Threat Intelligence Directory
Phishing

Social Media Account Recovery Phishing

Attack Trigger

Fake account suspension or policy violation notice forces the victim to log in through an attacker-controlled page

What Attackers Want

Social media account credentials, linked payment methods, and follower base

How This Attack Works

Attackers send emails or DMs impersonating Facebook, Instagram, TikTok, or YouTube claiming the victim's account will be permanently deleted due to a policy violation or copyright strike. The appeal link leads to a fake platform login page that captures credentials and sometimes phone numbers for 2FA interception.

Red Flags to Watch For

  • Sender is not from an official @meta.com, @facebook.com, or @instagram.com address
  • Appeal link does not go to the platform's official domain
  • Email threatens permanent account deletion within 24–48 hours
  • The page requests your password to "file an appeal"
  • Copyright or policy violation mentioned refers to content you do not recognize
  • A two-factor code is requested on the fake page — enabling real-time account hijack

Known Malicious Domains

These domains have been associated with this attack. Never click links going to these addresses.

  • facebook-appeal-form.comMALICIOUS
  • instagram-account-disabled.netMALICIOUS
  • meta-policy-violation-appeal.comMALICIOUS
  • tiktok-account-suspended.netMALICIOUS

Glance automatically blocks emails from domains on this list. Domain list is not exhaustive — attackers register new domains continuously.

How Glance Stops This

  • Domain similarity analysis catches lookalike sender addresses at millisecond speed
  • SPF / DKIM / DMARC validation flags authentication failures before you ever see the email
  • VirusTotal + Google Safe Browsing checks every link in real time
  • Urgency language detection scores the email higher for manual review
  • Known malicious domain blocklist updated continuously from live scan data

Don't wait to get hit.

Glance scans every incoming email against 12 detection layers — including the exact tactics described above — before it reaches your inbox.

Protect My Inbox — Free