Doppel Email Security is now generally available! | Register for the webinar to learn more
General

What Is Angler Phishing?

Angler phishing uses fake customer support accounts on social media to intercept complaints and steal credentials. Learn how it works, its warning signs, and how to defend.

Doppel TeamSecurity Experts
August 31, 2026
5 min read

Angler phishing is a social media impersonation attack (opens in new tab) in which criminals create fake customer support accounts (opens in new tab) for a legitimate brand, monitor public complaints from real customers, and reply before the genuine support team can, steering victims into direct messages or credential-harvesting pages (opens in new tab).

The name comes from the anglerfish, whose glowing lure draws in prey: the fake support reply is the lure, and the customer's own complaint brings the victim within reach. Where ordinary phishing pushes messages out to a list the attacker built, angler phishing waits for a customer to raise a problem in public, then answers first.

How angler phishing works

The attack unfolds in a predictable sequence, starting with a lookalike account (opens in new tab): a handle that differs slightly from the real one, the brand's logo and bio copied over, and words like "support," "help," or "care" added so the profile surfaces when a distressed customer searches.

In one early documented campaign, customers who posted to a major UK bank's support handle got replies from an account with two words transposed (opens in new tab).

Attackers automate and time victim selection. They run keyword monitoring (opens in new tab) for terms like "help," "billing issue," or the brand name itself, then reply to the customer's public post before the real team does. The interception works because the victim started the conversation (opens in new tab): the customer reached out expecting support, so a reply that offers it arrives already trusted, without the suspicion a cold message would draw.

The conversation then moves into a direct message or a "support link," and in some cases the fake account hands over a phone number instead. Wherever it lands, the payload is the same. The attacker sends the victim to a spoofed login page (opens in new tab) or asks them to "confirm" a password or enter a "security code.

In crypto variants, the attacker routes them to a fake support form that requests a wallet seed phrase.

Why angler phishing is hard to stop

The attack lives inside a race condition. The gap between a customer's public post and the genuine reply is the attacker's entire operating window, and the attacker only has to answer first.

Platform verification no longer closes that gap. Since legacy verification ended in April 2023, X has sold blue checkmarks through X Premium, and paid badges make impersonators look legitimate. X's paid model has since drawn an EU penalty under the Digital Services Act (opens in new tab) over "verified" status granted without meaningful identity verification (opens in new tab).

Alongside paid badges, generative AI (opens in new tab) has eroded the profile and conversational tells defenders once relied on. Attackers now fabricate convincing support personas (opens in new tab) at scale and run adaptive conversations (opens in new tab) that adjust to a victim's replies in real time.

Warning signs of angler phishing

The tactic shows up across banking, travel, and crypto exchange support (opens in new tab). Anyone reviewing suspected fake support activity should look for these indicators:

  • Lookalike handles. Slight misspellings, added words ("support," "help"), extra characters, numbers, or underscores relative to the official account.
  • Thin, young profiles. A short bio, copied logo, low follower count, and recent creation date are all reasons to doubt an account claiming to represent a major brand.
  • Paid verification badges. A blue checkmark can be bought through X Premium, so it does not by itself confirm identity.
  • Unsolicited replies that pivot to DMs. Fake accounts respond before the brand's own team does and immediately push the conversation private.
  • Requests for sensitive data or off-platform contact. Passwords, card numbers, seed phrases, or a "secure portal" link in the first few messages.
  • Urgency language. Pressure phrases and artificial verification deadlines are meant to rush the victim past a second look.
  • Multiple simultaneous "support" replies. Several accounts answering one complaint signal competing impersonators racing to reach the customer first.

How to defend against angler phishing

Compress the window between a customer's complaint and your response, and take down the fake accounts operating inside it.

Attackers redeploy fake support handles and phishing pages faster than manual, per-platform reporting (opens in new tab) can remove them, so monitoring and takedown have to run continuously rather than incident by incident.

How Doppel helps

Doppel is the AI-native Social Engineering Defense (SED) (opens in new tab) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab). It detects lookalike support accounts across social platforms and drives automated takedowns (opens in new tab).

Angler phishing operators rarely stop at one handle: they pair a fake support account with lookalike domains, spoofed login pages (opens in new tab), and scam ads. The Doppel Threat Graph (opens in new tab) correlates signals across social, domains, ads, telco, and crypto to surface the full impersonation campaign (opens in new tab), so a takedown dismantles the whole operation rather than a single profile.

Request a demo (opens in new tab) to see how the platform maps and dismantles a live impersonation campaign.

Frequently asked questions about angler phishing

What is angler phishing?

Angler phishing is a social media attack in which attackers set up fake customer support accounts impersonating a real brand, watch for public complaints from that brand's customers, and reply before the genuine support team can. The reply steers the customer into a direct message or a fake login page that harvests credentials, payment details, or other sensitive data. The name references the anglerfish, which uses a glowing lure to attract prey.

What is the difference between angler phishing and regular phishing?

Standard email phishing (opens in new tab) pushes fraudulent messages out to a target list the attacker built in advance. Angler phishing works in reverse: the customer's own public complaint on social media triggers the attack, so the customer initiates contact and arrives already expecting help from the brand. The channel differs too, playing out on platforms like X, Facebook, and Instagram rather than email. It also impersonates a brand's customer support function specifically, not a generic institution or executive.

Can a verified account still be an angler phishing account?

Yes. On X, a blue checkmark can be obtained through an X Premium subscription, and criminals exploit paid badges to make fake support accounts look legitimate. In December 2025, X drew a Digital Services Act penalty over findings that the badge deceives users because the company does not meaningfully verify who is behind an account. A paid badge does not prove authenticity.

What is an example of angler phishing?

Airline customer service impersonation is one documented example (opens in new tab): during a major travel disruption, attackers crawled social media for posts from stranded travelers and asked for booking numbers and bank details. Banks, retailers, and crypto exchanges face the same tactic, with fake exchange support accounts asking customers for wallet seed phrases. In each case, the public complaint hands the attacker a timely pretext to offer fake help.

Last updated: August 31, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.