How to spot a fake login page

Updated View source
Stay safe

A fake login page is a copy of a real sign-in screen built to steal the username and password you type into it.

How a fake login page works

Scammers copy a familiar sign-in screen: your bank, your email, a shop. The logo, the colors, and the layout can be a perfect match. The trick is not how the page looks but where it sends what you type.

Real login versus fake login Real login Your password Real sign-in page login.bank.com The bank Fake login Your password Fake sign-in page bank-login-secure.net A stranger
Same screen, different destination. Only the address tells you which lane you are in.

Check the web address first

A design can be faked. The domain is much harder. Read it from the end backward.

Watch how the page behaves

How to protect yourself

Fish Catcher warns you in plain language when a login screen sits on a lookalike domain or a site it does not recognize. It never blocks the page.

Common questions

The page looks exactly like the real one. Does that mean it is safe?

No. Looks are the easiest part to copy. A scammer can save the real page and change only where your password goes.

There is a padlock in the address bar. Is that enough?

No. The padlock means the connection is encrypted. It says nothing about who owns the site, and many phishing pages have one.

I already typed my password into a page I now think was fake. What should I do?

Change that password right away on the real site, opened by typing the address yourself, and on any other site where you reused it.