Threats

Fake login pages: how to spot one before you type

Phish Plug TeamSeptember 10, 20267 min read

A fake login page is the sharp end of phishing — the screen where a moment of trust turns into a stolen password. They are convincing by design, and on a small mobile screen they are harder than ever to catch. Here is how they work, the tells that can give them away, and why the real fix is not asking your customers to be vigilant.

Why they are so convincing

A fake login page is usually an exact copy of the real one. Attackers simply duplicate the front-end — the HTML, the stylesheet, the logo, the layout — and host it on a lookalike domain. There is no technical trick to the appearance; it looks right because it is the same front end. The deception is entirely in the address and the context.

The tells — and their limits

A careful user can sometimes spot a fake. The classic signs:

  • The domain is wrong. Your brand may appear in the address, but the real registrable domain is different — brand.secure-login.net is not brand.com.
  • You arrived from a link. Pages reached by tapping a link in an email or text are far riskier than ones you typed or bookmarked.
  • Urgency and pressure. "Your account will be closed," "verify within 24 hours" — manufactured panic is a hallmark.
  • It asks for too much. A login page that suddenly wants your full card number or extra personal details is a red flag.

The problem: these tells are not reliable. A homoglyph domain can look perfect, cloaking can hide the page from checks, and on mobile the full URL is often truncated. Vigilance helps, but it is not a defence you can depend on.

The credential trap, hidden by cloaking

The dangerous core of a fake login page is the credential trap — the form that captures what the victim types. On a cloaked page, that trap is shown only to real, targeted mobile visitors, while security scanners and crawlers are served a harmless decoy. That is why a fake login page can pass automated checks and still be actively stealing passwords.

signin.brand-account.help
heritage-archiveARCHIVE · STORIES · ABOUT
What a search crawler sees
Canonical · clean
ACCOUNT SERVICES
Your session has expired

Re-enter your details to restore access.

EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COM
What a mobile visitor sees
Cloaked · malicious
Phish Plug crawls as both a search bot and a real in-country phone, then diffs the two responses to prove the redirect.

Same URL: a clean page to a scanner (left), the credential trap to a real mobile visitor (right).

Why the brand has to catch them

Expecting every customer to detect a pixel-perfect clone on a look-alike domain — often on a phone, under manufactured pressure — is not a realistic defence. The party best placed to act is the brand being impersonated. By monitoring for clones of its own login pages and removing them quickly, a brand protects every customer at once, instead of hoping each one spots the trap.

What that looks like in practice

  1. Watch for clones of your sign-in pages and lookalike domains around the clock.
  2. Resolve the cloak by crawling as both a scanner and a real mobile device, and diff the two.
  3. Capture evidence of the trap — screenshots, headers, the diff — the moment it is confirmed.
  4. Take it down fast, across host, registrar and safe-browsing feeds.

Phish Plug does exactly this: it detects cloned login pages, proves the cloaking that hides the trap, and files the takedown — so the fake page is gone before most of your customers ever reach it.

The takeaway

Fake login pages are convincing because they are literal copies, and cloaking lets them hide from the very tools meant to catch them. User vigilance helps but cannot be relied on — especially on mobile. The durable fix is for the brand to watch for its own clones and remove them fast, protecting every customer at once.

Put detection and takedowns on autopilot

Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.