Modus Operandi of the Nasty List scam is proliferating through Instagram accounts pilfered by cybercriminals. They send messages to followers with claims of being included in a temporary list ominously dubbed 'Nasty List'. These messages read something like 'OMG, you're actually on here, @TheNastyList_34, your number is 15! It's really messed up .'
Messages sent to the pilfered account
As per shared screenshots, hackers dispatch these messages to all followers of the compromised account.
If an individual receiving a message sent by the hacker accesses the displayed profile, it will be named something like 'The Nasty,' 'Nasty List,' or 'YOU'RE ON HERE!!'. Profiles include a description resembling 'Everyone is really putting us all in here, I'm at position 37. If you're reading this, you're probably here too' or 'WOW, you're really here, ranked 100th! That's terrible, WHAT ARE YOU WAITING FOR? CHECK OUT THE TOP 10!' as shown below.
Illustration of the Deceptive Nasty List Profiles
These profiles include descriptions along with a link allowing you to view this Nasty List and the reasons why you're on it. For instance, the aforementioned profile is using the URL nastylist-instatop50[.]me. Upon accessing this link, a login page resembling the official Instagram page appears.
Fake Instagram Login Page
Although the login page above may seem authentic, it's crucial to pay attention to the URL displayed at the top of the window, identified by the red arrow in the image above. As you can see, this login page is actually located at the address nastylist-instatop50[.]me, clearly not the legitimate Instagram site.
To avoid falling victim to scams like the Nasty List, if you're on a page that is not instagram.com, never enter your account login information.
What to do if your account is stolen by the Nasty List?
If your account falls prey to the deceptive 'Nasty List' scam but you still have access, the first step is to verify if your account is using the correct phone number and email address.
Check by navigating to your profile and selecting Edit Profile. Scroll down to view your email and phone number. If incorrect, update the information accordingly.
If both the email and phone number are correct, for added assurance, change your password. After changing your Instagram password, all current devices logged into your account will be logged out. Re-login to Instagram at that point to regain control of your account.
If you're unable to access your account after it's been compromised, report the issue to Instagram.
Download Instagram on Android and iOS devices here.
- Download Instagram for Android
- Download Instagram for iPhone
https://Mytour.vn/deceptive-practices-nasty-list-instagram-24781n.aspx
To enhance the security of your Instagram account, check out the Instagram two-factor authentication method here.