DMs Promise Enhanced Pictures, but Deliver Malicious Links



instagram phishing scamScammers are sending phishing messages on Instagram telling users to check out some edited versions of their photos, according to John Finn at Screen Rant. Finn explains that the scammers send the messages from hacked accounts to the hacked accounts’ contact lists, so the targets see the message as coming from someone they know.

“I didn't expect this to take so long, But I finally got to it,” the message states. “You better love it. I used some of your pics.”

The message is followed by a link titled “3 Of Your Pictures, And 4 Hours Of My Time.” If the user clicks this link, they’ll be taken to a fake Instagram login page designed to steal their credentials.

“As is often the case with link scams, the link itself is the main part of the scam,” Finn writes. “Instead of redirecting the user to the photos, the link goes to a fake version of the Instagram website, prompting the user to sign in to view the images. Once signed in to the fake Instagram site, the user has effectively handed over their Instagram credentials to the scammers. At which point, they can take control of the account. This is where the Instagram friends issue comes in. Once one Instagram account has been compromised, the scammers can use the login details to send a DM to all of the account's listed Instagram friends. As the DMs are coming from a known person, the likelihood of the friends clicking the link to view the pictures becomes all the more likely.”

Finn concludes that you should simply ignore scammy-looking messages, or you can contact your friend through a separate mode of communication to let them know their Instagram account has been hacked.

“The easiest way to avoid this scam is just to avoid any direct message that claims to have improved your pictures and provides a link for the user to view the images,” he says. “This includes even when the DM comes from a known Instagram contact. Of course, in cases where it is someone the user knows well, they can always take the extra precaution of contacting the friend outside of Instagram to confirm the DM was authentic.”

New-school security awareness training can help your employees recognize social engineering tactics designed to trick them into clicking on malicious links.

Screen Rant has the story: https://screenrant.com/instagram-dm-three-pictures-photo-phishing-scam/


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews