Truviss

Tag: Social Media Monitoring

  • The DM-to-Order Reels Selling Fake Shoes

    The DM-to-Order Reels Selling Fake Shoes

    Home/Blog/The DM-to-Order Reels Selling Fake Shoes
    Social Media

    The DM-to-Order Reels Selling Fake Shoes

    Catch counterfeit selling before it reaches DMs

    Truviss’s Social Media Monitor flags accounts and content trading on your brand across Instagram, YouTube, TikTok and more.

    Book a demo
    DM to Order counterfeit selling cover
    TL;DR
    • A recurring Reels/Shorts format: a shopkeeper pans across branded-looking shoes, flashes a discounted price on screen, captions it “DM to order.”
    • The actual sale happens entirely in private messages, so there’s never a public listing to screenshot or report.
    • The video reads as organic local-shop content to recommendation algorithms, not an ad, so it spreads the same way genuine bargain-hunting content does.
    • Marketplace-focused brand monitoring never sees this, because nothing here ever touches a marketplace.

    A Ghost Data study reported by NBC News in 2019 found counterfeit-linked Instagram accounts for luxury brands, Gucci, Chanel, Balenciaga, Louis Vuitton and Dior among them, had nearly tripled in three years, from around 20,000 accounts in 2016 to over 56,000. More recently, in May 2026, City of London Police raided a warehouse in Rotherham and seized more than 26,000 counterfeit items, plus roughly £1.16 million ($1.5 million) in suspected stolen clothing, after finding a suspect livestreaming the sale of counterfeit goods on TikTok Shop. Consumer-safety coverage of this pattern has been thorough for years: spot the red flags, don’t pay through CashApp or Venmo, check reviews before you buy, use reverse image search on the product photos. What almost none of that coverage addresses is the other side of the same problem, what a brand is actually supposed to do about it, and why the usual brand-protection playbook doesn’t reach this format at all.

    The mechanism, shot by shot

    The format repeats often enough to describe almost frame by frame. A phone camera pans slowly across shelves or a table stacked with shoeboxes and pairs on display, sometimes inside a small shop, sometimes what looks like a home storeroom. A price flashes as on-screen text, usually crossed out against a higher “original” price beside it. The brand’s name might be spoken in the voiceover or shown briefly in a logo close-up, rarely spelled out in the caption itself. The caption ends with some version of “DM to order,” “price in inbox,” or a WhatsApp number. The comment section fills with past buyers replying “sent 🙏” or “arrived, thanks bro,” which reads as social proof to the next person scrolling past, and costs the seller nothing to generate.

    None of this is unique to shoes or to any one platform. The same shape shows up across counterfeit apparel, accessories, electronics, wherever a physical product photographs well and a discount is the obvious hook. What makes it worth naming as its own pattern isn’t the product category, it’s the structural choice sitting underneath all of it: the actual transaction never happens anywhere public.

    Why the sale never becomes a reportable listing

    A public listing with a price and a “buy now” button is exactly what marketplace and social-commerce monitoring is built to catch, a specific product, a specific price, a specific seller account, all sitting somewhere a brand can screenshot and report. Moving the transaction into direct messages removes all three from anything publicly visible. There’s no fake product listing to flag, no storefront page to send to a platform’s brand-abuse team, and no public price to prove the product was ever claimed as genuine, only a video that, read literally, shows a shop and some shoes without a single written claim of authenticity.

    This is the same underlying deception as any other counterfeit sale. What’s changed is that it’s been restructured so it never generates the one artifact, the listing, that makes a fake listing reportable in the first place. A seller doesn’t need to be more careful about hiding evidence when the evidence was never created publicly to begin with.

    Why the algorithm helps, not just the seller

    A Which? investigation found 23 of 34 cosmetic products it bought across Amazon, eBay, TikTok Shop and Vinted were likely counterfeit, including five of six bought directly through TikTok Shop, evidence the pattern already extends well beyond shoes into any category that photographs well on a phone camera. Short-form recommendation systems reward watch time and engagement, not verified authenticity of what’s on screen. A video of a shop full of steeply discounted branded-looking shoes performs exactly like any other bargain-hunting or local-business content, gets the same recommendation boost, and reaches viewers who never searched for it in the first place. The comment section’s “sent, thanks” replies read as genuine customer testimonials to anyone scrolling past, which pulls more DMs in without the seller doing anything beyond posting the next video. The platform’s own incentive to keep people watching works in the seller’s favour here, not against them.

    See how Truviss monitors social content and comments, not just storefronts and listings.

    Explore Social Media Monitor

    The blind spot in brand-side monitoring specifically

    Most brand-protection monitoring is built around marketplace monitoring, scanning listings, prices and seller accounts on e-commerce platforms. A DM-to-order video on a short-form platform never touches a marketplace, so a brand relying solely on marketplace scanning isn’t missing this because it’s hard to find. It’s missing it because nothing in that monitoring was ever pointed there. The content lives entirely inside the social platform’s own video and comment ecosystem, a different surface that marketplace tooling was never built to reach.

    This distinction matters because it changes what “we have brand protection in place” actually covers. A programme built around counterfeit listings and unauthorised resellers on Amazon or Flipkart can be running perfectly and still never encounter a single instance of this pattern, simply because it’s looking in a different place. The gap isn’t a quality problem with existing monitoring. It’s a coverage-surface problem, and it only shows up once someone goes looking specifically for it.

    What actually has to change: content and account signals, not listings

    Since there’s no listing to match against a catalogue, detection has to work on the video and the account instead, flagging content that pairs a brand’s name or visual identity with discount language and “DM to order” phrasing, then reviewing the account’s pattern of posting rather than waiting for a single reportable product page. This sits closer to brand impersonation monitoring than traditional listing detection, because the target is the account and the recurring pattern, not one page. Truviss’s Social Media Monitor is built around exactly this kind of account and content-level signal, watching for accounts and posts trading on a brand’s identity across Instagram, YouTube, TikTok and similar platforms, rather than assuming every threat will eventually surface as a listing somewhere.

    A few practical questions separate a brand that’s actually covered here from one that only assumes it is. Does existing monitoring look at video content and comment sections at all, or only at listings and storefront pages? Is there a defined process for flagging an account, not just a single post, once a pattern of DM-to-order content is spotted? And when a video does get reported, is there a documented trail, screenshots, timestamps, the account handle, in case the same seller reappears under a new account after the first one is taken down, which happens often enough to plan for rather than treat as a surprise.

    Getting started

    If a brand sells footwear, apparel, or anything else that shows up often in “discounted branded goods, DM to order” content, the fastest useful check is whether current monitoring even reaches Reels, Shorts and comment sections at all, not just marketplace listings and impersonator profile accounts. Most brand-protection programmes built before this format became common were never pointed there in the first place, and the gap only closes once someone deliberately extends coverage to the accounts and content driving it, rather than waiting for it to eventually show up as a listing that never comes.

  • GitLab’s Fake Recruiters Are Everyone’s Problem

    GitLab’s Fake Recruiters Are Everyone’s Problem

    Home/Blog/GitLab’s Fake Recruiters Are Everyone’s Problem
    Social Media

    GitLab’s Fake Recruiters Are Everyone’s Problem

    Watch for fake recruiter profiles, not just fake storefronts

    Truviss’s Social Media Monitor flags accounts and content trading on your brand’s identity, including impersonated hiring processes.

    Book a demo
    Fake recruiter brand impersonation cover
    TL;DR
    • GitLab warned on 10 December 2025 about fake recruiter profiles, fake domains and fake hiring processes impersonating its own HR team.
    • This is structurally the same brand-impersonation pattern as the L’Oréal domain case, just running through LinkedIn and job boards instead of registered domains.
    • Reported tactics include real-time deepfake video interviews and malware disguised as onboarding software.
    • Fake recruiter profiles don’t reliably show up in marketplace, domain, or generic social-media impersonation monitoring — it needs its own watch.

    On 10 December 2025, GitLab published a warning about a wave of fake job scams impersonating its own recruiters. Scammers were using the company’s name, logo and real team member identities, building fake recruiter profiles on LinkedIn and Teams posing as GitLab HR staff, registering lookalike domains including gitlab.careers and careers-gitlab.com, and referencing fake credentials like a “CPD USA Certification” to appear legitimate. This is a real, named, first-party disclosure from a company with genuine security resources, not a hypothetical warning written for a blog post.

    Why this is the same problem, on a different channel

    This is the identical underlying pattern behind L’Oréal’s 705-domain case, a brand’s name and identity borrowed to extract something valuable from someone who trusts it, just running through a different channel. There it was lookalike domains harvesting job applicants’ personal data. Here it’s fake recruiter profiles and job listings extracting money, credentials or, in some documented cases, malware installation, through an entire fabricated hiring process. Both are brand impersonation in the fullest sense, not just a copied logo but a copied identity, a real team member’s name attached to a fake conversation. The difference is where it lives, registered domains in one case, LinkedIn profiles and job boards in the other, and that difference is exactly why a brand watching only for lookalike domains would miss this pattern entirely.

    How convincing this has gotten

    This isn’t crude anymore. Reported 2026 tactics include scammers using real-time face-swap filters during video interviews to convincingly impersonate real company executives on camera, live, not just in a written message. In some documented cases, candidates who accept a fake offer are directed to install a “work-from-home security suite,” which is actually a remote-access trojan handing the scammer control over the victim’s own device. GitLab’s own published red flags are worth citing directly because they’re concrete and checkable: email addresses that aren’t on the company’s real domain, requests for payment for equipment or certifications, communication that stays in chat with no verified calendar invite, and job listings that don’t actually appear on the company’s own official careers page.

    See how Truviss watches for impersonated hiring processes, not just fake storefronts and listings.

    Explore Social Media Monitor

    The scale context, honestly framed

    The FTC’s April 2026 report found Americans lost $2.1 billion to social media scams in 2025, an eightfold increase, with roughly 30% of all scam-loss reports starting on social media. That figure covers social media scams broadly, shopping scams were the single most-reported category, not job scams specifically, but it’s still useful context for how large the delivery channel has become. A brand’s careers page and hiring process are increasingly competing for attention with a convincing fake version running on the exact platforms candidates already trust.

    Why this needs its own monitoring surface

    Fake recruiter profiles and fake job listings don’t reliably show up in marketplace monitoring, and they often don’t show up in domain monitoring either, some of these scams run entirely through legitimate job boards and LinkedIn’s own profile system without registering a single lookalike domain at all. They also don’t fit neatly into generic social-media impersonation monitoring built around fake product-selling accounts, since the target here is a hiring process, not a storefront. This is a specific, identifiable pattern, a real brand name combined with real team-member identities layered onto a fake hiring conversation, and it needs to be watched as its own thing rather than assumed to be covered by whichever monitoring already exists for other channels.

    Getting started

    The most direct defence is the same instinct GitLab itself acted on: publish and keep visible a single, canonical, up-to-date list of real open roles and the only legitimate domains and contact methods a candidate should ever expect to hear from. From there, monitoring for recruiter profiles and job listings using the brand’s name outside that canonical set is what catches the pattern early, before a candidate gets far enough into a fake process to hand over money, credentials, or control of their own device, and it complements the same continuous, evidence-first approach behind any well-built takedown request.

  • How to Protect Your Brand on Social Media

    How to Protect Your Brand on Social Media

    Home/Blog/How to Protect Your Brand on Social Media
    Social Media

    How to Protect Your Brand on Social Media

    Stop impersonators before they reach your customers

    See how Truviss’s Social Media Scanner catches fake accounts and scam pages the moment they go live.

    Book a demo
    How to Protect Your Brand on Social Media cover
    TL;DR
    • Impersonator accounts and scam pages using a brand’s identity are one of the fastest-growing ways counterfeit and fraudulent offers reach real customers.
    • Fake giveaways, cloned profiles and scam “customer service” replies are the most common patterns brands encounter on social platforms.
    • A single viral scam post can reach thousands of a brand’s own followers before a manual report is even filed.
    • Continuous monitoring across platforms, paired with a documented takedown process, closes the gap that manual reporting leaves open.

    Why social media is a target

    Social platforms give a brand direct access to its customers, and that same openness is exactly what makes them attractive to scammers. An impersonator account can copy a brand’s logo, bio and recent posts closely enough to pass a quick glance, then use that borrowed credibility to run a scam directly in front of the brand’s own audience, through comments, ads, or direct messages. This is a core part of what online brand protection now has to cover, alongside marketplaces and domains.

    Clothing, footwear and leather goods, categories with a heavy social-commerce presence, jointly accounted for 62% of all counterfeit goods seized globally (OECD/EUIPO, Mapping Global Trade in Fakes 2025), and impersonator accounts are frequently the channel used to promote those fakes straight to a brand’s own followers rather than through a search engine.

    Common scam types brands face

    The most common pattern is a cloned profile: a fake account using a brand’s exact logo and product photos, running a “flash sale” or giveaway that asks entrants to pay a small fee for a “free” item, a classic advance-fee scam. A close second is a fake customer service reply, where a scam account replies to a real customer’s public complaint before the brand does, offering a “refund” that requires payment details. Ad-based impersonation, where a fraudulent ad uses a brand’s name and imagery to link out to a counterfeit storefront, is a third, less visible pattern that can quietly run for days before anyone at the brand notices it.

    The cost of inaction

    Global trade in counterfeit goods reached an estimated USD 467 billion in 2021, equivalent to 2.3% of total world trade, and EU imports of fakes alone were valued at EUR 99 billion, or 4.7% of the EU’s imports from outside the bloc (OECD/EUIPO, Mapping Global Trade in Fakes 2025). Social platforms are one of the main distribution channels feeding into that figure, since they let a fraudulent offer reach a large, already-engaged audience without the seller needing to build any of their own traffic.

    Beyond the direct financial cost, a scam that runs under a brand’s name and goes unaddressed damages the trust that took years to build. Customers who lose money to a convincing impersonator often blame the real brand for not stopping it, even when the brand had no way of knowing the account existed until it was already live.

    Detect, verify, enforce on social

    The same three-stage process that works for marketplaces and domains applies here:

    Detect continuously across the platforms a brand’s customers actually use, watching for new accounts and pages using the brand’s name, logo or product imagery, not just a one-off manual search.

    Verify against the brand’s real accounts and known partners, so a genuine fan account or an authorised regional page isn’t mistakenly flagged as an infringement.

    Enforce by filing a documented takedown request directly with the platform once an account is confirmed as impersonation, with the evidence trail kept in case the same operator resurfaces under a new account.

    See how Truviss’s Social Media Scanner catches impersonator accounts before they reach your customers.

    Explore Social Media Scanner

    Building a response plan

    A workable response plan starts with knowing which platforms matter most for a brand’s own audience, rather than trying to cover every platform equally from day one. From there, a documented process for verifying and reporting suspected impersonator accounts, including who on the team is responsible and what evidence gets logged, turns an ad hoc reaction into something repeatable. Customer-facing teams also need a simple way to flag suspicious accounts they spot in comments or messages, since customers often notice a scam before any monitoring tool does.

    Common mistakes brands make

    The most common mistake is only reacting after a customer complains, by which point the scam account may have already reached thousands of people. A second is treating every report from a customer as equally urgent without a way to verify it quickly, which either burns team time on false alarms or lets a real scam sit for days. A third is stopping at a single takedown: operators who get one account removed frequently reappear under a near-identical name within days, and without ongoing monitoring that repeat account can go unnoticed for just as long as the first one did.

    Getting started

    Start with the platform where a brand has the largest, most active following, since that’s where an impersonator has the most potential reach. Put continuous monitoring in place there first, build a documented verify-and-report process around it, and expand to other platforms as the process proves itself. Pairing this with brand impersonation monitoring and marketplace coverage closes most of the gaps a brand is likely to face across channels.

    Frequently asked questions

    How is brand impersonation different from a parody or fan account?

    A parody or fan account is usually clearly labelled as unofficial and doesn’t try to collect payments or personal data. Brand impersonation specifically tries to pass as the real brand, often to run a scam, which is the distinction platforms use when reviewing takedown requests.

    Can I just report impersonator accounts directly to the platform myself?

    Yes, every major platform has its own reporting process, but manually finding every fake account before it gains traction is difficult at scale. Continuous monitoring surfaces new accounts as they’re created rather than relying on customers to spot and report them first.

    What should I do if a customer says they were scammed by a fake account using my brand?

    Acknowledge it publicly if the complaint is already visible, direct the customer to report the account to the platform, and file your own verified takedown request with your evidence trail. A documented response also helps other customers recognise the account as fake.

    Do impersonator accounts only appear on social media?

    Social media is the most common channel, but the same fake-identity approach shows up as fraudulent marketplace seller accounts and cloned domains too, which is why brand protection typically covers all of these channels together rather than social media alone.

    Is this only a risk for consumer-facing brands with a large following?

    Smaller and mid-sized brands are targeted too, sometimes precisely because they have fewer resources to monitor for impersonation, which makes an automated process more valuable relative to the size of the team available to run it.

    How quickly can an impersonator account typically be removed once reported?

    This varies by platform and by how well-documented the report is. A verified impersonation with clear evidence is generally actioned faster than a vague report, which is why a consistent evidence trail matters even for routine takedowns.