The mechanism
The copy of the page in the middle, and how the code gets through
Step 2 of 4. The link opens a copy of the sign-in page. Its address is close to the real one and not the same. The password typed into it goes to the fraudster.
A drawing of the method, with no real site in it. A fake support desk works the same way with a voice in place of the page: the caller asks for the code, or for remote access to the screen, and is given it.
Also searched asfake customer support scam · one-time code scam · smishing and vishing · remote access scam
How it works, step by step
- A message arrives by e-mail, text or app: a problem with the account, a payment to confirm, a security alert. It carries a link or a telephone number.
- The link opens a copy of the firm’s sign-in page at an address that resembles the real one.
- The password entered there goes to the fraudster, who types it into the real site straight away.
- The real site sends a one-time code to the real customer. The copy page, or the caller, asks for it.
- With password and code the fraudster is signed in. Details are changed, money is moved.
- In the support version, the “agent” asks you to install software so that they can “fix” the problem, and then works your device in front of you.
Why it is convincing
- It uses the firm’s real logo, wording and layout, which are public and easy to copy.
- It arrives when a message from that firm would not be surprising, and sometimes in the same thread as genuine ones.
- It is urgent, and about security: the feeling it produces is that acting quickly is the careful thing to do.
- The fake help desk appears just when help was being sought: as an advertisement above the real result, or a reply to a public complaint.
The warning signs
- A link in a message that asks you to sign in. Read the address from right to left: the part just before the first single slash is the site you are on.
- Anyone at all asking for a password, a one-time code or a recovery phrase. Genuine staff have no use for them.
- A request to install remote-access or screen-sharing software.
- A deadline: the account will be closed, the payment will go, within the hour.
- A sender’s display name that is right above an address that is not.
- A support number found in a search advertisement or a social media reply and not on the firm’s own site.
One sign alone proves nothing, and a fraud may show none of them at first. The Check this offer list puts fourteen such questions side by side.
If it has happened
- Change the password from a device you trust, sign out all other sessions if the service allows it, and tell the firm through its own published contact details. If a code was given out or software installed, tell your bank as well.
- Stop paying. Send nothing more, whatever the reason given: a tax, a fee, a deposit to “unlock” the account, a charge to recover what was lost. A further payment is the usual next step of the fraud.
- Stop the conversation. There is no need to explain, argue or warn. Do not delete it, either: it is a record.
- Keep records. Messages, names and numbers used, the addresses of websites, payment receipts, account and wallet details, screenshots of anything that might disappear. Note the dates.
- Tell your bank or payment provider at once. Use a number you find yourself, on a card or a statement, not one from a message. Say it is fraud. Time matters, and they will say what they can and cannot do.
- Report it to the authority in your country. That is usually the police or a national fraud-reporting service, and the financial regulator. A report helps others even where it does not help you.
- Secure what was shared. Change passwords that were given out or reused, remove any remote-access software that was installed, and tell the provider of any account or card whose details were passed on.
- Expect a second approach. People who have lost money are contacted again, by “recovery agents”, “lawyers” and “officials” who ask for a fee first. See the page on recovery-room fraud.
- Tell someone you trust. These frauds are built by people who do it for a living, and they work on careful, intelligent people. Silence helps only the fraudster.
Nobody can promise that money lost to fraud will come back. Sometimes some of it does; often it does not. Anyone who guarantees a recovery, or asks to be paid first, is describing another fraud.
Regulators publish free warning lists and registers of authorised firms; this site lists several under Nice & Need: stay safe. To check an address that claims to be this site, use Verify a GIO4X link.
Questions people ask
- If I have two-step verification, can phishing still work?
- It can, when the code is typed into a copy of the page or read out to a caller: the fraudster uses it on the real site within seconds. Two-step verification stops a stolen password from being enough. It does not stop a code that the customer hands over.
- How do I check that a web address is genuine?
- Read the host name from right to left. In an address such as signin.example.com.example.net the site is example.net, whatever comes before it. For this site’s own addresses there is a checker on the page “Verify a GIO4X link”.
- Will a real firm ever ask for my password or a code?
- A firm’s systems check a password; its staff never need to be told it. A code sent to your telephone is for you to enter yourself, on the firm’s own site or app. A person asking for either is not acting for the firm.
A description of a type of fraud, for study. It names no real firm, person, website or product and retells no real case. It is general information, not legal advice, and not a judgement on any offer you may have received. What applies in your country is a question for the authorities there.
