Example of a social media impersonation scam where a fake bank page used a “like” to deceive customers without posting a comment.The Social Media Scam We Didn’t See Coming

And Why It Changed How We Think About User-Generated Content

If you’ve worked in banking long enough, you develop a pretty good radar for nonsense.

You know what spam looks like.
You know what a bot reply sounds like.
You know which comments are just noise — and which ones deserve attention.

When it comes to social media, most banks have learned the usual patterns. We’ve all dealt with the sketchy link, the fake reply, the comment that clearly doesn’t belong.

That’s why what we saw in December stopped us in our tracks. This incident was a reminder that bank social media scam tactics are evolving in quieter, more subtle ways than many institutions expect.

Not because it was loud.
But because it was quiet.

The Risks We’ve Learned to Watch For

Traditionally, user-generated content (UGC) risk shows up in ways that are hard to miss.

A customer leaves a comment on a bank post.
A bot jumps in with a reply.
Then another.
Then several more.

It’s disruptive and sometimes frustrating, but at least it’s visible. There’s something concrete to review. Something to remove. Something you can point to and say, “Yes — we caught that and handled it.”

Most banks have built their monitoring around this kind of activity. And for a long time, that approach made sense.

Until it didn’t.

The December Moment That Changed the Conversation

In this case, there was no reply.
No comment.
No obvious red flag sitting in the thread.

Instead, a scammer created a fake Facebook page that looked remarkably like the bank’s real one. Same logo. Same branding. Same name — almost.

Then they did something most banks would never think twice about.

They liked a customer’s comment.

That’s it.

At first glance, there’s nothing to review. No one is scanning “likes.” No one expects a problem there.

But when the customer received the notification, what they saw wasn’t harmless.

It looked like the bank had interacted with them — and the page name included a message. Something along the lines of:

“ABC Bank – You Have Won”

No comment appeared publicly.
No link was posted in the thread.
Nothing obvious surfaced for the bank team to review.

But from the customer’s perspective, it felt personal. It felt legitimate. And it felt connected to their bank.

That’s the moment where trust gets leveraged.

Why This Flew Under the Radar

Here’s the uncomfortable truth: no bank is reviewing every reaction on its social media pages.

And frankly, no examiner expects that.

Banks focus on comments, replies, and messages because that’s where risk has historically lived. This tactic didn’t rely on any of those traditional review points. It relied on association — the credibility that comes with a bank’s name and logo.

There was nothing obvious to moderate. Nothing that triggered a workflow. Nothing that raised an immediate red flag.

But the brand association was already doing the damage.

“This was one of those moments where you realize the risk didn’t change — the tactic did. And that means our assumptions have to change too.”

— Jill Williams, Founder, Bank Monitor

The Compliance Question Beneath the Surface

From an examiner’s perspective, the issue isn’t whether the bank created the content. It’s whether the bank understands — and can explain — how activity on its social media channels is monitored and managed.

Examiners don’t usually ask:

  • Did you post this?

They ask:

  • How do you monitor third-party activity?
  • How do you identify impersonation attempts?
  • How do you document what you review?
  • How do you respond when something creates potential customer harm?

When activity is visible on a bank-controlled channel, “we didn’t see it” can become a very uncomfortable answer.

Where a Lot of Banks Feel Confident — Until They Shouldn’t

Many banks feel covered because they:

  • Monitor comments
  • Remove obvious spam
  • Rely on alerts or notifications
  • Use tools that capture bank-created posts

And most of the time, that has been enough.

But this situation exposed a gap that isn’t about effort — it’s about assumptions. The assumption that risk will always show up in familiar places. The assumption that impersonation will be obvious.

Scammers don’t work that way anymore. They look for credibility, proximity, and subtlety.

What We Did When We Saw It — And Why That Matters

When this activity surfaced, our first reaction wasn’t panic — it was pattern recognition.

Once the impersonation account was identified, it was immediately added to our internal Bad Actor list. That action didn’t just block the account for the affected bank — it prevented that same impersonation from interacting with any of our bank clients’ social media pages going forward.

That step mattered for two reasons.

First, it addressed the immediate risk for the bank involved.
Second, it acknowledged a reality banks are increasingly facing: scam activity rarely targets just one institution.

These accounts are often reused, rebranded, and redeployed across multiple pages. Treating them as isolated incidents misses the broader pattern.

The takeaway isn’t that every bank needs the same tools or workflows. It’s that learning from one incident should strengthen protections everywhere, not just where the issue was first spotted.

That’s how real risk management works in practice.

Rethinking What “Good Oversight” Really Means

This isn’t about chasing every interaction or policing social channels to death.

It is about asking better questions:

  • Are we monitoring user-generated activity — not just our own posts?
  • Would we recognize impersonation if it didn’t come in the form of a comment?
  • Can we clearly explain our monitoring process if an examiner asks?
  • Are we documenting review and response in a way that holds up over time?

Mature programs don’t just respond to incidents — they learn from them and adjust controls accordingly.

A Simple Gut Check

If this exact scenario happened on your bank’s page tomorrow, could you confidently answer:

  • How it would be detected?
  • Who would review it?
  • What action would be taken?
  • How it would be documented?

If your answer is “probably” or “I think so,” that’s usually a sign it’s worth taking a closer look.

The Bigger Takeaway

User-generated content risk isn’t just increasing — it’s evolving.

The most problematic activity isn’t always the obvious spam that jumps out at you. It’s the quiet, believable interaction that borrows your brand credibility and slips past normal review points.

The goal isn’t perfection. It’s awareness, defensibility, and confidence — especially when someone across the exam table says:

“Walk me through how you manage this.”

That’s the standard worth aiming for.


Ready to See the Difference?

If this scenario made you pause — or made you rethink how user-generated content is monitored on your bank’s social media channels — you’re not alone. These are exactly the kinds of issues we help banks navigate every day.

I’m always happy to talk through what you’re seeing, answer questions, or help you assess whether your current approach would stand up to examiner scrutiny.

📩 Email: jill@springmediasolutions.com
📞 Call or Text: 318.243.1076
📆 Schedule Your Free Social Media Compliance Assessment

Schedule here →

BANK MONITOR
Trusted by Banks. Built for Examiners. Managed by Experts.


Sources

The regulatory guidance below is helpful context for how financial institutions are expected to identify, monitor, and manage compliance, operational, and reputation risks related to social media activities.