Fake sign-in alerts and how attackers steal passwords
"Unusual sign-in on your account. Confirm it's you." It is one of the most effective scams going, because it turns your own caution against you: you want to secure your account, so you click, and hand the attacker exactly what they were after.
How the trick works
The message links to a page that looks identical to the real login. You type your username and password to "confirm", and they go straight to the attacker. More advanced versions sit in the middle in real time, passing whatever you enter (including a texted or app code) straight to the real site as you type it.
The page looking perfect is not reassurance. It is a copy. The only thing that matters is how you got there.
The safe way to check
Never sign in through a link in an alert. If you are worried there really was an unusual sign-in, open the app or type the website address yourself, log in there, and check your account's security or activity page.
If the alert was real, you will see it in your account. If it was not, you just avoided handing over your password.
Turn on multi-factor authentication, and pick the strong kind
One kind of second step defeats this scam outright. A passkey or a hardware security key is tied to the real website, so it will not work on a copy, however good the copy is. That beats even the real-time trick above, where the fake page passes your code straight to the real site as you type it.
Any second step is far better than none, and which kinds are strongest is a subject of its own: our guide to passwords and multi-factor covers it properly rather than in a paragraph here.
Never approve a prompt you did not start
Attackers who already have your password will sometimes spam you with MFA approval prompts, hoping you tap "approve" just to make them stop. Do not. If a prompt appears when you were not signing in, that is someone trying to get into your account: deny it, and change your password.
The short version
- A fake login page is a perfect copy. How you reached it is the only thing that matters.
- Never sign in through a link in a message. Open the app or type the address yourself.
- Turn on MFA everywhere that matters; a passkey or hardware key is the phishing-resistant kind.
- Never approve an MFA prompt you did not personally start.
Build the reflex, not just the knowledge.
BadgerQuest is a two-minute daily game that keeps this instinct sharp. Free for individuals, no card.
Play a round free →Training a team instead? See pricing · Credential theft across a client book
Common questions
How can a fake login page look exactly like the real one?
Because it is a copy of the real one. Attackers clone the genuine page, so "it looks right" proves nothing. Safety comes from how you got there, not how the page looks.
Does multi-factor authentication stop phishing?
It stops most of it and is the single best upgrade for your important accounts. Be aware that advanced real-time phishing can relay a texted or authenticator-app code as you enter it, so those codes are not foolproof. A passkey or hardware security key resists even that, because it is bound to the real site and will not work on a fake one.
I got an MFA prompt I did not request. What does that mean?
It usually means someone has your password and is trying to sign in. Deny the prompt, then change that password immediately (and anywhere you reused it).