Scammers are exploiting Meta's automated Instagram copyright-reporting workflow to submit false ownership claims, triggering removal of legitimate content and temporary suspension or disabling of creators' and businesses' accounts. The perpetrators then contact victims, commonly through Telegram, and demand cryptocurrency in return for withdrawing the strikes; victims have reported lost brand contracts and repeated targeting even after payment.
The Delhi High Court has separately questioned Meta over alleged abuse of its Rights Manager tool, including claims that scammers registered creators' original videos and used them to strike the creators' own accounts. Meta said it restored content in reviewed cases and introduced unspecified protections, while maintaining that Rights Manager can detect matching material but cannot determine infringement; the court directed restoration where ownership can be proved. Affected users should preserve evidence, use official Instagram appeal and support channels, avoid extortion payments, and remain alert to related credential-phishing attempts.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
Abin Tom Sebastian, who operates the Morbid Kuriosity Instagram account, said fraudulent copyright-strike complaints and Meta's inadequate resolution process caused him to lose crucial brand contracts to another creator.
After reviewing accounts identified by the BBC, Meta restored affected content and said it added unspecified protections intended to prevent similar fraudulent copyright-reporting attacks. Meta also said it combats deceptive behavior designed to scam users.
Delhi High Court Justice Anup Jairam Bhambhani questioned Meta about access restrictions, eligibility criteria, and policies for its copyright-management tools following allegations of fraudulent Rights Manager claims. The court directed Meta to restore content removed through fraudulent strikes where Mohit Kumar can establish ownership.
Meta admitted in a Delhi High Court matter that 13 copyright-strike notices against Saurabh Maurya's @iitian_trader_official Instagram account were fake and restored the affected content.
Sumedha Bhattacharyya reported that Instagram disabled her account after eight copyright reports against content she owned. The purported rights-holder identities used variations of her YouTube channel name, TheSumedha14, and five unrecognized Outlook addresses.
Instagram removed creator Shobhit Bakliwal's video containing political commentary about Gautam Adani after a reportedly fake copyright notice was sent from an impersonated Japanese-language email address.
Shyam Meera Singh said Meta removed his reel about Prime Minister Modi following an allegedly fraudulent copyright notice submitted in his own name. He alleged the claim used the email address bjp.olny@outlook.com.
Creator Mohit Kumar alleged that scammers registered his original videos in Meta Rights Manager and used fraudulent claims to strike his @risewithmohit Instagram accounts. Meta said it reinstated his content and that his accounts had not been suspended.
A history-focused Instagram account owner received repeated copyright claims from the same email address and paid $50 in cryptocurrency because Meta's resolution process was expected to take weeks. The scammers immediately targeted the account again after payment.
Scammers submitted fraudulent copyright complaints through Instagram's legitimate reporting system, causing targeted accounts to be suspended or disabled after repeated strikes. They then contacted victims through services including Telegram and demanded cryptocurrency payments to withdraw the complaints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcebbc.co.uk
Open sourcemedianama.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.