Instagram Copyright Infringement is the Latest Phishing Scam Targeting Social Media

Stu Sjouwerman | Nov 14, 2019

businessman hand pointing to padlock on touch screen computer as Internet security online business conceptFocused on compromising social media credentials, scammers trick Instagram users into giving up credentials and other personally identifiable information with convincing phishing emails.

A good scam is made up of a mixture of powerful emotional triggers to create urgency, familiar branding, and a seemingly recognizable user experience. This scam has them all. Users are sent an email purporting to be from Instagram informing them of a copyright infringement they need to address. Those that click the link are taken to a realistic-looking webpage that informs them they have the option to appeal the infringement or be blocked after 48 hours.

With social media users not wanting to be cut off from their precious platforms, appeal is the only real option. Next users are asked for their account details and birthdate (to facilitate compromise of their actual Instagram account).

Phishing%20email,%20interstitial,%20and%20landing%20page

Note that the web address even appears to provide some degree of credibility, using both “Instagram” and “copyrightinfringement” in the URL.

The challenge with these kinds of scams is that it’s completely plausible that someone would violate a social media platform’s terms of service. Users need to elevate their sense of security around unsolicited emails that are vague in nature (e.g., this scam never provides the specifics around what exactly was posted that infringed on someone’s copyright) despite the impersonated use of a well-known brand.

Users can be easily educated on such tactics – as well as why and how to incorporate security-mindedness into their daily work activity – using Security Awareness Training. Today, the attack is about copyright infringement; tomorrow, it will be about some other issue that demands your users’ attention. Putting them through continual Security Awareness Training will help users to know how to identify suspicious emails, webpages, links, etc., allowing them to safely ignore or bypass the threat.

Stop Being a Target for Social Media Exploits

Social media is the new frontier for targeted spear phishing and credential theft. Use our Free Social Media Phishing Test to identify which users are likely to click malicious links or leak data on platforms like LinkedIn and X, and get your results in just 24 hours.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.