A message from a familiar person urgently requesting to borrow money. A link to an allegedly sensational video. An investment offer promising quick profit. Such situations seem familiar to many today, but not everyone realizes that behind them are not only simple internet scammers but also professionally organized cybercriminal groups. Experts warn: even a very strong password is no longer sufficient protection, and the greatest weapon against users is increasingly psychological manipulation.
Read more After the nationalization of «British Steel,» China’s «Jingye» threatens legal action

Only part of the problem
According to Justina Paulauskaitė, hacking into social media accounts is a very common and well-organized phenomenon today. Cybercriminals have turned account theft into a serious business: special programs are used that massively test leaked passwords or conduct automated phishing campaigns. “Hackers today operate like a business – they automate processes, massively check passwords, and look for the weakest points. One successful login can open the way not only to a person’s social media but also to their email, banking data, or even workplace systems,” explains the specialist.
According to the interviewee, stolen accounts are mostly used for financial fraud. After hijacking a profile, criminals send messages to the person’s friends asking to urgently lend money, make a transfer, or click a link. Since the message comes from a familiar person’s account, victims often do not doubt its authenticity.
However, financial fraud is only one side of the problem. Hacked accounts are also sold on the black market, used to spread spam and malicious links, and sometimes become a tool to damage a person’s reputation. Hackers can post offensive messages, change profile information, or use the account for other scams.
A reliability indicator
So-called mature accounts – profiles used for a long time with a large audience of friends or followers – are especially valuable to criminals. Such accounts inspire more trust, making them a very effective tool for social engineering. “When people receive a message from a known person or public figure’s account, they are much more likely to click links, open files, or even make money transfers. Scammers take advantage of this,” says the expert.
Moreover, social media algorithms respond more slowly to suspicious activity on verified accounts, giving hackers more time to carry out attacks. Sometimes accounts of well-known people also become objects of blackmail – large ransoms are demanded for their return.
The expert emphasizes that today the “verified” badge is no longer a guarantee of reliability. Platforms like Meta or X have started offering blue checkmarks as a paid feature, so they often indicate a subscription rather than a person’s trustworthiness.
“A person receives a question: ‘Is that you in this video?’ Clicking the link opens a fake login page where the entered data instantly falls into the hands of scammers.”
Creating an illusory closeness
The most common scam schemes using stolen accounts remain quite similar. One of the most popular is fake investments, usually related to cryptocurrencies. Scammers announce an alleged opportunity to get rich quickly and lure people into fake investment platforms.
Messages with alleged videos or photos are also common. A person receives a question: “Is that you in this video?” Clicking the link opens a fake login page where the entered data instantly falls into the hands of scammers.
Another widely used scheme is fake charity campaigns or contests. People are invited to donate to an allegedly noble cause or pay a “delivery fee” to claim a non-existent prize.
Why do many people so easily believe such messages? According to J. Paulauskaitė, the so-called authority effect comes into play – people tend to trust well-known, visible, or successful individuals more. “If a person is a famous athlete, performer, or opinion leader, we subconsciously tend to believe they can be trusted in other areas as well. Social media also creates an illusory closeness – it seems like we know the person personally, although we have never actually met them,” explains the expert.
Read more Award for merits in India-Lithuania friendship presented in Rusnė
They enter the data themselves
Hackers gain access to accounts in various ways. One of the oldest is password guessing or “brute force” attacks, where special programs automatically try thousands of combinations until they find the right one.
However, today a much greater threat comes not from technical but psychological attacks. One of the most common is “phishing,” a scam attack where a person enters their login data on a fake page themselves.
J. Paulauskaitė also warns about malware and “stealers.” They often spread through unofficial apps, game modifications, or pirated software. Such viruses can steal passwords saved in the browser, session cookies, and other sensitive data.
A big problem remains the use of identical passwords. If the same password is used on several platforms, hacking one system allows criminals to easily access other accounts.
Recently, artificial intelligence has been increasingly used. According to the expert, scammers are already creating very convincing emails, voice fakes, and “deepfake” videos that allow impersonation of another person.

How to protect yourself?
The most important protective measure named by J. Paulauskaitė is multi-factor authentication (2FA or MFA). This method requires not only a password but also additional verification, for example, a code generated on a phone or biometric confirmation. “Even if a hacker learns your password, they will not be able to log into the account without the second verification factor. This is one of the most effective protective measures today,” says the specialist.
She also reminds that a strong password alone is no longer sufficient protection. Even the most complex password will not help if a person enters it on a scammer’s fake page.
It is equally important to critically evaluate all received messages, check internet addresses, avoid clicking suspicious links, and never disclose SMS or authentication codes to anyone. If a friend on social media asks for money, it is recommended to call or contact them by other means first.
If the account has nevertheless been hacked, experts advise immediately changing passwords, logging out of all devices, enabling two-factor authentication, and informing friends and followers about possible fraud. It is also necessary to check the email account, linked payment cards, and review active login sessions.
According to the specialist, the most important thing is to understand that today anyone can become a target – regardless of age, profession, or number of followers. Therefore, vigilance on the internet is no longer a choice but a necessity.

The project “Fake? Check it!” is partially funded by the Media Support Fund. 9,000 euros allocated in 2026.
Read more Linas Linkevičius. No one prepared the Russians for such a crisis