Starting to see accounts that have been compromised after clicking on the fake 'verify your account' spam that's doing the rounds here.

Please boost for visibility:

* Familiarise yourself with you instance's admin and moderator accounts and ONLY trust account-related messages from those accounts.

* Do not click links without confirming with your instance staff that they're legit!

* Generally, any problems with your account will be brought up via email, not from a random fediverse handle.

@Curator
You don't need to know admin accounts.

I've had services messages. I've even gotten a warning ("strike") from an admin of a previous instance. Every single one has been a notification, NOT a post.

For good reasons. Not only does it make it easy to see which ones are from the actual admin, but posts get missed all the time.

Apps show these notifications in different ways, but they do not show up in between the mentions and replies. In the app I use, it's a separate icon that shows up st the top.

@leeloo knowing the admin accounts, though, is an extra step in helping people recognise that these accounts are not official; it's good for people on an instance to know who their admins are (like me, I'm the instance admin for mastodon.art and I often post important things like this as well as occasionally message people about moderation issues that fall outside the scope of reporting).

@Curator

Thank you for the heads up. Just spotted one of these. Blocked & reported.

@cavyherd @Curator that same one sent me a post too. Also blocked and reported.

@Curator

I had that scam on my Mastodon, I had to ask the lad if it was Kosher.

He said Mastodon would never contact you like that, they would e-mail you, plus below the Mastodon sign is an 'odd' inter-net address.
But it will fool many.

@Curator how we do know that the account got hacked

Idk this didn't happened to me but I need to know how can we stop it

@Rinakochi they're accounts that had existed for a while posting 'normal' things that then started sending out the scam 'verification' message
@Curator People should be familiar with who runs their servers in general, if only to know who to direct complaints/suggestions and gratitude toward.