Scams & Phishing News Scammers pose as airline customer support to help with your complaints and then steal your credit card info

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,141
6,188
2,168
Germany
Fraudsters are taking advantage of people venting on social media
  • Check Point warns scammers spoof airline customer support on social media to steal payment data
  • Hundreds of fake accounts created daily, luring frustrated passengers into private chats or forms
  • Campaign active since 2024; mirrors earlier fake support scams seen during crypto wallet fraud
Scammers are now posing as customer support for airlines, tricking already frustrated customers into sharing payment details and possibly losing money, too.

People who have had poor experiences flying would often vent their frustration on social media, be it X, Facebook, Instagram, or any other platform. They would tag the company and demand help, or at least an explanation. However, according to new research from security experts Check Point, the airline’s social media department is not the only one monitoring these complaints - hackers do it, too.

Not only are they monitoring the channels, they are actively preparing to hop in and talk to the customers.

Years-old campaign
Every day, hundreds of new social media accounts are created - some are built to spoof the airlines themselves, others are built to look as if they’re used by the airlines’ customer support or similar department. When the customer leaves a post or a comment, the criminals swoop in, publicly apologizing for the inconvenience, and offering assistance in a different, private channel. Sometimes those are the platform’s DMs, and sometimes it is WhatsApp or a different platform entirely.

The end result differs from case to case. Sometimes, the criminals would try to get the victims to share their personal and payment information and would later try to make a wire transfer. In other instances, the crooks would prepare a fake form for the victims to fill out, possibly creating a database for later use.
Check Point doesn’t know exactly when the campaign started but found some of the impersonation accounts dating back to before 2024, with the majority being created either in 2024, or later. “This suggests that the activity has accelerated over the past two years. The campaign remains highly active, with hundreds of new accounts appearing daily and new scam techniques continuing to emerge,” they said.

However, we can confirm that this type of fraud has been around for a lot longer than that. Fake customer support scams were rampant on X even in 2021, during the crypto ICO craze, during which crooks were taking advantage of people losing access to their wallets, or making transactions towards nonexistent wallet addresses in the same way.
 


Hi, this is a particularly effective impersonation scam because the victim has already announced both the problem and the company whose help they expect. The safest rule is simple: treat every unsolicited “support” reply as unverified and resume the conversation through the airline’s official website or app.

How the trap works​

The public complaint gives scammers enough context to sound convincing: the airline, the disruption and sometimes a booking route or flight number. They then move the passenger into direct messages, WhatsApp or a lookalike form, where other users cannot flag the exchange.

A polished profile, logo, reassuring language or even knowledge of the complaint does not authenticate the account. Nor does a blue check automatically prove that a particular agent or payment request is legitimate. The decisive check is whether the contact route is listed in the airline’s official app or on the website address you entered yourself.

The quoted article attributes claims about hundreds of accounts and the campaign’s timeline to Check Point, but no primary evidence is included here to verify those changing figures. That does not alter the practical warning; the impersonation method itself is well established.

What passengers should do​

  1. Do not post booking references, boarding passes, phone numbers or email addresses publicly. Boarding-pass images can expose more data than expected.
  2. Do not use links or phone numbers supplied by an account that approached you. Open the airline app or type its known website address yourself, then find support there.
  3. Verify the reply independently. Compare the exact username with the account linked from the airline’s official site; lookalikes often substitute characters or add words such as “helpdesk.”
  4. Reject unusual payment methods. Gift cards, cryptocurrency, bank transfers, remote-access apps and requests for one-time security codes are strong fraud indicators. A genuine refund should not require handing over an MFA code or installing screen-sharing software.
  5. Report and block the impersonator. Preserve screenshots, the profile address, messages and transaction details first if money or information was exchanged.

If information was already shared​

The response depends on what crossed the line:

  • Only opened the profile or message: usually no remedial action beyond blocking and reporting, unless a file was opened, an app installed or credentials entered.
  • Entered card details: contact the card issuer through the number on the card or its official app, freeze or replace the card as advised, dispute unauthorized charges and monitor transactions.
  • Sent a bank transfer: contact the bank’s fraud team immediately and ask whether the transfer can be recalled. Speed matters.
  • Entered an airline or email password: From a trusted device, change it through the official service, revoke other sessions and unrecognized connected access, enable MFA, check recovery details and email forwarding rules, and replace that password anywhere it was reused.
  • Shared an MFA code or approved a login notification: treat the account as potentially accessed; changing the password alone may not terminate an existing session.
  • Installed remote-access software or ran a command at the scammer’s direction: disconnect that device from the network, protect affected accounts from a separate trusted device, and seek individualized cleanup through MalwareTips’ Malware Removal Assistance team—even if an antivirus scan reports nothing.