77Trust
Verified
🔍 Web Verified
Aral BalkanonMastodon16d ago
RE: https://mastodon.uno/@amministratore/116967326136690873
Looks like there’s a Mastodon identity verification scam going around.
Good rule of thumb: if a web site asks you to verify your identity, you close that browser tab.
The scam letter looks like this (thanks to @amministratore):
***
We detected suspicious activity on your account and have temporarily restricted access. Your new posts are currently visible only to you. To restore full access, please complete the verification process using the link below:
🔗 <shortened link removed but you can report UPDATENOTIFICATION.CLICK to https://globaldomaingroup.com/report-abuse for it to be taken down>
If you do not verify within 24 hours, your account may be deleted for guideline violations. Successful verification will grant you a badge to enhance your visibility.
Thank you for your cooperation.
Sincerely,
The Support Team
***
Do NOT click any links if you receive such a message and inform your server admin.
#mastodon #scam #updateNotificationClick #fediverse #warning
Trust Metrics
75
85
70
82
Accuracy75%
Framing85%
Context70%
Tone82%
Analysis Summary
A phishing campaign impersonating Mastodon support is circulating, using fake verification messages that threaten account deletion and promise visibility badges. The scam redirects users through shortened links to a malicious domain. Users should never click verification links sent via message — legitimate platforms ask for verification through account settings, not external links — and should report suspicious messages to their server admin.
Claims Analysis (3)
“There is a Mastodon identity verification scam going around.”
The post references a specific scam message pattern and cites another Mastodon user as witness. Web search confirms active phishing campaigns targeting platforms and using verification pretexts. The scam pattern (fake verification, account restriction threats, shortened malicious links) matches known phishing infrastructure documented by security researchers.
“The scam uses a shortened link to UPDATENOTIFICATION.CLICK domain registered to globaldomaingroup.com.”
The post provides the specific domain name and reports it as phishing infrastructure. Web search did not return specific confirmation of this exact domain in relation to Mastodon phishing, but the pattern matches documented phishing tactics (shortened URLs masking malicious destinations). Cannot independently verify this specific domain without direct lookup.
“The scam claims account access has been restricted and threatens deletion within 24 hours if verification is not completed.”
This is a documented phishing tactic. The message text provided in the post matches the structure and language of known phishing campaigns that impersonate platform support teams. Multiple security researchers document this threat pattern.
Was this analysis helpful?
Try ClearFeed free →