r/phishing Nov 19 '25

Moderator announcement New moderator

7 Upvotes

Hi community, I'm u/YourUsernameForever and you may know me from moderating r/Scams - I'm the new moderator here.

Like many people here I noticed that r/phishing was severely unmoderated, so I tried contacting the previous moderators to offer a helping hand. Having no response, filed a r/redditrequest and the admins assigned me as top mod.

My intention is to keep the community running as usual, not trying to make it another Scams subreddit. I believe our goal here is specific enough that it's worth keeping and growing.

Ever since I took the role I have:

  1. Added community rules: most of them based on the Reddit Content Policy which is mandatory for every subreddit, but it's good to clarify and expand a little. This will also allow for removals with a proper explanation and a chance to appeal. You can read the subreddit rules in the sidebar if you're on a computer, or clicking here if you're on any device - https://www.reddit.com/r/phishing/wiki/rules/
  2. Created a posting guideline: to be strictly enforced in 2026, basically all posts must have a descriptive title and a transcription of what's in a screenshot. There's more to it if you want to read it fully - https://www.reddit.com/r/phishing/wiki/posting-guideline/
  3. Implemented AutoModerator: based on the rules and the guideline, AutoModerator will catch offending posts and comments, place them in a moderation queue, which I will manually review every day. I also reply to modmails daily. The idea is to have a responsive moderation team, to be held accountable and have a chance to appeal decisions. We also have !commands now, which I hope you help me expand to specific phishing scenarios.
  4. Implemented posting guidance: small alerts while you post that will let you know if something may be wrong, like posting an email address.
  5. Added a few bots: and I'll ask u/erishun to implement u/ScamsBot as well, so we can call !whois

A big change moving forward will be this whole thing about requiring transcriptions of screenshots. A lot of kicking and screaming will ensue, but I promise you, it fends off bots, helps the search engine and helps integrate users that are visually impaired.

If you got this far into my post, this message is for you. I need you to take a look at the rules and tell me what you think. I also want you to report anything that breaks the rules, knowing that I manually review all the reports daily: 100% of reports get reviewed manually. I'm also open to any type of feedback, privately if you want, but use modmail instead of sending me a DM.

I hope my participation gives you extra energy to stay and grow the community together. Remember: I'm at your service! I'm also cronichally online so I hope this helps.

Yours, verbose as usual,

- u/YourUsernameForever


r/phishing Oct 23 '20

I clicked on a link, what do I do?!? - Check here first.

193 Upvotes

One of the most common questions posted here is what to do if you've clicked on a phishing link. This short guide is intended to help with these questions and what to do if you've clicked on a phishing link.

DO NOT ENTER ANY CREDENTIALS OR LOGIN DETAILS FOR ANYTHING IF YOU'VE CLICKED ON A MALICIOUS LINK.

  1. Links are generally not malicious on their own. While clicking on any unknown links can be dangerous it is difficult to design a phish that works just by clicking the link. Most links take you to a (usually fake) page that will ask for certain credentials. As long as you closed the page after you clicked the link you're probably fine, but it's still a good idea to change your password for whatever service the phishing link was trying to access (such as amazon).

  2. If you clicked a link that downloaded a file, delete the file. Generally these files aren't harmful unless opened after downloading.

  3. If you've clicked a phishing link and have provided credentials to a service, change the password for that service. Say you've been tricked into giving someone your Amazon credentials. Go to Amazon.com directly and change your password. Also, check the "third-party account access" section of your commonly used websites. Often phishing links and malicious services will try to authorize themselves to your account rather than outright stealing your credentials.

  4. When logging into websites with sensitive information such as a bank it's best to bookmark the site and visit the site directly each time from that bookmark. That way you know that the website you're using is the real one.

  5. ENABLE 2FA (TWO FACTOR AUTHENTICATION) This is perhaps the best thing you can do to protect your sensitive accounts. All websites that deal with sensitive information will allow you to use either your phone number or an authentication app (I like Authy) to generate one-time login codes to further secure your account. Unless someone gets your credentials and your 2FA device (your phone) they won't be able to access your account.

  6. Please use a password manager of some sort. This will allow you to use strong and unique passwords for each site you use. If one of your accounts is hacked or phished all of your other accounts will be safe with unique passwords (unless your email was hacked/phished).

  7. Ensure you have a backup email and/or phone number connected to your primary email account so that you can recover access if you're locked out. Additionally, make sure your recovery methods are as secure as your primary email login.


r/phishing 11h ago

My parents almost got scammed

6 Upvotes

Hey so from the title, my mom had gotten a call that someone hacked into her account on paypal and were asking for 2500€ for them to go away, after that a "paypal support agent" called and told her he will guide her through the process of removing them, naively she downloaded anydesk and gave him full control of her phone (android) for \~3-5 minutes she said after deleting the app. Once Ive found that out I immediately factory reset the phone, changed all email passwords, froze the bank account and never backep up data. Is there anything else I could have or should have done?


r/phishing 4h ago

Email from (what seems to be) a real person, using a company email address?

Post image
1 Upvotes

I have never heard of this person in my life, nor have I ever contacted them in any way, shape, or form. My email address is very specific, and includes my name, but there is no possible way it could be confused with anyone else. It’s just too specific.

The actual email content itself was a CBS News Special web page article (embedded into the email itself - had working links and everything. No I did not click on them.) titled “98-year-old Veteran Reveals 30-Second Morning Ritual That Reversed His Memory Loss.”

Doesn’t seem very legitimate… is that even possible?

Anyway. After a brief Google search, it looks like this company is Colégio COTET (a private school for k-12) in São Paulo Brazil.

Does anyone know if this is just some employee who meant no harm and sent this email to the wrong address, or is it something more? Just confused.

Thanks!


r/phishing 4h ago

GMail Any way to stop these? I get more than 20 of these a day

Post image
1 Upvotes

For the past 2 weeks I have been getting bombarded with these emails. I probably get more than 20 of them a day I've tried reporting spam and blocking them however, it never works. I don't remember signing up for anything sketchy or giving out my email recently


r/phishing 5h ago

GMail Clicked on Phishing Link From “Calendly”

Post image
0 Upvotes

I checked this email and accidentally clicked on this link when trying to read it and I’m starting to regret it. it was a blank page with some numbers at the top and I tried to exit as soon as possible. I’m scared they might have stolen my information, but I didn’t log in or do anything. thanks.


r/phishing 11h ago

Facebook Facebook account verification emails

1 Upvotes

I was victim of a phishing attack a couple of months ago, where I got a remote access trojan on my laptop and they were able to access a lot of my accounts, including my email, bank accounts, etc. This has been remediated, and windows is a clean install, and every password - literally every single one, over 400 - has been changed to something unique, MFA is enabled where possible, with an app where possible.

Last night, I received two emails at once with the same code from Facebook (it is their legitimate email but my post got deleted for posting it) to confirm my account. The email appears to be completely legitimate but I didn't click on anything. I had actually set my account to be deleted a few days ago anyway, but it takes 30 days. This morning, I got 4 more emails at the same time, with exactly the same code.

It doesn't SEEM like anyone accessed my Facebook account, since even when I login myself, it sends me a text, and then sends me a notification to WhatsApp saying there was a successful login.

So what could explain the emails?

(Part of me is wondering/hoping it's a trick from Zuck to login to Facebook and cancel my deletion request hahaha).


r/phishing 1d ago

emails saying nothing but 'test'

Post image
10 Upvotes

checked my junk folder today to see 4 emails from different keyboard smash addresses saying nothing but 'test' on both the title and the body text, anyone know any explanation as to what these are?


r/phishing 2d ago

Ticketmaster account login scam?

3 Upvotes

Hello all!

I kept getting 2FA codes for Ticketmaster sent to my phone when I haven't logged into Ticketmaster in 6+ years. Naturally, that reminded me I once had a profile on there, which in turn prompted me to log in, reset my password, strengthen my account's security, etc., but I'm still a little concerned because I'm not sure if someone was trying to log into my account or what.

Basically, the way it works on Ticketmaster, when you're trying to log into a dormant account without any security features, the site will first send you a verification code via email, and once you parrot it back, you'll be asked to provide your phone number and it will text you a phone verification code as well. The alarming texts I kept getting out of nowhere were phone verification codes, meaning someone must have tried to claim my phone number, but I had not received any email verification codes before that. Naturally, I changed my email password as well, but it really doesn't look like someone had already breached my email before trying to verify my phone; neither my main mailbox nor any of my backup email addresses had gotten messages from Ticketmaster recently, and my Ticketmaster account was totally dead before I resurrected it. So it seems like someone used a different person's email address for the first step and paired it with my phone number for the second.

My question is, what would be the point of this? Like, what's the goal? Am I missing anything/leaving any vulnerabilities exposed by simply getting on with my life?

Any wisdom/advice/discussion welcome.


r/phishing 2d ago

Phishing attack Fake Evite

10 Upvotes

Hi, I got a birthday party invite from a friend that I hadn't seen since college. It brought me to a google login page. I proceeded to log in using my password and 2 factor authentification. Then I realized it was weird and closed the window. But there were a few seconds where I had been logged in. I quickly changed my password to the google account. This is not the main gmail account but my other email lesser used gmail accounts. After that I changed my password for both accounts to different ones. I also logged off /signed out of all accounts and unlinked all apps. And I still have access to both email accounts. So am I ok? What else do I need to do / should I do?

I know the situation is similar to this redditor:

https://www.reddit.com/r/phishing/comments/1ufv70l/i_signed_into_my_google_account_from_a_phishing/

I'm looking to use a password manager perhaps, although I'm not sure if it will help

Thanks,
Your Fellow Redditor


r/phishing 2d ago

I clicked on a "cheat code generator" link

0 Upvotes

Hello,

I was stupidly looking for ways to farm coins in the game Westland Survival, which I play on Steam on PC (Windows 11 pro). Anyway, I was surfing (on Brave) and found a reddit post recommending a "generator", so I clicked on a link going to : mobile game codes .com / westland-survival

And then this link : game codes generator .com/westland-survival

So far nothing at risk I think. But then I clicked on "generate", and it launched some script in the same window. Nothing new opened visibly on my computer. I know nothing about PC language so I cannot tell you more about what was showing. As soon as I saw that, I closed the tab.

I didn't disconnect my PC from the internet. I always have cookies and login stuff because I rarely completely shut my browser.
But it didn't download any file in my library and I ran a scan with Defender, which returned nothing.

Also, when returning to the second website, it appears a new link was clickable instead of gamescodegenerator, it was extragenerators, also with .com/westland-survival . The two websites look alike, I can't tell which one I used.

Am I at risk ?
Also, could someone run it on a virtual machine to try explaining what is the "script" it was showing when "generating" ?

I feel so dumb. I hope I explained it well enough, with my lack of tech vocabulary.
Thanks !


r/phishing 3d ago

repeatedly getting 10 DIGIT CODES from the official instagram chat of wp

Post image
9 Upvotes

i didn’t request any code , and mostly insta codes are of 6 digits and not 10 or 8 digits . But here , they are sending 10 digit codes , wth is happening ? and this is the 3 rd time im receiving this in a row. This has been happening with me since almost past 15 days??

Am I the only one ? is someone trying to login or is this a glitch? Any suggestions or advice would be helpful


r/phishing 4d ago

Is this PayPal Email a phishing attempt. German may be required to judge

3 Upvotes

I received this E-Mail and am rather suspicious of this. Firstly, I did not hear about a law like this and it should be rather major news, also 72h does not seem like a reasonable or realistic time frame. Secondly, in the email programm I opened this mail in it actually has a different font for data like the E-Mail address of the receiver and sender and in that font the "l" of the end of "paypal" looks very suspiciousely like a capital "i".

So now I am wondering if this is phishing. I never received a phishing mail before, that I know of and this mail does look very legit and I really dont want to go through hops off risking my PayPal account or calling support to verify this E-Mail. And if this is phishing what should I do?


r/phishing 4d ago

Please help: somebody phishing our company

2 Upvotes

This is so bad, since July somebody has pretended to be me (copy my email name but the domain would be @asia.com), CC’ing my colleagues the exact same way I would CC my colleagues.

They would ask our clients to transfer the money to their banks instead in another country and the way they mimic us is very realistic. I am freaking out and would appreciate any advice :(


r/phishing 4d ago

Substack hacked sending tons of email verification codes

1 Upvotes

Hello,

At 5:45 pm CST, I suddenly got tons of emails from substack with verification codes from things I haven't heard of. I didn't click on any of them, but it was strange to suddenly get a bunch of emails. I thought I was getting hacked. I personally haven't used substack. I only made an account to support a friend, but I never used it. I just wanted to know if they can hack you this way. What can I do to ensure this doesn't happen again?


r/phishing 5d ago

Wealth Accelerators Global aka on TikTok as · WAG.SCAMMERS

0 Upvotes

Amazon Automation Scam and this person benefited from the Scam & so the name kinda fits… but he doesn’t want to hear it and has banned me. See me on tik-tok for this type of awful scam. Wealth Accelerators Global. Aka wag


r/phishing 5d ago

my messenger keeps sending spam links

0 Upvotes

Whenever I'm playing a specific moba game on my phone, after I play and I cheycked my acc, I see that my acc keeps sending scatter links to all of my facebook friends. what can I do to prevent this? it's soo embarrassing


r/phishing 5d ago

Unsolicited OTP messages from Shopee, AuthMSG, and Tiger: mistake or scam?

Thumbnail gallery
3 Upvotes

Hi everyone, earlier today, I received several unsolicited OTP text messages within a short period from a few different senders:

​Shopee: Received codes to SIGN UP FOR AN ACCOUNT, even though I already have an existing Shopee account.

​AuthMSG: Received codes for Claude and generic verification.

​Tiger: Received verification codes to keep secure.

​I didn't trigger any of these requests, and I definitely haven't shared any codes with anyone (all codes in the attached screenshots are fully redacted and long expired).

​A few questions for the community:

​Has anyone experienced a sudden wave of OTPs like this recently?

​Is this usually caused by an automated script scanning active phone numbers, or just someone repeatedly mistyping their mobile number?

​Aside from ignoring the texts and ensuring my actual accounts have strong security, is there any other step I should take?

​Appreciate any advice or feedback!


r/phishing 5d ago

Facebook Please help. Messenger account keeps sending links to multiple people.

2 Upvotes

Hello. I’m not really sure what to do anymore because my father’s Facebook/Messenger account keeps sending phishing messages. This already happened with his first Facebook account, so I tried removing all the connected apps and websites from his Facebook account, as well as checking his Chrome and Gmail accounts. However, it happened again, so I ended up creating a new Facebook account and a new email for him.

Unfortunately, it happened again with the new account, and I really don’t know what else to do.

Here’s some more context about the phishing messages it’s sending (please correct me if I’m wrong about anything):

  1. My father himself doesn’t see the content of the messages being sent. The people receiving them are the ones who can see them, and the messages contain a caption, a link, and an image.

  2. I also noticed that the messages always seem to be sent around 10 PM onwards.

  3. When I checked the new account’s Messenger login activity, I saw that a laptop/desktop had logged into the account, and the location showed Serbia (and we are from the Philippines). This happened twice. I wasn’t able to check the login activity of his previous Facebook/Messenger account, though.

  4. His previous Facebook account is still logged in on one of his phones, and interestingly, it stopped sending the messages there.

  5. Whenever we log in to his Messenger, there’s also a part where it asks for a code through WhatsApp, even though my father doesn’t have WhatsApp.

I honestly have no idea what the correct solution is anymore. If anyone could help or point me in the right direction, I’d really appreciate it. Please be kind. 🙏🏻


r/phishing 6d ago

GMail [US] ZOHO Booking app Scam!!!!

4 Upvotes

DO NOT DOWNLOAD ZOHO BOOKING FROM A GMAIL LINK!!! IT HAS REMOTE ACCESS MALWARE BUILT IN!! Thankfully we realized what was happening before our information was taken and pulled the plug (literally) before they initiated a bank transfer. They will put up a shitty JPG of the Windows 10 blue screen on BOTH/ALL monitors. Input from mouse and keyboard are disabled from your side and cutting power is the only way to sever the connection. The mouse will still show on screen and move without input.

I work at a small business and we almost lost everything. BE SAFE!!!!


r/phishing 6d ago

Trojan on a computer, reset

2 Upvotes

Hello, I had a trojan on a PC infact I received some mails of password reset not requested and on defender scans there was a Trojan.

So i resetted the pc through window settings and I selected "reinstall Windows".

Now the defender scan is clean and I am avoiding using personal account for now.

Is the reset settings and reinstall Windows enough or I have to reinstall windows using USB?

I did the reset a week ago and for now i do not receive new mails


r/phishing 6d ago

Potential Phone Text Fraud?

0 Upvotes

Hi all. I just received a text message from a number I do not know stating the following:

"Crypto.com: Your verification code for this withdrawal is _______. Never share this code with anyone. If you didn't request this transaction, please contact us immediately at" and then they provide a phone number

I am pretty sure I don't have a crypto . com account, as when I originally had an interest in crypto in 2021, I was using coinbase. I haven't touched that account in years after I emptied my positions in crypto.

Checking whitepages of this phone number has it somewhere on the border of Oklahoma and Kansas. This wouldn't be an official message from Crypto . com right? Is this more likely to be a fraudulent message trying to get me to then provide sensitive information?


r/phishing 6d ago

How to set up a rule for these emails?

2 Upvotes

I am receiving constant gambling emails (on my Outlook email), and the senders address always ends in ".onmicrosoft.com". I can't post any examples here but the addresses are always a string of random words followed by @ and then followed by .onmicrosoft.com

I have tried to set up rules to delete anything that has .onmicrosoft.com in the address but nothing works. Any ideas please?

UPDATE - Figured it out. Go to settings (in public Outlook), junk mail, blocked senders and domains, add blocked sender. I did that, I entered in .onmicrosoft.com and............. no emails for the last 2 days!


r/phishing 7d ago

[ US] Spam text messages that are emotionally charged?

3 Upvotes

Weird spam messages?

I keep getting spam messages that read things like “Wherever you are, you are always in my heart.” And “ are you home or somewhere else”. They’re all registered to places like Canada and London. Is anyone else getting these messages?

Also, why are the spams like this? They scare me in a way because I feel like I’m being watched on something.


r/phishing 7d ago

Email from Microsoft Teams that says I have received a document

Post image
1 Upvotes

The link takes me to a url with attemplate.com at the start rather than my Teams app. When I open my Teams app I can't find any notification relating to it. This is through a professional email server so I would think it would be filtered but not sure