Criminals are hijacking Instagram influencers’ accounts and demanding that victims pay a ransom in bitcoin to regain access.
Kevin Kreider, a Los Angeles-based Instagrammer who’s known for his following around fitness-related topics, told Motherboard that extortionists first targeted him when someone named Lana reached out with a fake business opportunity. Posing as a press relations staffer from fashion company French Connection, Lana offered a sponsorship deal and sent over a link shortened with Bit.ly to the company’s own Instagram account. After being clicked by Kreider, the link redirected him to a fake login page designed to steal his Instagram credentials.
“I was at the gym going through my emails and thought it was an opportunity with a brand I respected and thought I could put on my Instagram, and when I saw that my Instagram [@kevin.kreider] disappeared from my app, my heart dropped to my stomach,” Kreider said to Motherboard.
Shortly thereafter, those responsible for hijacking Kredier’s account contacted him and demanded a ransom payment. The Instagram influencer ultimately paid $110. Even so, the criminals deleted his account, as it became unsearchable. He said he eventually retrieved his account, though it’s not clear how at the time of this writing.
Kreider is just one influencer on Instagram whom criminals have recently targeted with account takeover and extortion attacks. As reported by Motherboard, something similar happened to Lindsey Simon. She used the services of a computer-savvy friend to delay the ransom payment process and eventually recover her password. And then there’s Anna Wood, an influencer with over 50,000 followers who regained access to her hijacked Instagram account only after her followers posted her story on the platform.
Cassie Gallegos, a lifestyle-based Instagram influencer, wrote about how she reacted to a success account takeover attack in a blog post:
*** This is a Security Bloggers Network syndicated blog from The State of Security authored by David Bisson. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/criminals-holding-hijacked-instagram-influencers-accounts-for-ransom/