Cybersecurity researchers at Check Point have issued a fresh and urgent warning about a sprawling social media fraud campaign that is actively targeting airline passengers. According to the researchers, scammers are now impersonating airline customer support teams on popular platforms such as X, Facebook, and Instagram, with the express goal of stealing payment data and money from frustrated travelers. The campaign, which has been running for some time and remains highly active, involves the creation of hundreds of fake social media accounts every single day. These accounts are designed to look like legitimate airline profiles or customer support handles, and they are being used to intercept unsuspecting passengers who post complaints or tag airlines in the hope of getting help. Instead of receiving assistance from a real airline representative, these passengers are being lured into private conversations where criminals attempt to extract sensitive financial information. The warning from Check Point highlights a growing and increasingly organized form of cybercrime that exploits the very public nature of social media complaints, turning a moment of frustration into a serious security risk.
The mechanics of the scam are deceptively simple, yet highly effective. When a customer takes to social media to vent about a delayed flight, lost baggage, or poor service, they often tag the airline’s official account in their post. This action alerts both the airline and the scammers to the customer’s distress. The criminals, who monitor these channels around the clock, are quick to respond with a public apology and an offer of assistance, often instructing the user to continue the conversation in a private channel. This could be a direct message on the same platform, or a move to an entirely different app such as WhatsApp. Once they have moved the conversation out of the public eye, the scammers deploy a range of tactics to harvest information. In many cases, they ask the victim to provide personal details, such as passport numbers, address information, or banking credentials, under the guise of verifying their identity or processing a refund. In other instances, they send a link to a fraudulent form designed to capture payment card numbers, expiration dates, and CVV codes. The collected data may then be used to make unauthorized wire transfers or purchases, or it may be stored for future fraudulent activity.
According to Check Point’s research, while the exact start date of this campaign is difficult to pinpoint, the researchers were able to identify impersonation accounts that predate 2024. This suggests that the practice is not entirely new, but the real explosion in activity has occurred over the past two years. A majority of the fraudulent accounts they discovered were created either in 2024 or later, indicating a sharp acceleration in the campaign. The researchers noted that hundreds of new fake accounts are appearing on a daily basis, and that scam techniques continue to evolve, making it harder for both platforms and users to distinguish between legitimate customer service representatives and cybercriminals. This recent wave of airline-related fraud also mirrors an earlier trend observed on X during the cryptocurrency ICO craze in 2021, when scammers used similar fake support accounts to target people who had lost access to their digital wallets or mistakenly sent funds to nonexistent addresses. That earlier campaign operated in much the same way, relying on the victim’s distress and urgency to push them into a false sense of security, and the current airline scam is a textbook example of the same social engineering method being adapted to a new industry.
The effectiveness of this scam lies in its exploitation of human psychology and the realities of modern air travel. Flying is often a stressful experience, and when things go wrong, passengers can be left feeling angry, anxious, and desperate for a quick resolution. Long wait times on official customer service hotlines and unhelpful chatbots only add to this frustration, making the prospect of a social media representative who responds almost instantly seem like a welcome relief. Scammers are well aware of this dynamic and deliberately craft their fake accounts to appear as helpful, empathetic, and legitimate as possible. They steal official airline logos, use recognizable usernames, and mimic the tone of genuine customer support agents. In some cases, they go as far as liking or retweeting real posts from the airline to further legitimize their profile. The result is that a passenger who is already emotionally vulnerable is far less likely to scrutinize the account before handing over sensitive information. Even more concerning is that the theft of payment data can lead to financial loss, identity theft, and further targeted attacks, as the criminals may sell the collected information on dark web marketplaces or use it to carry out additional fraud against the victim.
In light of these findings, cybersecurity experts are urging both airlines and social media platforms to take more aggressive action to protect consumers. For airlines, this means actively monitoring social media for unofficial accounts that misuse their branding and working quickly to have them reported and removed. It also means creating clearly verified channels for customer support and educating passengers about how to identify the official account. For social media platforms, the responsibility lies in improving the speed and efficiency of their verification processes and takedown procedures. However, researchers at Check Point emphasize that the best defense ultimately rests with the individual user. Travelers should take a moment to verify that the account they are speaking to is genuinely affiliated with the airline, looking for blue checkmarks and checking the exact spelling of the username. They should be extremely wary of any unsolicited request to move a conversation to a different messaging app, particularly if that move is accompanied by a demand for payment or personal information. Also, individuals should never share sensitive data like passwords, PINs, or full card details through social media or messaging platforms. If an account asks for such information, it is almost certainly a scam, and the interaction should be terminated and reported immediately.
The rise of fake customer support scams in the airline industry underscores a broader trend in cybercrime, in which attackers exploit existing trust in brands and the human need for assistance. As social media continues to be one of the most common places for customers to voice complaints, it is inevitable that criminals will refine their methods and expand into new sectors. Check Point’s findings suggest that this particular campaign is not winding down anytime soon, and that new techniques are constantly being developed to evade detection. The warning serves as a reminder that in the digital age, not every helpful response is genuine, and that the convenience of social media comes with its own set of risks. Whether a traveler is dealing with a canceled flight, a lost bag, or any other travel headache, it is safer to use official airline websites, apps, or verified contact numbers than to respond to an unverified social media message. By staying alert, questioning unsolicited requests, and reporting suspicious accounts, passengers can protect themselves from becoming another victim of this growing wave of social media fraud. The bottom line is simple: while airlines and platforms must do their part, the ultimate responsibility for protecting personal and financial data lies with the user, and a moment of caution is well worth the price of avoiding a costly and stressful scam.

![{
“analysis”: “I need to inspect the provided files and understand the existing migrated implementation before creating the required run.sh wrapper.”,
“plan”: “List the /app directory contents and inspect the structure to see what’s available.”,
“commands”: [
{
“keystrokes”: “ls -la /app\n”,
“duration”: 0.1
},
{
“keystrokes”: “ls -la /app/src /app/legacy /app/data /app/sample 2>/dev/null || true\n”,
“duration”: 0.1
}
],
“task_complete”: false
}](https://disa.org/wp-content/uploads/2026/09/CRRFyjRJcZe8qvwLLLssrL-2560-80-768x432.jpg)