A warning post from communications strategist Lulu Cheng Meservey went viral on X in early August, and it has founders, executives, and security teams paying close attention. The post describes a scam that has been working its way through the startup and crypto world, a message that looks like a request from a reporter at a major outlet, but is actually the start to a credential-theft attack.

 

Lulu Cheng Meservey's warning post, which brought widespread attention to the scam.

According to the post, the target receives a direct message from someone claiming to be a journalist at a recognizable outlet, most often Bloomberg or TechCrunch. The message is specific and it references the target's work and invites them to be interviewed for an upcoming story. Once the target responds with interest, they are directed toward what looks like a scheduling page. That page asks them to log in with Google, and that login prompt is where the theft happens.

 

The impersonation is more convincing than it should be

What makes this scam effective is the quality of the fake persona behind it. In one screenshot circulating alongside the original post, the account presents itself as a Bloomberg correspondent, complete with a bio, a photo, a plausible follower count, and posting history that mirrors what a real journalist's profile looks like.

  

A fabricated Bloomberg correspondent profile used to approach targets on X.

  

The initial direct message, styled to read like a routine interview request from a business reporter.

This is not an isolated report. Investor Carlos Domingo commented that he was approached the same way but declined once he was unable to verify the person's identity, he noted that the account behind the attempt has since been suspended. His experience matches a pattern others described in the replies, the message looks routine up until the target tries to confirm who they are actually talking to.

  

Carlos Domingo describes being targeted by a nearly identical impersonation attempt.

 

The tactics keep changing

Several replies to the original post point to how far attackers have refined this approach. One user, Nick Foley, mentioned that clicking through revealed a message telling him he had failed a simulated phishing test run by his own organization. In the same thread, Nic Carter described an escalation of the tactic whereby attackers sometimes move targets onto a fake video call with no working audio, then ask them to download a Zoom update to fix it. That download is the credential harvesting method.

  

Replies describing a simulated internal phishing test and a related fake video-call tactic.

Author and systems architect Daniel Jeffries added that he was caught by an earlier version of this scam roughly three years ago. In his case, the link led to a fake Calendly page designed to gain access to his X account; once compromised, his bio was briefly changed to promote a cryptocurrency token.

  

Daniel Jeffries recounts a similar attack from several years earlier.

That detail matters, because it points to the motive behind many of these attempts. Andrew Hires described the pattern as a familiar one from crypto-focused attackers who compromise accounts to promote fraudulent tokens, and suggested this fake-journalist approach may simply be a new entry point for an established playbook. 

A reply noting the connection to established account-takeover and token-promotion scams.

 

Why people still fall for it

Andrew Conner, another commenter, made an observation that applies to not just this scam, when he asked a follow-up question, the response he got back was nothing like how an actual reporter would engage. He noted that the scam succeeds in part because it relies on people not knowing how journalism actually works.

  

A reply pointing out how the scam exploits unfamiliarity with normal press outreach.

Another reply summed up the defensive posture worth adopting, treat any unsolicited outreach through a social platform's direct messages the way you would treat spam, and expect a legitimate reporter, recruiter, vendor, or partner to reach out through a verifiable channel instead.

  

A reply recommending that cold outreach through social media DMs be treated with the same skepticism as spam.

 

The same playbook targets healthcare organizations, just through email

The same tactics show up in the inboxes of hospitals, clinics, health plans, and business associates. Swap "reporter" for "auditor," "recruiter," "vendor," or "health system representative," and the attack looks identical, a plausible message, a request to move to a second step, a login page or file download that harvests credentials instead of delivering what was promised.

In healthcare, the stakes of that credential theft are higher than a hijacked social media bio. A compromised email account at a covered entity or business associate can expose electronic protected health information, trigger breach notification obligations under HIPAA, and lead to regulatory penalties, not to mention the damage to patient trust.

In late 2024, Numotion, a wheelchair and mobility equipment provider, discovered that several employee email accounts had been compromised after staff responded to phishing emails between September and November 2024. The breach was first reported to regulators in March 2025 as affecting roughly 494,000 individuals, though that number was later revised up to 529,004. The attackers accessed names, dates of birth, product and payment details, health insurance information, and medical information. The entry point wasn't a technical exploit, it was one or more employees trusting a phishing email enough to act on it, exactly the mechanism behind the fake-reporter scam described above.

Read also: Top credential harvesting techniques

 

What healthcare organizations and execs can take from this

A few takeaways translate from this scam to healthcare email security:

  • Verify identity through a second, independently confirmed channel before clicking any link in an unsolicited message, no matter how credible the sender's profile looks.
  • Treat login prompts triggered by an email or DM link as a red flag, especially when they ask for credentials to an account you were not expecting to use.
  • Use email security tools that authenticate senders and flag look-alike domains and spoofed display names before a message reaches an inbox.
  • Run regular, realistic phishing simulations so staff recognize social engineering patterns, not just obvious spam.

Read also: Secure, HIPAA compliant email for healthcare

 

FAQs

What is social engineering?

Social engineering is the use of psychological manipulation, such as flattery, urgency, or authority, to trick someone into handing over information or access rather than breaking in through a technical flaw.

 

What is phishing?

Phishing is a social engineering attack delivered through a message, usually email, that impersonates a trusted sender to get the recipient to click a malicious link, download malware, or hand over credentials.

 

What is spear phishing?

Spear phishing is a targeted version of phishing aimed at a specific person or organization, often using personal or professional details to make the message more convincing.

 

What is credential harvesting?

Credential harvesting is when an attacker uses a fake login page to capture a victim's username and password so they can access real accounts later.