- Vector
- phishing
- Severity
- moderate
- Data exposed
- Compromised established accounts; followers lured to credential- and wallet-stealing sites
- Attacker
- Cybercriminals targeting established accounts
- Disclosed
- 2024-01-01
- Date
- 2024-01-01
What happened
Cybercriminals hijack established, high-follower social-media accounts, including on Reddit, through targeted phishing and social engineering, then abuse the trusted accounts to spread cryptocurrency 'giveaway' and investment scams. The takeovers let attackers push links to malicious sites that steal followers' wallet information or further credentials, exploiting the credibility of the compromised account. On Reddit, related schemes include staged giveaway hoaxes that require victims to send money or personal documents to 'claim' a prize. The FBI and security vendors recommend unique passwords and multi-factor authentication to resist the initial account compromise. The pattern overlaps with Reddit's broader fake-moderator phishing problem.