Scammers have finally found the one DM that gets people to panic-click faster than “free Nitro” or “your ex uploaded something.” It’s four words: “you’ve been reported.” Two decades of platforms training users to fear the moderation queue, and it turns out that manufactured fear beats manufactured greed every time. That’s the quiet joke buried in Malwarebytes’ new writeup on the Reddit and Discord false report scam, and it’s worth sitting with because it says something uncomfortable about how cybersecurity actually fails in practice: not at the firewall, not at the server, but in the half-second between “I got a scary message” and “I typed in my code.”

Reddit app icon representing account takeover scam targeting users with false report claims
The false report scam turns a platform’s own anti-abuse system into the lure.

The mechanics are almost insultingly simple, which is exactly why they work. A message lands, usually from an account dressed up to look like staff or a concerned “witness,” claiming you’ve been reported for something serious: harassment, CSAM, doxxing, whatever gets the adrenaline moving fastest. It comes with a link to “verify your account” or “appeal the report” before some deadline. The link leads to a convincing clone of the real login flow. You enter your username and password. Then it asks for the code your authenticator app or SMS just sent you, because of course it does, that’s what a real login screen would ask for too. Except this one is relaying that code straight to the attacker in real time, who’s using it to log into your actual account before the code expires.

The Cybersecurity Blind Spot Trust and Safety Teams Accidentally Built

Here’s the part that should bother security teams more than it does. Reddit and Discord spent years building genuine trust and safety infrastructure: report buttons, moderation queues, ban appeals, the whole apparatus. Users were told, correctly, to take these systems seriously. That training is exactly what makes the scam work. You can’t out-engineer a threat that’s exploiting a behavior your own product deliberately cultivated. This isn’t a technical vulnerability in the traditional sense; there’s no CVE, no patch, no firewall rule that stops it. It’s a trust exploit dressed up as a compliance workflow, and it’s a reminder that cyber security programs that only model technical attack surface are missing half the board.

It also explains why this scam disproportionately hits people who’d otherwise consider themselves careful. Security-aware users are, if anything, more likely to take a report notice seriously and act on it fast, because they’ve internalized “don’t ignore official-looking security messages.” The scam weaponizes good instincts against a bad UI.

Why MFA Didn’t Save Anyone Here

Multi-factor authentication gets sold as the thing that stops account takeover. It does, against the attacks it was designed for: credential stuffing, brute-force login attempts, password reuse. It does nothing against a real-time phishing relay, because the victim is doing the authentication themselves, correctly, against a page that’s just forwarding everything to the attacker’s actual login session a few seconds later. One-time codes delivered by SMS or TOTP app are phishable by design; the code doesn’t care who typed it in, only that it arrived within the validity window.

This is exactly why phishing-resistant MFA, meaning FIDO2 security keys or passkeys bound to a specific origin, exists as a distinct category from “any MFA.” A hardware key or passkey checks that the domain requesting authentication actually matches the real service. A cloned login page fails that check silently, before the user ever has a chance to hand anything over. If your organization is still treating “we have MFA” as a finished sentence, this scam is the argument for finishing it.

What Actually Reduces the Blast Radius

None of this means MFA is worthless or that user training is a lost cause. It means the response has to assume some percentage of people will click, every time, no matter how good the training is. Plan for that instead of pretending it won’t happen.

  • Move high-value accounts, admin consoles, and anything tied to community moderation to phishing-resistant MFA (security keys or passkeys), not just app-based codes.
  • Build a fast session-revocation and password-reset path into your incident response playbook specifically for social platform accounts, not just corporate SSO. A compromised community Discord server is a brand and supply-chain risk, not a personal inconvenience.
  • Turn on login alerting everywhere it exists. Threat detection doesn’t have to mean a SIEM; a “new device signed in” email that people actually read is threat detection.
  • Teach the one rule that survives panic: legitimate report and moderation systems never ask you to log in through a link in a DM. They live inside the app you already have open.
  • Treat “urgent, scary, time-limited” as the tell, regardless of platform. That pattern is the actual signature, not the specific wording.

On the infrastructure side, this is also a good moment to check that basic security hardening hasn’t quietly lapsed while everyone was busy worrying about exotic threats. Defense in depth still means something boring: rate-limit and monitor login attempts on anything you control, keep threat-protection rules current on exposed services, and don’t assume brute-force defense is someone else’s job because your MFA “handles it.” Tools like IPBan Pro exist precisely for the mundane, unglamorous layer of this problem, blocking repeated bad login attempts on your own servers, and that layer still matters even when the flashiest attacks of the week are social engineering rather than credential stuffing. Defense in depth means both layers get attention, not just whichever one made headlines this week.

The Part Platforms Keep Getting Away With

The uncomfortable truth is that Reddit and Discord’s own reporting and moderation systems are opaque enough, and appeals slow enough, that a fake urgent notice is plausible. Real moderation actions on these platforms genuinely can feel arbitrary and poorly explained, which is exactly the soil this scam grows in. If platforms want fewer users falling for fake report notices, the fix isn’t just a blog post telling people to be careful. It’s making the real process transparent enough that a scam impersonating it looks obviously wrong by comparison. Until then, security teams whose employees use Discord or Reddit for community support, dev channels, or customer engagement should treat those accounts as part of the attack surface, not personal business that stops at the office door.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.