Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Posted a complaint on social media? Fake customer support may reply first

A public comment reveals that you are waiting for help. Before moving into direct messages, verify the profile and start contact through the company’s official channel.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
15 September 2026
READING TIME
7 min read
TOPIC
Human Security
Posted a complaint on social media? Fake customer support may reply first

You comment under a bank, airline or retailer’s profile: “I have been waiting two days for my refund. Please contact me urgently.” Minutes later, an account carrying the company logo replies and invites you into a direct message. The agent understands the issue because they read your public comment. That does not mean they work for the company.

A scammer does not have to guess who needs support. You identified the problem, brand and moment when a quick answer matters. All they need is a similar account name, copied logo and polite response delivered before genuine customer service arrives.

Knowing the context does not prove the agent’s identity

The fake account can repeat a flight number, complaint type or product name visible in your comment. It may ask for an order reference, phone number and email so that the exchange resembles routine verification.

Pause when “support” moves you to another messenger, sends a form on an unrelated domain, asks for a password, text-message code, full card details or a small payment to release a refund. A real agent does not need your account password or a code that authorises a sign-in or payment.

Do not rely on the logo, display name or follower count alone. Check the account’s history, exact handle and links from the company’s official website. Even then, it is safer to start the conversation yourself through the app, customer portal or a number from your agreement.

Keep public complaints free of account details

Do not publish a booking or order number, phone number, email address, partial card details or a document photograph. A general description is enough to draw the company’s attention. Share case details only after entering a verified support channel.

If somebody asks you to remove the comment “for security” before the contact is verified, that alone does not prove fraud, but it is a reason to pause and check independently. Removing the public trail can make it harder to notice several fake profiles working beneath the same post.

Return safely to genuine support

Close the direct-message exchange and open the company’s app or type its address yourself. Use the contact section, not a number provided by the suspicious account. If the brand operates verified social profiles, reach them through links on its official website.

Send genuine support a screenshot and link to the impersonating profile. Report the account to the social platform as well. Use the appropriate national cybercrime reporting service for any suspicious link.

If you shared only an order number, expect follow-up attempts that use it to sound more convincing. If you disclosed a password, change it through the real service and end unfamiliar sessions. Contact your bank immediately after sharing card details or approving a payment.

Companies can reduce the space available to impostors

A brand should explain whether it uses direct messages, what its official profiles are and what information support will never request. It should monitor replies beneath its posts and customer complaints, remove impersonating accounts quickly and place warnings where customers are already looking.

Social-media staff also need a simple escalation route. They should not conduct an investigation alone or ask the customer to post more details publicly.

What the sources confirm and what Breachroad recommends

Services Australia warns in its social-media scams factsheet that criminals create fake pages, profiles and groups and comment on official social accounts. The agency says it does not request personal information through social media. The US Federal Trade Commission describes the wider pattern of business impersonators using messages and social platforms. The contact policy of any particular organisation must still be checked through that organisation’s own channels.

Breachroad recommends treating a public complaint as a signal visible to scammers as well as the company. A reply can fit your case because the case is public. Our guide to reporting a scam and warning one other person covers the next step. Organisations can prepare customer-service teams and employees through cybersecurity awareness training.

SHARE / COPY