← All terms

Angler Phishing

Angler phishing is a social media attack where criminals pose as a brand's customer support account to intercept complaints and steal credentials or payment data.

Angler phishing is a social-media-based phishing attack in which criminals impersonate a company's customer service team and "help" customers who complain publicly. The name comes from the anglerfish, which dangles a glowing lure to draw prey toward its jaws — here the lure is a fake support account that looks eager to solve your problem.

How it works

The attacker monitors platforms like X, Facebook, Instagram, or LinkedIn for people tagging a brand with complaints — a delayed bank transfer, a lost airline booking, a locked account. They then reply from a look-alike support handle (for example @BankOfAmerlca_Help instead of the real handle), complete with the brand's logo, colors, and a reassuring tone. Because the victim initiated the contact and is already frustrated, their guard is down: they expect the brand to respond.

The fake agent moves the conversation to direct messages and asks the victim to "verify" their identity — account number, password, one-time code — or sends a link to a spoofed login or refund page, often on a typosquatted domain. Financial services, airlines, and e-commerce brands are favorite disguises because their customers routinely discuss account problems in public. Unlike traditional phishing, the attacker never has to find the victim's email address or get past a spam filter; the victim walks up to the lure on an open platform.

How to defend against it

For individuals: only use support channels found on the company's official website, check the account's handle spelling, age, and follower history before engaging, and treat any "support" request for passwords or one-time codes as an automatic red flag — no legitimate support team needs them.

For organizations: register and monitor look-alike handles, report impersonation accounts aggressively, and publish your official support channels prominently so customers know what real help looks like. Because employees who manage corporate social accounts are prime targets themselves, include angler-phishing scenarios in your security awareness training and test recognition with realistic simulations.

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.Spear PhishingSpear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.TyposquattingTyposquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo