Instagram Phishing Emails Use Fake Login Warning Baits

Instagram Phishing Emails Use Fake Login Warning Baits


Instagram users are currently targeted by a new phishing campaign that uses login attempt warnings coupled with what looks like two-factor authentication (2FA) codes to make the scam more believable.


Crooks use phishing to trick potential victims into handing over sensitive information via fraudulent websites they control with the help of a wide range of social engineering techniques, as well as messages designed to look like they're sent by someone they know or a legitimate organization.


In this case, the phishing e-mails distributed by the attackers behind this campaign use fake Instagram login alerts stating that someone attempted to log in to the target's account, asking them to confirm their identity via a sign-in page linked within the message.


Authentication codes used to add legitimacy


These messages are designed to look as close as possible to what official messages coming from Instagram to avoid raising any suspicions before the target is redirected to the attackers' phishing landing page.


"Apart from a few punctuation errors and the missing space before the word ‘Please’, this message is clean, clear and low-key enough not to raise instant alarm bells," details Sophos' Paul Ducklin who analyzed the campaign.


To further increase the illusion that they are official Instagram alerts, the crooks also add a code which apparently should be used as a second authentication code for identity confirmation.


"The use of what looks like a 2FA code is a neat touch: the implication is that you aren’t going to need to use a password, but instead simply to confirm that the email reached you," Ducklin adds.



Instagram phishing email sample

Once on the phishers' landing page, the targets see a perfectly cloned Instagram login page secured ..

Support the originator by clicking the read the rest link below.