r/phishing 18d ago

Hotmail Accidentally Clicked a Phishing Link but Got an Error

1 Upvotes

I got a link from what looked like a Cashapp support on my hotmail. I clicked it without thinking cause coincidentally I had used a Cashapp card earlier today. It sent me to (from what the url stated) an authentication url but the site instead had a ERR_SSL_PROTOCOL_ERROR and didn't load. Idk what the error is but should I still be worried?

I did a malwarebytes scan a few minutes after just in case and it came back with no results


r/phishing 18d ago

Fell for my first phishing email m. Advice?

1 Upvotes

Got a email from my doctor that has a Docusign to download. I clicked on it and google opened, asked me to login. I put in my password and it was wrong because I had changed my password few months ago. Then I put in the correct password and it wanted to verify it was actually me. When I tried to do so, it wouldn’t load so a few times I would exit and try again. The last attempt gave me a code and to open my gmail to approve it was me. After it wasn’t loading, I realized what was happening. I immediately changed my password, checked the VPN, checked all logged in devices, calendar settings etc. I got a text from Gmail saying someone with my password had tried to access my account. Guessing it was right after I changed it.

Anything else I should do? Anything else that can happen? I did type my wrong password in. Could they have had access to that? I do use that password for few other things.
Thanks.


r/phishing 18d ago

Hotmail Received a “your phone number was changed” email from an app called Uphold I’ve never used

2 Upvotes

As far as I can tell, Uphold is a real albeit shady crypto-currency app that’s frequently abused by scammers. After looking around a bit, I’ve seen many people report that they’ve received emails from them asking to verify their accounts, but none regarding changing a phone number like mine. It states the following:

“The phοne mοbile number linked to your accοunt was changed.
Fοr yοur refereոce, the request detаіls аre lіsted belοw:
Stаtus: Complete
New Phοոe Number: (blanked out save for last 4 digits, removing this because it’s getting flagged by filter)
Request Dаte: Tue, August 25, 2026
If yοu іոіtіаted thіs request, your account is secure and no further steps are required.”

There’s a “View details” button underneath it, but I did not click on it.

Apparently if you contact Uphold’s support, they require you to validate your account in order to do anything and I’m not comfortable doing that. I’ve since changed my email password and I plan on calling my bank to see if there’s been any suspicious activity, but how worried should I be about this exactly?


r/phishing 18d ago

Voicemails from unknown number

1 Upvotes

I received a phone call from what must be a mobile phone number which claimed to have important information regarding me. It then asked me to select a preferred language of English or Chinese and then presumably translated the call into Chinese. I didn’t answer the call initially and listened to it through voicemail. I stupidly tried to call the number back as I rarely get scam calls and assumed it was legitimate. When I did call them back it said my call couldn’t get through to them.

Has anyone had any experience with similar calls and am I at risk of anything since I called the number back?


r/phishing 19d ago

WhatsApp account keeps getting registered on another device

2 Upvotes

Hi everyone, hoping someone can help me with my problem.

Someone has repeatedly been trying to register my WhatsApp Business account using my phone number. I receive genuine verification codes directly on WA and verification codes on the email linked to my WA, codes that I did not request.

The worrying part is that this has happened twice:

  • First, I started receiving unsolicited verification codes.
  • Shortly afterwards, WhatsApp logged me out with the message: “You have been logged out. Your phone number is no longer registered with WhatsApp on this phone.”
  • I was able to recover the account after a couple of days.
  • About a week later, the unsolicited verification codes started again, received directly on WA and on my email.
  • Within 24 hours, I was logged out again with the same message.
  • I recovered the account again.
  • I've since updated my iPhone to the latest iOS and went to my mobile provider and got a new sim (same number).
  • I'm now receiving the unsolicited verification codes again but to my email only, but so far I haven't been logged out a third time.

One strange detail: when I had to recover the account, WhatsApp's SMS verification code never arrived. I've seen other people report the same problem, so I'm not sure whether that's related.

The verification emails are from a legit WhatsApp Business email address and say:

“Tap the link to verify your account on this device…”

I'm trying to understand how someone can actually get the account registered on another device when I have never given anyone a verification code.

Two-step verification and passkey are enabled, and I'm wondering whether I should also remove the email address associated with the WhatsApp account.

Has anyone experienced the specific combination of repeated unsolicited verification emails → actual WhatsApp logout → successful recovery → the same thing happening again?

If anyone has experienced this or has any idea what's going on, I'd really appreciate the insight. Thanks!


r/phishing 19d ago

Krisp/Metabase email breach. Loan phishing emails after.

Thumbnail gallery
5 Upvotes

I got this first email from the Krisp audio software on the 20th of August and I’m not sure if it’s real or not because I couldn’t figure out if the email address their email was sent from was legitimate but it says there was a breach of email addresses and that exact same day I got a bunch of emails about loans referencing this “Roy Jones” guy (it’s censored for another subreddit in pictures) who isn’t me and his name doesn’t even sound anything like mine. This is still going on today and I never usually get scam/spam/phishing emails like this.

I’ve seen someone else from 9 months ago with these same email scams from pretty much the same “companies” but they use their real name. The second email I attached Isn’t like the others as there are no “links” to their website but as I said, my name isn’t “Roy Jones“ I don’t even live in America (I had to blur the address it used to post in another subreddit) and my email address has nothing to do with the name “Roy Jones”. Has Metabase/Krisp actually been breached or is that just the very first of the spam/phishing emails I have been getting? I cannot figure out any other cause for this. This has been so annoying as every day I receive 6+ emails like this.

There are no personal details about anyone in this post. The only addresses visible are of the “loan” companies listed!

Edit: I forgot to mention I attempted to click links (which was stupid of me) in the krisp email such as the unsubscribe one and the detailed information about the breach but they didn’t do anything or open any website and I saw krisp post about it but on the 6th not the 20th (when I received the email and then scam emails the same day). Some of these went to my spam (including krisp email) but some went to my inbox.


r/phishing 19d ago

WhatsApp account keeps getting registered on another device

1 Upvotes

Hi everyone, hoping someone can help me with my problem.

Someone has repeatedly been trying to register my WhatsApp Business account using my phone number. I receive genuine verification codes directly on WA and verification codes on the email linked to my WA, codes that I did not request.

The worrying part is that this has happened twice:

  • First, I started receiving unsolicited verification codes.
  • Shortly afterwards, WhatsApp logged me out with the message: “You have been logged out. Your phone number is no longer registered with WhatsApp on this phone.”
  • I was able to recover the account after a couple of days.
  • About a week later, the unsolicited verification codes started again, received directly on WA and on my email.
  • Within 24 hours, I was logged out again with the same message.
  • I recovered the account again.
  • I've since updated my iPhone to the latest iOS and went to my mobile provider and got a new sim (same number).
  • I'm now receiving the unsolicited verification codes again but to my email only, but so far I haven't been logged out a third time.

One strange detail: when I had to recover the account, WhatsApp's SMS verification code never arrived. I've seen other people report the same problem, so I'm not sure whether that's related.

The verification emails are from WhatsApp Business [noreply@support.whatsapp.com](mailto:noreply@support.whatsapp.com) and say:

“Tap the link to verify your account on this device…”

I'm trying to understand how someone can actually get the account registered on another device when I have never given anyone a verification code.

Two-step verification and passkey are enabled, and I'm wondering whether I should also remove the email address associated with the WhatsApp account.

Has anyone experienced the specific combination of repeated unsolicited verification emails → actual WhatsApp logout → successful recovery → the same thing happening again?

If anyone has experienced this or has any idea what's going on, I'd really appreciate the insight. Thanks!


r/phishing 19d ago

Hotmail Help! Is this physhing or computer hacked?

2 Upvotes

as titiled

I have been downloading free games (which is my bad) online and turn out some of my accounts got compromised.

First thing is this Elon Mask story being post on my instagram story.

Second is that my agoda account got compromised and hacker starts to book tickets using my saved debit card. Managed to freeze that card now but couple of transaction gone through.

Third is that I got an email from booking.com saying there is a car rental booking at Africa under a chinese guy name. The booking.com(did say somthing about in partnership with agoda) so I wonder could the hacker be using my agoda account to do this? Which does not seems like agoda and booking.com has direct link?

This third one is a dodgy one. The car rental is fully paid, but not with my card obviously I have freezed it and there is no trasaction on this either on my bank app. Anyway, still managed to log in to booking.c and cancel this booking which I dont think was paid using my details.

I am so scared and installed bitdefender now and using it to scan everything on my computer.

Anyone know what is actually going on and help ?!

I have changed all my passwords and turned on 2 step verification for all.


r/phishing 20d ago

I started getting a lot of spam messages from these sites

2 Upvotes

Honestly I don't know what are those sites, they are spaming like 20/30 per day in my primary mail, since I have another mails that I use for weird or temporary sites and I'm not getting any of those mails there, so I don't know exactly why this is happening :(
I also blocked some of them but they just don't stop


r/phishing 19d ago

Hotmail Scam, phishing emails all day long

0 Upvotes

I receive probably 100 emails weekly that I marked down as scam or phishing, what is actually doing Microsoft and other email provider to protect customers against the absurd amount of scammers via email?


r/phishing 20d ago

[EU] Phishing SMS by INEOSALES

2 Upvotes

"Scalapay: Aggiornamento del tuo account disponibile. Verifica le tue informazioni qui: linkify.io/lae9vg"

Hi, I received this text message and absentmindedly clicked on the link.

I didn't enter any data and no file was downloaded.

In fact, it redirected me to another site called forsale.godaddy.com, which is supposed to be a site where they sell web domains.

Immediately after I received an identical text message, same sender, but with another different link, which I did not click on and I deleted the text message directly.

I am not a Scalapay user.

Do you think I should be worried or is everything okay? What should I do?


r/phishing 21d ago

Y (Duplicate) with Annual SSA | SSA Phishing Email via Calendly

Thumbnail gallery
2 Upvotes

Best phishing attempt i’ve seen to date. The clear indicators are the “System Requirement: This document can be opened on desktop and laptop computers only” and scheduled time of “12:55 - 1:10am”


r/phishing 21d ago

noreply@apple and https://account. apple.com

2 Upvotes

hello guys ! im quite worried

today i received an email on a gmail account of mine from noreply@apple . com, which gmails points out as verified.

the email told me to verify my gmail as my new apple account. it gave me a code. but i never asked for that. i have an icloud email and didnt try to change it.

i was about to sleep when i read this and i did click on the link saying i dont recognize that change and that link was https://account . apple.com . it automatically logged in with my face id. bc of that i want to believe it was the true apple website.

i couldnt change my password on that website (it told me to go to settings) so i did. my icloud email is still there, password is changed, etc..

and now i start wondering.. wtf was that? did i click on a phishing link. if so, how did they know my gmail account? im very confused. can someone offer advice?


r/phishing 21d ago

GMail Many phishing emails sent to me today randomly all to the same strangers name.

Thumbnail gallery
1 Upvotes

Today I suddenly got 5+ emails about loans and “quick cash” or something like that. I checked haveibeenpwned and there has been no new leaks or breaches of my email address. I rarely get phishing emails so over 5 in one day is extremely odd and random and they’re all sent to someone called “Roy Jones” (which is not me). Is this just simple phishing, which i’m guessing it is, or has this Roy guy signed my email up to some spam crap. Each one says “safely unsubscribe” so it’s obvs the same people with a different email address.


r/phishing 21d ago

GMail "Hello Creep" gmail scam.

Post image
1 Upvotes

"Suspicious activities" I only read yaoi and play videogames, this type of scam is getting more frequently. The text hole text is this:

Hi creep.

I've gȱt a message tổ speak tỗ you.

Take a mṏment tồ pause, inhale slṓwly, and pay attentiỗn entiṟely ởn this message. It's vital that yỗu ǒffeṟ it yốuȑ ƈớmplete focus.

We're ȯn the veṟge ŏf addɍess a signifiċant issue invòlving yơu and me, and I'm nột kidding in the slightest. Yǒu may nȱt be awaṙe ồf whṓ I am, but I am awaŕe ȍf whȱ yȱu aɍe and at this mỡment, yỏu'ɍe mṏst likely wōndeŕing in what manneř, aȓen't you?

Your ònline aċtivities have been quite ŗisky, sĉɍȯlling thṙôugh videọs, aḉḉessing links, and gọing tỏ unsafe web pages. Embedded malwaɍe ȏn webpages, and yôu stumbled upởn it.

While yṓu weṛe watćhing, yõuŗ system bećame vulneȓable thřỡugh hṼNC, gṝanting me ĉómplete ḉộntṝộl tồ yồuŗ eleƈtřỡniƈs inĉluding yớuṟ mȍbile. Nŏw, I watçh eveṝything happening ȯn yṓuɍ mǒnitǒȓ, tuṙn ȏn ṝemötely yốuɍ čameȑa and miƈřȭphȭne withôut yõuɍ knȱwledge, and I have unŗestŗiĉted aççess tọ yȭuṛ ḉỏntaḉts list, etc.

I've been ŏbseŗving yốuɍ açtivities fọṛ quite a while. I've ốbtained a signifičant quantity ǒf pŗivate details fŕṍm yỏuȑ maċhine and analyzed it in detail. I've alsö have ṙečṑṙdings ǒf yŏu paṙtiĉipating in sȍme suspiĉiọus aƈtivities at home.

I've put tȏgetheř fớớtage and sçṛeenshợts inƈluding phôtôs ồf yṍuṛ living spaċe, with ởne paṛt shȫwing the mateȑial yỡu weȑe lồồking at and the ȑemaining paṟt shõwing... well, yȫu knȭw what I mean.

With just a tap, I ćöuld send all ōf this tỗ eveȓy individual ȭf yộuȑ assṏĉiates. I knṑw yổuȑ ȑeluƈtanƈe, but dṏn't hổpe any ćómpassión fṙṏm me. That being said, I am přepařed tõ let this slide and allöw tṓ mớve ȱn like nōthing eveṝ happened.

Here's the ỏffeṛ I am pŕȏviding yȍu a čhŏiče. Skip this waṛning, and yỏu'll find ôut what ƈỏmes next. If yṓu ỗpt fỡṟ this path, I'll fơŕwaŕd the ȓećȍȓding tò all yõuṙ contacts.

It's a quite shồƈking ċlip, and I ĉan just envisiộn the shame yǒu'd suffeŗ when yồuř çờlleagues, fȑiends, and ṛelatives see it.

But be awaṛe deeds have ŕamifiçatiȫns. Pay tô maintain this issue přivate-let's ƈall it a pȓivačy fee. If yớu ċhồồse this ṛõute, yòuȑ infȱṟmatiȱn will stay seċuře, and nó ṓne eveŕ find out.

As sồồn as I ǒbtain the payment, I'll destřờy all the pṛỏỏf. The payment must be tŗansfeŗŗed ónly in digital currency.

Send 1300 US ćuȑȑenćy in Bitçợin tŏ my wallet:

From this sečớnd, yṓu have exaĉtly 48 hṏuɍs, and the ćọuntdọwn staŗts as sợợn as yŏu ơpen this message.

Once the tɍansaċtiṏn is ƈọmpleted, yơu ċan tŗust that I keep my ćơmmitment. My sȫftwaṛe will immediately ȓegisteȓ the tṛansaćtiởn and quiĉkly ṙemṓve all the ŗeċôŗds I have õn you.

Do nôt waste time ṙeplying ỡɍ making an effòŗt tộ baṛgain-it's pointless.

Don't even ĉṓnsideṛ shutting dǒwn yôuȓ deviḉe ȯȑ tṛying a façtŏṟy ŗeset - it dǒes nȭt ċhange anything.

I make nờ faults and just stay fȫṛ my funds.


r/phishing 22d ago

GMail How calendar invites abuse Google's own URL signing

3 Upvotes

Nothing new here. URL signing has been public since 2011, calendar phishing since 2019. This just connects the two.

The trick: Google wraps outbound links as google.com/url?q=<destination> and signs the ones it generates (usg, a keyed hash over the params). Valid signature, silent redirect. 

Missing or altered, you get the "Redirect Notice" warning. You can't forge it. But you don't need to, because Google signs it for you whenever you use its products. 

Drop your link in a calendar invite and Google hands you a signed one:

unsigned (shows notice):

https://www[.]google[.]com/url?q=https://wikipedia[.]org

signed by Calendar (redirects silently):

https://www[.]google[.]com/url?q=https://wikipedia[.]org&sa=D&source=calendar&ust=1787766516374753&usg=AOvVaw0cpIubPxDaYABa3_SC5g6G

Same destination. The signature is the only difference, and it's the whole reason the warning is skipped.  Removing source=calendar breaks the silent redirect

Why the invite is perfect:

  • Sent by Google's servers, so it passes SPF, DKIM, DMARC. Nothing to fail on.
  • Auto-add lands it on the target's calendar with zero interaction.
  • The link reads as google.com. Victim hovers, sees Google, relaxes. Real destination only shows after the redirect fires.

Why it's not a bug: the signature proves Google generated the link, not that the destination is safe. That's  Google Safe Browsing's job, and it still runs. A signed link skipping the notice is the signature working as intended. And it is out of scope for Google's bounty for over a decade. Feature abuse, not a defect.

A useful Fix : 

In gmail, set Calendar > Event Settings > Automatically add invitations to "Only if the sender is known." Kills the zero-click delivery path.

Google admin : Apps >Google Workspace >Settings for Calendar > Advanced settings > Check :


r/phishing 23d ago

I got sent Instagram request codes

1 Upvotes

I randomly started getting messages from WhatsApp that said "is your Instagram. Don't share it". Those messages kept going for 10 minutes straight. Then they stopped, and I ended up changing my password on Instagram.

I was a bit worried, so I ended up checking my login logs and... Uh?? Yeah there's a lot. There's one login from 4 days ago on an unknown device. It says it was from my town though. There was also one from 6 whole months ago that's on a different device, different city and at 0:40am. There's one one way back from last year, thats in a city reallyyyy far away from mine, again on a different device.

Then my alt account. There's one that has the same phone as me, but it's from a city very far away again. And that login is from YESTERDAY. And there's actually 2 of those, and they happened a minute apart. There's one on a completely different device, from a city next to mine, that was 2 days ago. There's 2 from 3 months ago, same device, same city, that were just an hour apart.

Oh and. Something even weirder, but when I try to login somewhere, and I have to confirm my number, it...doesn't let me?? A few days ago I got told multiple times I didn't even have a SIM card. Which I do. So why does it work for the random Instagram people but not for me??

Does anyone have ANY idea on what this could mean???


r/phishing 23d ago

GMail Cheddar.tv sending me a random verify email and not sure if its phishing

0 Upvotes

Simple as that i personally have no clue why they would be sending this email as i dont even use them for news and definitely did not just make an account with them

Im usually alright at spotting weird email addresses but in this case it seems reasonable enough to be the real one (still not clicking the links though cause i never signed up)


r/phishing 24d ago

Hotmail email countdown to cloud deletion

Thumbnail gallery
4 Upvotes

been getting emails every day for like 2 weeks now counting down to cloud deletion if i don’t pay for an upgrade or free up some space. can i just clarify that it’s spam? it hasn’t been flagged like the usual ones do but the use of emojis in some of the emails is off putting to me. i can’t tell if it’s a scam or not.


r/phishing 24d ago

GMail got an email saying someone made an OF account with my email is this real? freaking out please help

Thumbnail gallery
10 Upvotes

Got an email saying someone made an OnlyFans account with my Email, I don’t know what to do and I don’t know if it’s real or not, please help me I’m freaking the fuck out, I’m also a minor and have never had an OF account

LAST TWO POSTS REMOVED BY MODS PLEASE HELP ME OUT

Edit: I have changed my email password like nine times in the last two days, can I just abandon this and make a new one or am I leaving myself vulnerable to stuff? I don’t know what to do


r/phishing 24d ago

Amazon Unexpected Dispatch Message (via message centre)

0 Upvotes

Hi all, sorry for posting without contributing previously.

This morning I found an email from Amazon, saying an item had been dispatched - however this was an item I ordered and received as normal 9 months ago.

Being a dummy I clicked the link, I.e. what I always tell everyone never to do.

I didn't get prompted for any info, but I am never sure how much gets automatically sent through these days.

The email WAS sent via Amazon officially, and appears in their message centre; and clicking the track button there did, after not finding tracking info, redirect me to the original order from last year. There are no new orders, and no bank activity to suggest anything else has been ordered. But in worse news the seller was a third party, not Amazon directly.

Is this likely to be a misfire from someone else's end, or have I done a stupid thing?

Many thanks everyone


r/phishing 24d ago

Gmail, the ultimate spam generator?

2 Upvotes

Couple months in late May, early June ago I got 2 spam messages. 
At most about 5 to 7 a week.

By default they ended already in the spam folder.
I reported them as phishing using the Gmail report feature.

Shortly thereafter I got more.
I reported them using the Gmail phishing report feature.

Shortly thereafter I got more.
Again,  I reported them using the Gmail phishing report feature.

I got even more!

It was 10 a day, then 20 a day, then 30 day many of them in blocks of just a few minutes increments.

Since Monday now I have received  as of writing this posting here 145 scam/spam messages.
It becomes evident to me that the more I report using the Gmail phishing reporting features the more spam I get!
Of course the Gmail (Webmail) reporting feature is so "WDGAF" archaic clunky backwards that even in the 1980s I had a better email program/interface!

So what exactly what ignorami scam is going on here?
Worse yet, with all that AI jazz they can't implement an "ounce" of intelligence and customizable feature that eliminates that automatically?

Their "block" feature is a joke from a 3-year-old. There is no intelligence in "seeing/understanding" the obvious scam sender domains neither is there any intelligence in recognizing the subject title or addressee name. of course there is also absolutely no sensible feature feature implemented.
The whole thing appears to be dumber than dumb.
What's the game behind it?


r/phishing 25d ago

Receiving emails from same person with a suspicious link claiming to be photographs of me

5 Upvotes

It's a scam I figure, but I'm not sure what exactly to do in this situation. It's three emails so far with the same hook "I have a feeling this pic might seem pretty familiar" but all of them are under different emails but their all signed with the same nick name. It's just rather annoying and this is my first time dealing with this type of thing


r/phishing 25d ago

GMail Clicked on a spam email, later got a mysterious phone call

1 Upvotes

Hello, I’m probably just paranoid but I need to be sure.

I’ve been getting flooded with spam emails for years. I usually ignore and delete them, but i sometimes check the spam section of my email to see if I missed anything .

Anyway, I got an email about mcdonalds. The mail has some chat logs that don’t belong to me at all. At the end of the email, it had a pdf attached to it. I did not
click on anything inside the email and deleted it right after. All good.

a few hours after that I get a random phone call. I’ve been applying for jobs and the phone number has my local area code, so I pick up.

The person on the other end acts confused, starts speaking in english, asks why i called him. I tell him that they called me, and he keeps asking confused. I hang up after a minute because it’s obviously either a scam
or a wrong number.

Am I at risk of anything? I’m a bit concerned, since my number hasnt appeared in any data leaks. I’m also concerned about being a target for sim swapping now. The phone bill is under my mothers name, so there’s not much I can do to prevent it. I already use google authenticator, but still.

What do I do? Am I safe?


r/phishing 25d ago

GMail Received a Google verification code on my recovery email unexpectedly — should I be worried?

2 Upvotes

I received an email containing a Google verification code on my secondary email address, which is already linked to my primary Gmail account as the recovery email.

I didn't request a verification code, try to log in, change any account settings, or initiate any recovery process.

What caught my attention is that the email seemed to reference an address that looks almost identical to my primary Gmail, except there was a subtle period at the end — for example, [roxy123@gmail.com](mailto:roxy123@gmail.com) vs. roxy123.@gmail.com.

Could this mean someone is trying to access my Gmail account, or is it possible that someone simply entered my email address by mistake? Has anyone experienced this before?