Cybercriminals are monitoring public complaints made by airline customers on social media and using fake customer-service accounts to lure victims into providing personal and financial information,cybersecurity firm Check Point has found.
The threat actors reportedly target passengers who publicly complain about delayed flights, failed card payments, missing refunds and other problems by responding to their posts while impersonating the airline or its customer support representatives.
According to a Check Point investigation, the scammers exploit the public nature of customer complaints on platforms including X and Facebook, where they identify frustrated users and approach them before legitimate customer-service teams can respond.
The attackers typically apologise for the inconvenience, request additional details and ask customers to move the conversation into direct messages. They then seek information such as phone numbers, email addresses, booking details and, in some cases, financial information.
Check Point said it identified thousands of social media accounts impersonating airlines, vacation brands, customer-support teams and representatives, with new accounts reportedly being created regularly.
Some of the accounts use airline logos, profile images, cover photographs and descriptions designed to resemble legitimate customer-service pages. Others use variations of terms such as “Customer Support,” “Claims Department,” “Help Desk,” “Claim Assist” and “Live Assistance” in their usernames.
The cybersecurity company said the accounts were observed responding directly to customers who had tagged verified airline accounts with complaints.
In one example examined during the investigation, an impersonating account asked a customer to follow the account and send a phone number through direct message. The interaction was subsequently moved to WhatsApp, where the threat actor continued the impersonation.
How the scam works
Check Point said its researchers engaged directly with several impersonating accounts and found that the scammers followed a structured process designed to make the interaction appear like a legitimate compensation or refund claim.
The threat actors first requested personal information and details about the customer’s complaint. After obtaining the information, they claimed to have verified the complaint and told the victim that compensation had been approved.
In one case, a threat actor directed researchers to an international money-transfer service, where an unfinished transfer of $500 had been initiated using the victim’s name.
Check Point said the process was designed to make the victim believe they were receiving compensation, while ultimately attempting to get them to provide card information or send money to the fraudster.
In another case, researchers were told they were eligible for $1,200 in compensation and were directed towards another international money-transfer application after being asked to provide their name, email address, residential address and date of birth.
A third scam involved a Google Form presented as a “COMPENSATION/REFUND APPLICATION”, which requested personal information from people seeking refunds.
Check Point warned that links and applications sent during these interactions could also expose victims to additional risks, including malware or credential theft.
Possible links to Kenya
The investigation also identified several WhatsApp numbers used by the scammers. Although some appeared to be United States-based numbers, Check Point said the payments being arranged were directed towards Kenya.
The company said its investigation suggested that the campaign may be originating from Kenya, while noting that internet-based and purchased phone numbers can be activated in different regions from where their users are physically located.
Researchers also reported that one individual disclosed the surname “Waithaka”, which Check Point said is a Kenyan surname and also the name of an area in Nairobi.
The findings therefore point to possible links to Kenya, but the use of foreign or virtual phone numbers makes it difficult to establish the physical location of individual operators solely from their telephone numbers.
Not limited to one airline
Check Point said the activity was not restricted to a single airline.
Its researchers found similar impersonating accounts targeting several North American airlines, with the accounts using comparable language and methods to approach customers.
The company said individual airlines may become more prominent targets at different times, depending on the success of the scammers’ campaigns.
The investigation highlights a broader cybersecurity risk for companies with active customer-service operations on social media. Public complaints can provide criminals with information about a person’s current problem, their relationship with a company and, in some cases, enough personal details to make subsequent fraud attempts appear credible.
Check Point said airlines should continue reporting and removing impersonating accounts while educating customers about the scams.
It also recommended that airlines reconsider how they request sensitive information from customers on social media and move interactions involving booking details, telephone numbers or financial information to secure, verified channels.
The cybersecurity firm further urged airlines to work with social media platforms and international money-transfer companies to identify and disrupt fraudulent accounts and transactions linked to the campaigns.






