Angler Phishing
A social-media phishing technique where attackers run fake customer support accounts that intercept public complaints and reply with a malicious link or a request for account details before the real brand responds.
Definition
Angler phishing is a social-media-based phishing technique in which an attacker creates a fake customer support account impersonating a well-known bank, airline, telco, or retailer, monitors the platform for public complaints or mentions of that brand, and replies to frustrated customers with a helpful-looking message containing a malicious link or a request for account details, exploiting the trust and urgency of someone already looking for support.
The attacker sets up a social media handle that closely mimics a real brand's official support account, often differing by only a character or an underscore, and monitors the platform for public posts, mentions, or complaint hashtags naming that brand. When a customer posts a public complaint, the fake account often races to reply before or alongside the real support team, inviting the customer to move the conversation to a direct message, a WhatsApp number, or an external link where the actual scam takes place, typically a request to verify account details, a password, or a one-time code to 'process a refund' or 'resolve the issue faster.'
This technique works because the victim is already primed to trust and engage, they are actively seeking help, often frustrated, and less likely to scrutinize a reply that appears responsive and sympathetic. The real brand's typical response time on social media creates the exact window the fake account exploits, and because verification on most social platforms is inconsistent, a lookalike handle with a plausible name and profile picture is often enough to pass a quick glance. In Indonesia, banks, e-wallets, and telco providers are heavily used for customer service on platforms such as X and Instagram, making them frequent targets for this specific technique.
Brands can reduce their exposure by clearly registering and promoting their verified official handles, responding to public complaints quickly to close the window attackers rely on, and actively monitoring for and reporting lookalike accounts to the platform. Customers and employees handling social media complaints on a brand's behalf should be trained to verify that any support account matches the brand's officially listed handle before engaging, and to treat any request for a password, OTP, or full account number through a social platform as an immediate red flag regardless of how legitimate the conversation appears.
At a glance
- Severity
- Medium
- Prevalence
- Common and growing on platforms with public complaint threads
- Primary targets
- Customers of banks, airlines, telcos, and e-commerce who publicly complain on social media
How it works
- 1
Fake account setup: the attacker creates a lookalike social media handle mimicking a well-known brand's official support account.
- 2
Monitoring: the fake account watches for public posts, mentions, or complaint hashtags naming the real brand.
- 3
Race to respond: it replies to a frustrated customer's public complaint before or alongside the real support team.
- 4
Redirect to a private channel: the reply invites the victim to continue in a direct message, a WhatsApp number, or an external link to 'resolve it faster.'
- 5
Credential or data harvest: the victim is asked to verify account details, a password, or a one-time code through the fake channel.
- 6
Exploitation: the harvested credentials are used for account takeover, fraud, or further attacks against the victim.
Warning signs
- A support handle spelled slightly differently, missing a verification badge, or recently created
- An unusually fast reply that quickly invites you to move to a direct message or WhatsApp number
- A request for a password, OTP, or full account number to 'verify your identity' or 'process a refund'
- A link in the reply that does not lead to the brand's official domain
- An account with very few followers or little posting history despite claiming to be official support
How to defend
- Verify that a support account matches the brand's officially listed handle before engaging with it
- Never share a password, OTP, or full account number through a direct message or social platform
- Navigate to the brand's official website or app directly instead of clicking links from social media replies
- Report and block lookalike support accounts, and encourage colleagues to do the same
- Treat any support interaction that begins on social media as unverified until confirmed through an official channel
Real-world example
A bank customer in Jakarta posts a public complaint about a failed transfer, tagging the bank's official account. Within minutes, an account with a name almost identical to the bank's real support handle replies, asking her to direct message her account number and one-time password to 'expedite the refund,' a scam that succeeds because she is frustrated and eager for a fast resolution rather than checking whether the account is genuinely verified.
How Claro helps
Claro's awareness content extends the same verify-before-you-trust habit built for suspicious emails to the social media channels where customers and employees increasingly expect support, reinforcing that an unsolicited support reply on social media deserves the same scrutiny as an unexpected email, with reported incidents feeding into the same risk visibility security teams already use for phishing.
Frequently asked questions
What is Angler Phishing?
Angler phishing is a social-media attack where a criminal poses as a brand's customer-support account, watches for people complaining, and replies from a fake account to lure them into sharing credentials.
How is angler phishing different from regular brand impersonation?
Brand impersonation covers any imitation of a trusted brand's identity across channels. Angler phishing is a specific technique carried out on social media, using fake support accounts that intercept public complaints in real time before the real brand can respond.
Why do people fall for angler phishing so easily?
Victims are already frustrated and actively seeking help, which lowers their guard, and a fast, personal-seeming reply feels like a lucky break rather than a targeted attack, especially since most people do not think to check whether a support handle is genuinely verified.
What should I do if a support account messages me first?
Treat it as unverified until you confirm it matches the brand's official handle through their real website. Never provide a password, OTP, or full account number over social media, no matter how legitimate the conversation appears.
Can companies prevent angler phishing targeting their customers?
They can clearly register and promote their verified official handles, respond to public complaints quickly to close the window attackers exploit, and actively monitor for and report lookalike accounts to the platform.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Brand Impersonation
A phishing tactic where attackers mimic a well known company's branding, tone, and communication style to make fraudulent messages appear legitimate.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo