Guides
Part of Social posts and viral claims: a verification guide
How to check an unfamiliar account and viral post
Account and viral-post verification workflow for confirming identity, tracing origin, checking links and claims, contacting owners, and reporting safely.
What to take away
- Start from the exact post and preserve its live context.
- Confirm identity through channels the account does not control alone.
- Inspect destinations without trusting links or phone numbers in the message.
- Find the earliest content source and map every repost.
- Separate a hacked real account from a lookalike account.
An urgent post from a familiar logo can exploit recognition before a reader notices the handle. The same message can come from a new impersonator, a compromised real account, a copied screenshot, or an authorized account making an error. Identify which situation exists before describing motive or ownership.
Photo and credit
The scene provides communication-work context. It does not depict a social platform or imply that any named person is connected to online fraud.
1. Preserve before interacting
Save the post and profile URLs, handle, display name, account identifier, timestamp, text, media, linked-domain text, visible badges, follower count, relevant replies, and how the post reached you. Take screenshots and save the page according to newsroom policy.
Do not click a shortened or suspicious destination in an ordinary browser. Do not call the number or email the address supplied in the post to confirm the post. That returns control to the possible impersonator.
2. Compare the claimed identity
Find the person or organization's independently known website, filing, staff directory, prior press material, or confirmed contact. Look for links to official social accounts. Compare exact handles character by character, including punctuation, substituted letters, extra words, and Unicode lookalikes.
Review account history for creation date, previous names where visible, long-term posting pattern, language, geography, colleagues, and links. A new account is not automatically false, and an old one is not automatically safe. Old accounts can be sold or taken over.
3. Determine account type and current control
Classify the candidate:
- established official account under normal control
- established account with possible compromise
- unauthorized lookalike or clone
- declared parody, fan, or commentary account
- automated or organizational account with a platform label
- identity unresolved
Contact the owner through a previously published phone number, official website form, known email, or trusted representative. Ask whether the account and specific post are authorized. Preserve the reply and the route used to authenticate it.
4. Inspect the message safely
Write the requested action: click, pay, download, disclose credentials, move to private chat, call, share, evacuate, or invest. Expand and examine domains through safe newsroom procedures. Compare registration, spelling, certificate, redirect, and page branding with the known organization, but remember that attackers can copy design.
The FTC's business impersonator scam guidance warns that unexpected social messages may imitate a known company, invent an account problem or prize, and direct people to supplied links or phone numbers. Its advice to avoid those routes supports independent contact as both a safety measure and an identity check.
Never enter credentials or personal information during verification. Escalate malware, credential theft, or active fraud to security staff and the relevant platform.
5. Trace the post and attached media
Search exact wording and distinctive errors. Reverse-search images and video keyframes. Compare timestamps and edits. Find whether the account created the material, copied another post, quoted a private message, or uploaded old content with a new caption.
Build a chain table with account, time, content changes, evidence added, and link destination. A repost that changes "may close" to "is closed" creates a new claim. Verify that version separately.
6. Check the underlying claim
Use records and people who can establish the action, not only the claimed speaker. For an evacuation, find the current order and emergency authority. For a product recall, find the regulator and manufacturer notice. For an investment pitch, check registration and filings. For a quotation, find the full recording.
Ask the named party for a response and a safe public contact readers can use. If control of a real account is disputed, avoid publishing private recovery details that could assist attackers.
7. Publish the component result
Describe the handle exactly, but do not create a clickable route to active fraud unless public-interest reasons outweigh the risk. Explain whether identity, control, post authorization, media context, and claim accuracy were confirmed.
Use a correction plan for articles, embeds, screenshots, push alerts, newsletters, and partner feeds if the account changes, deletes the post, or recovers from takeover.
Common questions
Is a typo in a handle proof of impersonation?
No. It is a strong reason to compare the account with independent official channels and contact the named party.
Can a real account be hacked?
Yes. Long history and a genuine badge do not prove the owner authorized a current post.
Should I message the suspicious account for proof?
You may ask questions without sharing sensitive details, but confirm identity through a separate, independently obtained route.
Is deleting the post evidence of guilt?
No. Posts are removed for many reasons. Preserve the event and seek an explanation without inferring motive.