Scammers are monitoring airline complaints on social media and using fake customer support accounts to target passengers with refund and compensation offers, according to a Check Point Exposure Management investigation.
The campaign targets customers who post about delayed flights, missing luggage, failed refunds and other complaints on X, Facebook and Instagram.
Researchers found that scammers respond to these posts, pose as airline representatives and then move conversations to private channels, including WhatsApp.
Check Point identified thousands of accounts impersonating airlines, travel brands and customer support teams, with hundreds of new accounts reportedly appearing each day.
The fake accounts usually copy airline logos, profile images and other details from legitimate customer service pages. Some also use names such as Customer Support, Help Desk, Claims Department, Claim Assist and Live Assistance.
Once a passenger responds, the scammer typically asks for a phone number and booking details. The conversation then moves away from the public social media post.
Researchers said they interacted directly with several of the accounts and followed the process through to attempts to obtain payment and personal information.
How the scams work
In one case, a scammer requested the victim’s full name, email address, booking information, details of the complaint and the cost of the trip.
The researchers were then told that a $500 compensation payment had been approved. However, completing the transfer required credit card information and other personal details.
Another scheme promised $1,200 in compensation. The victim was then directed to an international money transfer application under the guise of receiving the payment.
A third approach used a Google Form titled “COMPENSATION/REFUND APPLICATION”. The form requested personal information as well as card numbers, expiry dates and CVV/CVC codes.
Check Point also found that scammers use WhatsApp Business accounts and virtual or temporary phone numbers when communicating with targets.
Some numbers used US area codes, including numbers associated with New York and Pennsylvania. The investigation also identified an active number traced to Kenya.
Researchers said phone conversations with some of the operators included delays associated with VoIP routing. They also found that some operators followed prepared scripts during calls.
The investigation’s intelligence and human-source work indicated that the campaign originates primarily from Kenya, although the researchers said the activity targets customers of several North American airlines and brands.
Check Point said some of the impersonation accounts existed before 2024, while most were created from 2024 onwards.
The company explained that the number of new accounts appearing each day suggests that the campaign remains active. Researchers also noted that the three scam methods documented in the investigation may not cover all the techniques being used.
The scammers pay close attention to the language and presentation used by legitimate customer service teams. On some accounts, they use official-looking logos, cover images and profile descriptions.
They also apologise for customers’ problems before asking them to continue the conversation through direct messages.
According to Lionel Dartnall, Country Manager, SADC at Check Point Software Technologies, public complaints give scammers information they can use to personalise their approach.
“Public complaints already provide useful context about the customer and their issue. AI can help turn that information into personalised responses quickly, allowing scammers to target more customers across more brands. For security professionals, this increases the need for continuous visibility into fraudulent accounts, brand impersonation, and other forms of external exposure,” Dartnall said.
Check Point noted that generative AI could make these scams easier to run at scale by helping attackers produce customer-service messages, adapt responses to individual complaints and communicate across languages. However, researchers did not confirm that the accounts examined in the investigation used AI.
Check Point’s advice to brands
The security company recommends that organisations monitor social platforms for accounts impersonating their brands and report them quickly.
It also wants companies to tell customers how legitimate support teams communicate and what information they will or will not request.
For complaints involving booking information, phone numbers or payments, Check Point recommends moving the conversation to official and secure support channels rather than handling sensitive information through social media.
It also recommends that companies work directly with social media platforms and payment providers to identify fraudulent accounts and transactions.
For consumers, the company advises contacting airlines through their official websites, verified social media accounts or known telephone numbers.
Customers should also be cautious when an account that responds to a public complaint asks for sensitive information or directs them to an unfamiliar payment service.
Legitimate customer support teams should not require passwords, one-time passcodes, gift cards, cryptocurrency payments or similar payment methods to process an ordinary refund.