A delayed flight or missing luggage is all it takes for cybercriminals to pounce. Discover how threat actors exploit public frustration on social media to steal thousands from unsuspecting consumers.
When travel plans collapse, public social media channels become the immediate outlet for distressed consumers. A delayed flight, a declined credit card, or lost luggage prompts passengers to tag airlines in desperate bids for assistance. However, security researchers at Check Point Exposure Management have revealed that coordinated threat actors are turning these public cries for help into lucrative digital traps. Rather than breaching corporate networks, these fraudsters sit directly in the public replies beneath brand posts, impersonating official support channels, capitalizing on brand delays, and stealing thousands of dollars from unsuspecting victims.
The Architecture of Impersonation
The mechanics of the campaign rely entirely on social engineering and weaponized public visibility. When a customer posts a public grievance on platforms like X or Facebook, impersonation accounts swiftly reply using sympathetic, official-sounding language. Names such as “Customer Resolution Centre,” “Claim Review Unit,” or “Live Assistance” are used alongside corporate logos to mimic real support desks.
+———————————————————————————–+
| PUBLIC BRAND COMPLAINT WORKFLOW |
+———————————————————————————–+
| 1. Victim posts public complaint on X/Facebook (tagged to official brand) |
| 2. Threat Actor (TA) replies instantly via fake handle asking for direct message |
| 3. TA requests phone number, booking details, and complaint specifics in DM |
| 4. TA moves conversation to WhatsApp (using burner/VoIP U.S. numbers) |
| 5. TA sends link/app registration to international payment service (Remitly, etc.)|
| 6. Victim inputs card details believing they claim a refund, but sends money to TA|
+———————————————————————————–+
By stepping into the vacuum left by overwhelmed support teams, bad actors request that victims follow their page and share private contact details, including phone numbers and booking references.
Inside the HUMINT Investigation
To uncover the operational pipeline, researchers conducted a direct Human Intelligence (HUMINT) investigation. After reaching out to impersonation accounts, investigators were redirected off-platform to WhatsApp. Although the accounts displayed U.S.-based area codes (such as New York’s 929 or Pennsylvania’s 412), network analysis revealed the numbers were virtual Voice over IP (VoIP) lines routed through third-party switching infrastructure like Neutral Tandem.
Telecommunication traces and operator slip-ups tied the nexus of operations to Kenya. Operatives engaged in high-pressure tactics using structured scripts, demanding sensitive information under the guise of processing immediate financial restitution.
Executing the Cash-Out Mechanisms The threat actors utilize three primary execution vectors to trick users into sending money while believing they are receiving compensation:
- Digital Remittance Applications: In one vector, fraudsters register the victim’s email address on platforms like Remitly or Lemfi. They initiate an outbound money transfer to Kenya (e.g., $500 or $1,200) and instruct the victim to open the app on their mobile phone to “claim” their funds. When the victim logs in, they are prompted to enter their credit card details to complete the pre-filled form, unknowingly authorizing a transfer directly to the scammer’s overseas account.
- Phishing Data Harvesters: Alternatively, scammers distribute hosted links such as Google Forms titled “COMPENSATION/REFUND APPLICATION”. These forms harvest full legal names, home addresses, dates of birth, credit card numbers, expiration dates, and CVVs.
Mitigation and Corporate Response
This threat vector is not isolated to a single carrier; hundreds of new impersonation accounts emerge daily targeting major brands across North America and Europe. To mitigate brand risk, enterprises must proactively monitor social platforms, swiftly request account takedowns, direct sensitive support away from public threads, and coordinate with international money transfer services to block fraudulent transaction patterns.
“The current campaign highlights a new dimension of exposure management. When scammers create fake support accounts to lure frustrated customers onto private channels like WhatsApp and specifically target their financial and credit card information there, trust in the entire brand comes under fire. For companies, it is therefore no longer enough to simply secure their internal IT infrastructure. Effective protection today requires continuous monitoring of the external attack surface—including fake social media profiles and brand imitations,” explains Daniel Dreier, AVP at Check Point Exposure Management.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de