Even with a strong password and 2FA, one trick can still catch you: a fake login page built to look exactly like the real one, to steal what you type. Here is how to never be fooled.

How it works. You get a message (“verify your account” or “unusual sign-in”) with a link. It opens a page that looks just like Gmail, your bank, or Amazon. You type your username and password, and it goes straight to the scammer. They may even ask for your 2FA code on the next screen.

How to tell it is fake:

  • Check the web address (the URL) at the top. The real site is a clean, known address like accounts.google.com. Fakes use look-alikes: google-verify-login.com, accounts-google.co, or a jumble of words. If it is not exactly right, leave.
  • A padlock is not proof. The little lock icon only means the connection is private, not that the site is honest. Scammers get padlocks too.
  • You arrived by clicking a link. Real login trouble does not require a link from a text or email.
  • Your password manager will not autofill. This is a powerful tell: a manager only fills in a password on the exact site it was saved for. If it does not offer to fill, you may be on a fake page.

A quick example. An email says “Your email will be deleted, sign in to keep it,” with a button. The page looks perfect, but the address bar reads mail-account-secure.net, not google.com. You close it. Nothing was lost.

What to do:

  1. Never log in through a link in a message. Go to the site yourself by typing its address or using a saved bookmark.
  2. Always glance at the web address before typing your password.
  3. If a manager will not autofill a saved login, stop, you are probably on a fake page.