Angler Phishing
Angler phishing is a social media attack where criminals pose as a brand's customer support account to intercept complaints and steal credentials or payment data.
Angler phishing is a social-media-based phishing attack in which criminals impersonate a company's customer service team and "help" customers who complain publicly. The name comes from the anglerfish, which dangles a glowing lure to draw prey toward its jaws — here the lure is a fake support account that looks eager to solve your problem.
How it works
The attacker monitors platforms like X, Facebook, Instagram, or LinkedIn for people tagging a brand with complaints — a delayed bank transfer, a lost airline booking, a locked account. They then reply from a look-alike support handle (for example @BankOfAmerlca_Help instead of the real handle), complete with the brand's logo, colors, and a reassuring tone. Because the victim initiated the contact and is already frustrated, their guard is down: they expect the brand to respond.
The fake agent moves the conversation to direct messages and asks the victim to "verify" their identity — account number, password, one-time code — or sends a link to a spoofed login or refund page, often on a typosquatted domain. Financial services, airlines, and e-commerce brands are favorite disguises because their customers routinely discuss account problems in public. Unlike traditional phishing, the attacker never has to find the victim's email address or get past a spam filter; the victim walks up to the lure on an open platform.
How to defend against it
For individuals: only use support channels found on the company's official website, check the account's handle spelling, age, and follower history before engaging, and treat any "support" request for passwords or one-time codes as an automatic red flag — no legitimate support team needs them.
For organizations: register and monitor look-alike handles, report impersonation accounts aggressively, and publish your official support channels prominently so customers know what real help looks like. Because employees who manage corporate social accounts are prime targets themselves, include angler-phishing scenarios in your security awareness training and test recognition with realistic simulations.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo