Cybercriminals Hijack Instagram Influencer’s Account to Conduct Banking Credential Theft

Cybercriminals Hijack Instagram Influencer’s Account to Conduct Banking Credential Theft

Massive Instagram Scam Exploits Influencer’s Reach in Targeted Credential Theft Scheme

An Instagram account belonging to a high-profile lifestyle creator — boasting a following of more than 2.5 million — was silently taken over in a calculated social engineering plot that unfolded earlier this week.

On Monday, cybercriminals seized control of the influencer’s profile after deploying a deceptive spear-phishing email crafted to look like an urgent copyright infringement warning from Instagram. Once compromised, the account was transformed into a weaponized marketing trap.

Followers began receiving direct messages that mimicked brand partnerships and exclusive deals. These “offers” appeared legitimate, promising high-demand discounts — but clicking the links rerouted users to forged landing pages designed to steal login credentials.

The attack stood out for its precision. Rather than blasting the entire audience, the perpetrators focused on engaging the influencer’s most interactive followers, sending messages tailored to simulate authentic conversations. This personalized touch amplified the scam’s believability, pushing unsuspecting users to act quickly before the “deals” expired.

Fake Bios, Real Damage: Scam Exploits Influencer Trust to Drain Bank Accounts

Security experts at Kaspersky flagged a growing scam this week after multiple users reported unauthorized withdrawals from their bank accounts — all traced back to a single source: an influencer’s hijacked Instagram profile with a suspiciously edited bio.

What began as subtle changes to a profile quickly escalated into a full-blown phishing campaign. Investigators linked the operation to the elusive cybercriminal group known as TA505 — a veteran outfit in online fraud circles, infamous for blending psychological manipulation with malware deployment.

“This wasn’t just a technical breach — it was a social one,” noted Dr. Elena Markov, a lead cybersecurity expert at Kaspersky. “The attackers weaponized personal connection, capitalizing on the trust that followers place in digital creators.”

Unlike generic phishing campaigns, this one achieved unusually high engagement, driven by the illusion of exclusivity and the credibility of the compromised account. The result: more clicks, more stolen data, and faster monetization for the attackers.

Deceptive Promo Video Leads to Stealthy Banking Data Theft via Instagram Scam

What looked like a slick promotional video on Instagram turned out to be a digital trap — crafted not by brands, but by cybercriminals. According to researchers at Kaspersky, the first video shared through the compromised influencer account was a fake, designed to bait followers into clicking a fraudulent link.

Behind that link? A carefully staged credential-theft operation powered by a concealed JavaScript payload. Victims were taken to a page that mimicked a well-known brand’s offer, unaware that a hidden script was quietly working behind the scenes.

This script — obfuscated to avoid detection — built an invisible layer over banking login fields. As users entered their credentials, the malware captured them in real time and funneled the data straight to criminal servers.

The attack wasn’t just sneaky — it was smart. The malware checked whether it was running in a security lab or under investigation, refusing to activate in those conditions. This level of stealth is a known tactic of TA505, a group with a reputation for advanced banking fraud campaigns.

After the breach was discovered, Instagram’s security team swiftly took back control of the compromised account. Cybersecurity professionals are now piecing together the full reach of the attack.

Anyone who may have clicked on unfamiliar links through Instagram DMs this week is urged to update their banking passwords and enable two-factor authentication immediately.

More Articles & Posts