 2024 IBM X-Force Threat Intelligence Index states that threat group investment is increasingly focused on generative AI attack tools.Criminals have been…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today