Digital security & AI

Smishing and fake logins

Billing, rewards, or login alerts lead to fake pages that capture passwords and payment details.

A physical red padlock resting on a computer keyboard

If you have one minute

Pause, then verify independently.

The domain or spelling differs

Before paying

Open a known app or saved bookmark

See verification steps →

If you paid or shared details

Stop logging in or entering details

See response steps →

Start with these three signs

  • The domain or spelling differs
  • Unexpectedly demands an urgent login
  • The alert requests sensitive details

How the situation unfolds

  1. Contact

    Texts or messaging alerts containing links.

  2. The lure

    Your account will be suspended unless verified now.

  3. The demand and outcome

    A copied login page captures credentials and codes for account misuse.

Verify these things before paying

  1. Open a known app or saved bookmark
  2. Check the full domain, not the logo
  3. Enable multifactor authentication

Already engaged or paid?

  1. Stop logging in or entering details
  2. Change exposed passwords on a safe device
  3. Notify affected platforms and banks

Contact your payment provider and local police promptly. The responsible institution must confirm whether a payment can be stopped, disputed or returned.

Keep these records

Original message
Full URL
Disclosed-information list
Unexpected login records

Keep originals and organise working copies. Never give strangers verification codes, banking passwords, private keys or seed phrases.

Original references

  • Federal Trade Commission (FTC)Publisher location:United States · EnglishOpen the original reference ↗https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams

This page summarises public prevention guidance to help recognise methods. It is not an enforcement conclusion about a particular incident. Check the source page for its original title. Procedures and reporting routes vary by jurisdiction. Compiled October 2026.