Loading…
Loading…
Social media and account-takeover scams target the accounts that hold your audience, contacts and identity. Tactics include verification-badge and copyright-strike phishing, hacked-friend impersonation, fake 'account recovery' help, bogus monetization or brand-collaboration offers, and theft of login sessions or two-factor codes. Once an account is taken over it is used to scam your contacts in turn. Protect yourself with app-based two-factor authentication, never sharing one-time codes, scrutinising 'urgent' login links, and recovering accounts only through the platform's official process.
Fake 'apply for your blue tick' messages that harvest account credentials or charge fees for a badge that never arrives.
Fake copyright or community-standards notices that panic creators into handing over account credentials or paying to 'resolve' the strike.
Messages that appear to come from a trusted contact whose account has been compromised, used to request money, gift cards, or personal information.
Fake 'recovery specialists' who charge fees or steal credentials while pretending to help restore a locked or hacked account.
Fraudulent offers to enrol creators in monetisation programmes, ad revenue sharing, or brand fund access — all requiring upfront fees or credential submission.
Counterfeit brand partnership offers that harvest credentials, extract fees, or obtain personal data under the guise of a paid sponsorship deal.
Services selling artificial followers, likes, or comments that deliver bot accounts, steal credentials, or enable ongoing billing fraud.
Fake 'Sign in with [Platform]' buttons and malicious OAuth app authorisations that harvest tokens granting persistent access to your account.
Duplicate profiles built using your public photos and name to scam your contacts or tarnish your reputation.
Notices claiming your account has been suspended, directing you to external appeal pages that steal credentials or charge fees.
Fake prize notifications sent by DM that lead to credential-phishing pages or trick winners into authorising malicious apps.
Malware and malicious browser extensions that steal active session cookies, bypassing passwords and two-factor authentication entirely.
Multi-step attacks that manipulate victims into disabling or handing over their two-factor authentication to complete an account takeover.
Emails and in-app notices spoofing Meta Business Suite warn that a Page or ad account will be disabled unless the owner 'confirms' their identity on a phishing page that steals login credentials and ad-account access.
Fake recruiters contact job seekers on LinkedIn with attractive roles, then move the conversation off-platform to harvest personal data, charge fake onboarding fees, or deliver malware disguised as job documents.
Messages posing as TikTok's Creator Fund or Creativity Program invite creators to 'claim' earnings or bonus payouts, directing them to a phishing page that steals login credentials or payment information.
Emails impersonating YouTube warn that a channel received a copyright or community-guidelines strike and will be terminated unless the creator logs in through a fake link, handing over credentials that lead to full channel takeover.
Scammers exploit the existence of genuine paid verification subscriptions by offering to sell badges through unofficial channels or fake discounted bundles, collecting payment or credentials without ever delivering real verification.
Fake 'monetization team' messages target short-form video creators with promises of instant Reels or Shorts bonus payouts, using look-alike dashboards or upfront 'activation fees' to steal credentials and money.
Compromised or spoofed accounts direct message followers claiming a limited-time cryptocurrency giveaway that requires sending a small deposit first to 'unlock' a much larger return, which never arrives.
Unsolicited messages invite users to become a 'brand ambassador', requesting an upfront kit fee, personal identification, or bank details in exchange for free products and commission that never materialise.
Compromised accounts mass-tag friends in comments with a shocking or curiosity-driven link that installs malware or steals credentials, then uses the newly infected account to repeat the cycle against its own contacts.