Fake Bank Customer Service on Social Media
This is angler phishing: fraudsters lurk on social media, watch for customers publicly complaining to their bank, and pounce with a convincing fake support account. This walkthrough is a fictional, illustrative example built for training.
The scenario
A frustrated customer posts a complaint mentioning their bank on X or Instagram, for example about a failed transfer or a blocked card. Within minutes, an account with a name and logo almost identical to the bank's official support handle replies, apologizing and offering to help.
The fake handle looks convincing at a glance: a similar profile picture, a name like 'BankCare Official' or a slight misspelling of the real handle, and sometimes a fake blue-check styled image. It asks the customer to continue the conversation in a direct message or on WhatsApp 'for privacy'.
Once in private chat, the impostor asks the customer to 'verify their identity' by providing card number, expiry, CVV, mobile banking username, PIN, or the one-time password just sent to their phone. Each request is framed as a routine security step needed to unblock the account or reverse the transaction.
With these details, the attacker logs into the victim's mobile banking or completes a card transaction, using the harvested OTP to authorize it. The victim, believing they were talking to their bank, often hands over the final OTP that seals the fraud.
Red flags to spot
Customer service replied first, before you contacted them
Real banks respond through their single verified account and never proactively slide into your DMs from a second handle to ask for details.
The handle is a lookalike, not the verified official account
Attackers use near-identical names, added words like 'care' or 'official', or extra characters. Always check for the genuine verified badge and the exact handle listed on the bank's own website.
You are moved to DM or WhatsApp 'for privacy'
Shifting to a private channel takes you away from public scrutiny and platform protections, making it easier to pressure you unobserved.
A request for PIN, CVV, or OTP
No legitimate bank will ever ask for your PIN, card CVV, or an OTP. These exist precisely so that only you can authorize actions; sharing them hands over full control.
Urgency to 'unblock' or 'reverse' before it is too late
Manufactured time pressure is meant to stop you from pausing to verify the account through official channels.
The lesson
Treat any customer-service account that contacts you first as suspicious until proven otherwise. Banks communicate through one verified handle and their official call center, and they will never ask for your PIN, CVV, or OTP through social media, DM, or WhatsApp. If you need help, ignore the reply and instead call the number printed on the back of your card or listed on the bank's official website. Report impostor accounts to the platform and to your bank so they can be taken down before they reach the next victim.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
Angler phishing is when attackers impersonate a brand's customer support on social media, watching for complaints and replying from a fake account to lure victims into sharing credentials. Learn more in our glossary entry on angler phishing.
Related pages
Fake Kartu Prakerja Selection Notice
A message claims you have been selected for the Kartu Prakerja program and must pay an activation fee or register on a lookalike site that harvests your NIK, KK, and bank details.
Learn moreFake CPNS Recruitment Offer
A message posing as a recruitment committee offers a guaranteed CPNS position or asks for a fee and personal documents, exploiting the high demand for civil-servant jobs.
Learn moreFake ETLE Traffic Ticket with Malicious App
A WhatsApp message claims you have an electronic traffic ticket (tilang elektronik) and attaches an APK file to 'view the details', which is actually Android malware that steals your banking data.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo