Skip to content
Naked Security Naked Security

90% off Ray-Bans? It’s a 100% Instagram SCAM!

The ads look like they're been shared by friends, but they're really pod people who've hijacked accounts.

A scam ad for Ray-Ban sunglasses has been making the rounds on Instagram.

There are many versions, but they tend to feature the Ray-Ban logo and photos of sunglasses, along with the “whoa, what a crazy deal!” offers of “90% off”. We’ve seen one that dangles the cheap-cheap price tag of £17.65 (that’s US $22.13 – for glasses that typically go for over $100).

And of course, you better hurry, since this offer won’t last – it’s one day only! … And has been for a few weeks!

Not everybody is going to see the fake ads and write them off as being the scams that they are, unfortunately. After all, the ads bear the name of a (self-proclaimed) “official” website. Plus, you’ve likely seen these ads being posted by your Instagram friends.

Don’t fall for it, though. It seems too good to be true, which means it is.

(Watch directly on YouTube if the video won’t play here.)

Other fake-ad scams

It’s yet another example of fake ads doing the rounds on social media: we’ve seen an Adidas phishing scam that circulated on WhatsApp, offering “free” (nope!) shoes and money (double nope!). Scammers seem to have a bit of a fancy-footwear fetish: we’ve also seen bogus UGG outlet store scams on Facebook.

We’ve also seen online auctions for cutesy wutesy puppies and kittens that turned from “awww!” to “AAARRRGHHH!!!” in the blink of a scammer’s eye.

Those aren’t really your friends

The crooks behind scams like this often rely on compromised social media accounts to spread their fakery.

So, while it might look like your friends are urging you to take up an offer too good to ignore – it’s more likely to be a scammer who’s cracked their password so they can abuse the trust we place in our friends’ opinions.

That, in fact, is what happened to an Instagram celebrity, Lindsie Comerford, whose account – and then her bank account – was hijacked last year.

Account recovery: it’s like pulling teeth

Actually, recovering a hijacked Instagram – at least until Monday, when Instagram promised to make it easier – is more like painfully trying to pull teeth and then giving up because “72 hours later – still no account recovered!”

Comerford wrote a blog post about her hijacking ordeal.

Well, apparently to get a hacked account back I have got to email support and help 10 times, leave 3 voicemails, and report my account before I could reach a magical help screen that actually guides you towards getting your account back. Getting the help is no easy feat though and honestly it requires sheer digital magic.

Finally I reach Instagram; but only after trying to figure out how to navigate through my email account that has been switched to show only Turkish language.

It took three days of no help and still she didn’t get back her account. She wound up asking an ethical hacker to do it for her. Meanwhile, the crook took full advantage of all that time to first hack her email, and then her bank account, she said.

After a wave of complaints like that, Instagram is finally working on overhauling its kludgy response to hijacks. On Monday, it announced that it’s testing easier ways to get back hacked accounts, even if the attacker has changed a victim’s user name and contact data.

According to the BBC, the trial is of an in-app function through which users submit contact information associated with the account and then receive an access code.

For Android users, it also announced that it’s putting user names on the shelf, keeping them from being claimed for a “period of time” after account changes, whether those changes stem from a hack or the legitimate user doing a legitimate change.

This will hopefully bring much-needed help for users on Instagram, where hijacking has become a bit of an art form. As Vice has reported, hackers have been holding high-profile accounts to ransom for eye-popping prices: they can sell for up to tens of thousands of dollars on underground forums.

What to do?

If you see scam ads like these for Ray-Ban on your friends’ walls, let them know. If they didn’t post them, they’ll need to:

  • Change their Instagram password straight away – to something unique and strong.
  • Set up two-factor authentication (2FA) as well.
  • Review the access they’ve granted to third-party apps and services and revoke any that they don’t use or look suspicious. Go to Instagram Settings > Authorized Apps.

8 Comments

These scams are totally hilariously bad I have seen dozens of friends get hit by them and I have had sort them out to get some of the scams off their account and stuff I am sorta the anti-spam guy with all my friends

I was hit by this scam and my account has been locked, after 1 week still no assistance from Instagram any suggestions???

what happens when you went onto the website and entered your card details and purchased on it? Can they hack your bank account from there?

If you put your credit card details into a fake site, the crooks now have those details. So they could go to a real site and put those same details in…

…and they’d be correct. If you have entered your credit card data on a site you later realise was fake, I suggest you cancel your card and get a new one – even if the first crooks don’t use the data they got, they might sell the details on to someone else to use later. And watch your statements more carefully than usual.

I just discovered a joke of a fake Ray-Ban site, only online 7 days, 2021-04-21, that is having a 90% discount on all Ray-Bans that had the same price before the discount.

Each of the sunglasses on the site has a 5 star rating from the same number of reviews. The reviews are so off-the-wall, you feel like you entered the twilight-zone. From reviewers who treat their sunglasses like wallets or purses… use them as organizers to store files… to compliments that turn into complaints due to extreme damage when recieved, but ends in satisfied compliments.

Navigation on the site’s catalog pages are retarded. It has buttons to up or lower the price of the products (does nothing), and buttons to sort them for new or bestselling that are also nonfunctional.

On the bottom of the site is the usual follow buttons for Facebook, Twitter, Pinterest, Email, and the extinct Google+, that when clicked strangely sends you to this site’s homepage.

The site also recruits resellers, but this is only mentioned on their badly written privacy page, which is strangely dedicated to signing-up resellers, with no instructions on how to sign-up to be one, but talks about a live sales representative that will help you get started, who is no where to be found on the site.

The con-artist who created this stupid site is so scatterbrain, you feel like giving him your money.

Comments are closed.

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
You’re now subscribed!