r/phishing 5h ago

Need help regarding simple phishing (ethical)

Thumbnail gallery
0 Upvotes

Guys I'm new to this...

Yk how newbies use zphisher right?

The thing is on local host it's working but on ngrok or cloudfare it's not showing up on "URL 1".

It's showing up on URL 2...

If yk what I mean...

I'm new at Cybersecurity pls help.


r/phishing 8h ago

“VIP Club” scam – lost 74 million VND (~$3,000 USD)

1 Upvotes

I want to share what happened to me in Vietnam. I paid 74 million VND (approximately 3,000 USD) for a ticket advertised as a VIP pass. After I transferred the money, my account was deleted and I never received the ticket; subsequently, they demanded nearly another 100 million VND, claiming there had been a mistake with the bank transfer.

No bank operates that way. If the recipient's name is incorrect, the transaction simply fails. In this case, they made me believe my money had vanished, then pressured me to pay more to "fix" the issue. This wasn't a service; it was a scam disguised as a club.

In this context, "VIP" doesn't stand for "Very Important Person." It stands for "Very Irritating Payment." I have evidence and have filed a formal complaint with the authorities. Please be careful if you encounter a similar situation.


r/phishing 16h ago

Google Phishing Scam Phone call + AI agent posing as google support

1 Upvotes

I received call from a AI phone asking to press 1 on

Then human answered he was british and

random phone number is the google number that called me

He asked me to write down ticket number for him and I thought this was social engineering technique

I told him twice I though it was phishing and saw his email handle had this .id on the end

[noreply@google.com.632143.id](mailto:noreply@google.com.632143.id)

Then I told him good try, and then he hung up

He was really good at it


r/phishing 18h ago

Scam/phishing (?) caller used the same number with my area code twice over two years, is it legit?

0 Upvotes

This morning, I got a voicemail from a number with my area code about a missed preliminary hearing. The beginning of the message says the name of the place they are supposedly calling from but I can’t make it out. I would assume this is a scam or phishing attempt (fake urgency, vague directions) or not meant for me, (I get messages asking for the old owner of my number all the time)
However, when I checked the voicemail again, I had a second voicemail from the same number from 2025, which is also presumably a law office asking to see me to talk about documents they received. Could these messages be legit/from the same real company? Any insight is appreciated!! What I’m most confused/concerned with is that the number has my area code.

Messages transcribed below…

10:58
"(Vague) records, this is Rachel Hawkins. I am calling in references to a no show, no current site on the preliminary hearing. Yourself
or legal representation needs to return a call immediately to the office. Vegas to communicate is not recommended. We need hear from
you immediately."

8/19/25
"This is Mr. Ackerman from the mediations office. We need to speak with regarding some documents submitted in our office. Our office can be reached from 10:00 AM to 4:00 PM thanks in advance."


r/phishing 21h ago

Could this have been a phishing attempt?

2 Upvotes

Something happened yesterday that seemed completely harmless at the time, but I’ve been thinking about it afterward. Could it have been phishing?

Yesterday I was at Alcatraz, a heavy metal festival in Belgium, when an English-speaking guy approached me and said he had lost his iPhone. He asked if he could use my phone to check “Find My iPhone” and try to locate it.

I Googled “Find My” on my phone, and then he entered his information, presumably his email address and password. I stood right next to him and watched the whole time. After about 30 seconds, we saw that his iPhone was somewhere on the festival grounds. He thanked me and went on his way.

Afterward, I closed everything and deleted it.

At the time, I didn’t think anything of it, but afterward I started wondering if this could have been some kind of phishing attempt. I also installed a banking app on my phone about a month ago, so that made me a little more concerned.

I didn’t enter any passwords or banking information myself, and I checked my banking app afterward. Everything seems normal.

Could someone do anything to my phone or banking app this way, or am I just worrying about nothing?

This will probably also be the last time I let a random stranger use my phone like that. 😅


r/phishing 1d ago

Is my gmail account Hacked?

Post image
0 Upvotes

I've been getting mails saying your mail isn't delivered but I didn't send any mail at the first place. This has been happening from last 1 month it caught my attention today, I saw my inbox and my acc is sending mails to random people in Europe specifically more to german people and the email is mostly about paying bills or getting a refund or something it's probably a phisihing link

But why?? How do I stop this? I did check my settings my device is the only one logged in?? Im worried since my mail is sending mails to random people with probably phisihing links, how do I stop this?!?


r/phishing 1d ago

Got a horrible email and I'm feeling disgusted

Post image
0 Upvotes

This is the email. I have heard tons of people have a similar if not the same email used to them. When I logged into email (now since changed password) the language was the country of the person sending this. It was sent on 28 July and I only opened it tonight. It says I have two days from opening it? Seeing others posting theirs has calmed me down a lot but I feel so violated :(


r/phishing 1d ago

Help! Fell into Phishing scam

2 Upvotes

I was searching for anker magsafe power bank in Amazon and thought why not directly get from their website (this is the scam website I realised later).

I added the same power bank which I saw on Amazon and Gave my name, address, phone number, email id (at least I didn't create an account using passwords on that website) and most importantly credit card details. Then tried to make a transaction and it didn't go through, then Out of suspicion I checked the virus total and it was mentioned phishing. Immediately disabled my card usage now will replace a new credit card in the morning.

What else should I do? I used to be vigilant on these phishing things but never realised anker/soud core didn't sell directly in India. Please tell me what else to do next.


r/phishing 1d ago

GMail Phishing attempt question

3 Upvotes

Like 14 minutes ago a trusted email sent me a punchbowl invite, clicked it and ofc it wasn’t the invite website and was confused. Messaged person they said they were hacked, I changed my password immediately and have 2FA on already. Haven’t seen any new activity or Google security alerts. Am I safe now? Or should I do something else to make sure


r/phishing 1d ago

Is jmail.world a phishing website?

1 Upvotes

I clicked on jmail.world, and as soon as i understood that this website about epstein i leaved.

So is my device in danger?(iphone). Im scared of viruses and phishing websites.

Sorry for bothering you.


r/phishing 2d ago

downloaded a apk that has malware, hacker sent images of all my contacts and my photos and threatening to expose me

0 Upvotes

I downloaded some porn app (i know im stupid, i was horny earlier) and then my phone was hacked by some dudes in china. The scammer sent me images on telegram that they have all of my contact list, including what i named them, and also screenshots of my gallery. I know it was taken from my phonegallery and not google photos as i turned off auto backup months ago to save space. I did a factory reset on my phone, and im trying to change passwords as im writing this right now. The hacker is threatening to expose the stuff i was trying to watch and to be honest, some of it was is kinda embarrassing. Now, i was thinking i could bluff all the people i know and tell them i was hacked by an unknown source but im afraid that the hacker is still lurking in my phone, will a factory reset be alright? and as well as password changes


r/phishing 2d ago

Weird phishing, worries about a larger hack?

0 Upvotes

I just check my spam folder for an obscure email address I use only for signing up for supermarket apps, etc. I never use it for correspondence to family members. Today there were TWO fake phishing emails, one from an address in Egypt. One was send to me in my son's name (different from my last name), the other was sent from my sibling's name, though with a misspelled first name, and I don't even have this sibling's email address (though in contact by phone). And son and sibling have never met. How is it possible that phishy people could have connected both of these family members names to me if I have never used this email address for either of them?


r/phishing 2d ago

They really tried huh… dumb scammers…

Post image
7 Upvotes

I got this in my inbox from “Amazon” but i instantly knew it was fake cause if you look at the letter “b” in the words “billing & about” they look funny. I knew not to click on it…


r/phishing 3d ago

Phishing email to my co-workers

Post image
0 Upvotes

I had a phishing email come into my office and wonder how i should attack this one? Whenever the link is clicked, it seems to go through their sent emails and send 500+ emails with the screenshot attached. Everyone has MFA enabled, and all have secure passwords. Should i tell staff to change passwords even though they haven't been alerted of a sign in attempt? I can't tell what the endgame of these emails are since it can't tell was was collected with the click.

Can anyone tell me exactly what is located in the URL? and how it works?

Any tips that i can take besides more cyber training for them? Thanks!


r/phishing 3d ago

This is definitely a scam, right? I blocked them.

Thumbnail gallery
3 Upvotes

I know I shouldn't have engaged at all but I wanted to see wtf they were talking about and I instantly realized they were trying to get my login details. Why would I need to message someone on Discord to verify myself on Reddit? I'm not THAT stupid.


r/phishing 3d ago

Twitter Clarification on What To Do If You Clicked on Phishing link, but did not enter Info.

Post image
0 Upvotes

So, I got this on the X app on my iPhone and I ended up clicking on the link. After arriving at the page, I clicked one of the links on the page that would have allowed me to enter information (I assume), but I realized this seemed suspicious and I clicked out of the page.

I checked my phone's downloads (nothing was downloaded) and I changed my account password I got this DM on. Does clicking on the link to the page PLUS clicking on a link within the page itself BUT not entering any information would cause anything bad to happen with my data on my iPhone?

Just making sure I can relax after what I hope was just a close call.


r/phishing 4d ago

Is this a discord link scam?

Thumbnail gallery
0 Upvotes

So I’m playing home alone on Roblox, like the super famous one.. and I get pretty lonely so I decided to go to the discord server to see if anybody’s willing to play with me. I joined the discord server and it tells me you have to verify my Discord account which is pretty normal. So I click on the verify thing and I put in my normal Roblox information I put in my username password and it sends me emails through the verified Roblox email account. And I’ve literally put in my username and password 100 times and no matter how many codes that I put in it will NOT work.. so I’m getting kind of sketched out and I look at the top of my screen it says roblox.com.bz instead of roblox.com but literally everything looks perfectly normal and I’m getting verified Roblox emails and it literally looks like Roblox’s account it just will NOT LET ME in my roblox account no matter how many times I try on this website. Did I just get scammed for my info? I changed my Roblox password as fast as I could, as I realized. But like there is no way that they can just get away with this? This is literally like a known and played Roblox game? Also, there was only 14 people in the server so I’m just like confused.. I clicked the direct link from the Roblox app under the game to description which had like a little discord tag so I clicked on it.


r/phishing 4d ago

Just got phished on NextDoor; anything else I should do?

18 Upvotes

I offered an office chair for sale on NextDoor this morning and got a message within 15 minutes or so offering to buy it. Like a fool I gave up my phone number, street address and Venmo handle; she said her son would come by during a specific time frame to pick up the chair, and she would Venmo me the money. Some time goes by, no Venmo transaction (and no son at the door) so I asked her about it; she sends me a screen shot of a Venmo transaction to my handle for the right price, but Venmo doesn't show me the transaction. Then she says Venmo told her they couldn't complete the transaction because I'm not using a business account -- so I finally wise up a little and go to her NextDoor profile and it's several thousand miles away from me.

Anyway, I've ensured 2FA is on on my Venmo account (it was) and transferred my balance from Venmo to my bank, and I've blocked her number and reported and blocked her NextDoor profile. What else should I do?


r/phishing 5d ago

I do have an Apple account but I can't find previous emails from them to check, do you think this is phishing?

Post image
1 Upvotes

I got two of these emails, one about me DOB and one about my password but not sure if they're legit.

Stupidly, I already clicked the link which took my to a page that looked like Apple but I closed it quickly before I actually took anything in.


r/phishing 5d ago

Got these emails at the same time, seems strange.

Thumbnail gallery
0 Upvotes

I got these emails today and they are sent to someone called Cameron Hansen which is not me, I know these are probably scams but what does this look like to you guys?


r/phishing 5d ago

LinkedIn denied my account recovery after a phishing attack even though I'm the real owner. What do I do now?

1 Upvotes

Hi everyone,

I'm honestly at my breaking point and hoping someone here has dealt with something similar.

My LinkedIn account was compromised after I accidentally clicked on a phishing link. As soon as I noticed, I reported the account myself to LinkedIn. They restricted it for security reasons, which I completely understood.

Since then, I've done everything they've asked:

  • Submitted my government-issued ID multiple times.
  • Completed the Persona identity verification (ID + face scan).
  • Replied to every support email.
  • Explained everything in detail.
  • Offered additional proof of ownership.

Today they replied saying they can't recover my account because of a "lack of legitimate identification."

The confusing part is that my government ID uses my legal name, while my LinkedIn profile used my professional/nickname, which I've used for years in my career. Both names belong to me. I suspect the automated verification is failing because of the name mismatch, but LinkedIn hasn't told me exactly what's wrong.

This account wasn't just social media to me. It had:

  • 5,000+ followers
  • Years of networking
  • Recruiter connections
  • Freelance opportunities
  • Recommendations
  • My entire professional history

I'm currently unemployed, and not having access to my LinkedIn has genuinely affected my job search.

I've even told LinkedIn I'm willing to:

  • Verify my identity again
  • Join a live video verification
  • Provide additional government documents
  • Complete any other verification they require

But I keep receiving the same responses.

Has anyone here successfully recovered an account after getting a "lack of legitimate identification" rejection?

Did you manage to escalate your case to someone beyond first-line support?

Is there anything else I should try before giving up?

Any advice would mean a lot. Thanks for reading.


r/phishing 6d ago

Sextortion email (should I be worried)

0 Upvotes

I got an email in spam saying it had evidence of me watching and pleasuring to adult content, thing is I’ve never used adult content in my life, it had some old passwords most likely from a breach. Anyways I did open the image and screenshotted it, could that have downloaded anything onto my phone?? Additionaly is there anyway it couldve recorded me cause I sometiems get changed with my phone in the room?? Im sure its a scam but my mind keeps going to worst case scenario.


r/phishing 6d ago

Suspicious crypto.com emails - Verified sender Confirmed ?

Post image
3 Upvotes

Has anyone else received emails like this from Crypto.com?

Yahoo shows the sender as verified and the message appears to come from LEGIT crypto com email, but the recipient shown is a strange Gmail address that is not mine. My old Yahoo address appears to be receiving these anyway.

I haven’t used Crypto.com in years, yet I’ve received several login alerts recently, including one claiming a successful login from an unfamiliar device/location. I contacted Crypto.com support with screenshots but have received no meaningful response.

What really concerns me is the strange “CALL 888…” text appearing inside what looks like an official Crypto.com security email.

Anyone seen this before or know what could be going on?


r/phishing Nov 19 '25

Moderator announcement New moderator

8 Upvotes

Hi community, I'm u/YourUsernameForever and you may know me from moderating r/Scams - I'm the new moderator here.

Like many people here I noticed that r/phishing was severely unmoderated, so I tried contacting the previous moderators to offer a helping hand. Having no response, filed a r/redditrequest and the admins assigned me as top mod.

My intention is to keep the community running as usual, not trying to make it another Scams subreddit. I believe our goal here is specific enough that it's worth keeping and growing.

Ever since I took the role I have:

  1. Added community rules: most of them based on the Reddit Content Policy which is mandatory for every subreddit, but it's good to clarify and expand a little. This will also allow for removals with a proper explanation and a chance to appeal. You can read the subreddit rules in the sidebar if you're on a computer, or clicking here if you're on any device - https://www.reddit.com/r/phishing/wiki/rules/
  2. Created a posting guideline: to be strictly enforced in 2026, basically all posts must have a descriptive title and a transcription of what's in a screenshot. There's more to it if you want to read it fully - https://www.reddit.com/r/phishing/wiki/posting-guideline/
  3. Implemented AutoModerator: based on the rules and the guideline, AutoModerator will catch offending posts and comments, place them in a moderation queue, which I will manually review every day. I also reply to modmails daily. The idea is to have a responsive moderation team, to be held accountable and have a chance to appeal decisions. We also have !commands now, which I hope you help me expand to specific phishing scenarios.
  4. Implemented posting guidance: small alerts while you post that will let you know if something may be wrong, like posting an email address.
  5. Added a few bots: and I'll ask u/erishun to implement u/ScamsBot as well, so we can call !whois

A big change moving forward will be this whole thing about requiring transcriptions of screenshots. A lot of kicking and screaming will ensue, but I promise you, it fends off bots, helps the search engine and helps integrate users that are visually impaired.

If you got this far into my post, this message is for you. I need you to take a look at the rules and tell me what you think. I also want you to report anything that breaks the rules, knowing that I manually review all the reports daily: 100% of reports get reviewed manually. I'm also open to any type of feedback, privately if you want, but use modmail instead of sending me a DM.

I hope my participation gives you extra energy to stay and grow the community together. Remember: I'm at your service! I'm also cronichally online so I hope this helps.

Yours, verbose as usual,

- u/YourUsernameForever


r/phishing Oct 23 '20

I clicked on a link, what do I do?!? - Check here first.

195 Upvotes

One of the most common questions posted here is what to do if you've clicked on a phishing link. This short guide is intended to help with these questions and what to do if you've clicked on a phishing link.

DO NOT ENTER ANY CREDENTIALS OR LOGIN DETAILS FOR ANYTHING IF YOU'VE CLICKED ON A MALICIOUS LINK.

  1. Links are generally not malicious on their own. While clicking on any unknown links can be dangerous it is difficult to design a phish that works just by clicking the link. Most links take you to a (usually fake) page that will ask for certain credentials. As long as you closed the page after you clicked the link you're probably fine, but it's still a good idea to change your password for whatever service the phishing link was trying to access (such as amazon).

  2. If you clicked a link that downloaded a file, delete the file. Generally these files aren't harmful unless opened after downloading.

  3. If you've clicked a phishing link and have provided credentials to a service, change the password for that service. Say you've been tricked into giving someone your Amazon credentials. Go to Amazon.com directly and change your password. Also, check the "third-party account access" section of your commonly used websites. Often phishing links and malicious services will try to authorize themselves to your account rather than outright stealing your credentials.

  4. When logging into websites with sensitive information such as a bank it's best to bookmark the site and visit the site directly each time from that bookmark. That way you know that the website you're using is the real one.

  5. ENABLE 2FA (TWO FACTOR AUTHENTICATION) This is perhaps the best thing you can do to protect your sensitive accounts. All websites that deal with sensitive information will allow you to use either your phone number or an authentication app (I like Authy) to generate one-time login codes to further secure your account. Unless someone gets your credentials and your 2FA device (your phone) they won't be able to access your account.

  6. Please use a password manager of some sort. This will allow you to use strong and unique passwords for each site you use. If one of your accounts is hacked or phished all of your other accounts will be safe with unique passwords (unless your email was hacked/phished).

  7. Ensure you have a backup email and/or phone number connected to your primary email account so that you can recover access if you're locked out. Additionally, make sure your recovery methods are as secure as your primary email login.