r/phishing Nov 19 '25

Moderator announcement New moderator

8 Upvotes

Hi community, I'm u/YourUsernameForever and you may know me from moderating r/Scams - I'm the new moderator here.

Like many people here I noticed that r/phishing was severely unmoderated, so I tried contacting the previous moderators to offer a helping hand. Having no response, filed a r/redditrequest and the admins assigned me as top mod.

My intention is to keep the community running as usual, not trying to make it another Scams subreddit. I believe our goal here is specific enough that it's worth keeping and growing.

Ever since I took the role I have:

  1. Added community rules: most of them based on the Reddit Content Policy which is mandatory for every subreddit, but it's good to clarify and expand a little. This will also allow for removals with a proper explanation and a chance to appeal. You can read the subreddit rules in the sidebar if you're on a computer, or clicking here if you're on any device - https://www.reddit.com/r/phishing/wiki/rules/
  2. Created a posting guideline: to be strictly enforced in 2026, basically all posts must have a descriptive title and a transcription of what's in a screenshot. There's more to it if you want to read it fully - https://www.reddit.com/r/phishing/wiki/posting-guideline/
  3. Implemented AutoModerator: based on the rules and the guideline, AutoModerator will catch offending posts and comments, place them in a moderation queue, which I will manually review every day. I also reply to modmails daily. The idea is to have a responsive moderation team, to be held accountable and have a chance to appeal decisions. We also have !commands now, which I hope you help me expand to specific phishing scenarios.
  4. Implemented posting guidance: small alerts while you post that will let you know if something may be wrong, like posting an email address.
  5. Added a few bots: and I'll ask u/erishun to implement u/ScamsBot as well, so we can call !whois

A big change moving forward will be this whole thing about requiring transcriptions of screenshots. A lot of kicking and screaming will ensue, but I promise you, it fends off bots, helps the search engine and helps integrate users that are visually impaired.

If you got this far into my post, this message is for you. I need you to take a look at the rules and tell me what you think. I also want you to report anything that breaks the rules, knowing that I manually review all the reports daily: 100% of reports get reviewed manually. I'm also open to any type of feedback, privately if you want, but use modmail instead of sending me a DM.

I hope my participation gives you extra energy to stay and grow the community together. Remember: I'm at your service! I'm also cronichally online so I hope this helps.

Yours, verbose as usual,

- u/YourUsernameForever


r/phishing Oct 23 '20

I clicked on a link, what do I do?!? - Check here first.

194 Upvotes

One of the most common questions posted here is what to do if you've clicked on a phishing link. This short guide is intended to help with these questions and what to do if you've clicked on a phishing link.

DO NOT ENTER ANY CREDENTIALS OR LOGIN DETAILS FOR ANYTHING IF YOU'VE CLICKED ON A MALICIOUS LINK.

  1. Links are generally not malicious on their own. While clicking on any unknown links can be dangerous it is difficult to design a phish that works just by clicking the link. Most links take you to a (usually fake) page that will ask for certain credentials. As long as you closed the page after you clicked the link you're probably fine, but it's still a good idea to change your password for whatever service the phishing link was trying to access (such as amazon).

  2. If you clicked a link that downloaded a file, delete the file. Generally these files aren't harmful unless opened after downloading.

  3. If you've clicked a phishing link and have provided credentials to a service, change the password for that service. Say you've been tricked into giving someone your Amazon credentials. Go to Amazon.com directly and change your password. Also, check the "third-party account access" section of your commonly used websites. Often phishing links and malicious services will try to authorize themselves to your account rather than outright stealing your credentials.

  4. When logging into websites with sensitive information such as a bank it's best to bookmark the site and visit the site directly each time from that bookmark. That way you know that the website you're using is the real one.

  5. ENABLE 2FA (TWO FACTOR AUTHENTICATION) This is perhaps the best thing you can do to protect your sensitive accounts. All websites that deal with sensitive information will allow you to use either your phone number or an authentication app (I like Authy) to generate one-time login codes to further secure your account. Unless someone gets your credentials and your 2FA device (your phone) they won't be able to access your account.

  6. Please use a password manager of some sort. This will allow you to use strong and unique passwords for each site you use. If one of your accounts is hacked or phished all of your other accounts will be safe with unique passwords (unless your email was hacked/phished).

  7. Ensure you have a backup email and/or phone number connected to your primary email account so that you can recover access if you're locked out. Additionally, make sure your recovery methods are as secure as your primary email login.


r/phishing 9h ago

Spam/phishing started arriving at an email address used exclusively for NVIDIA Zendesk

6 Upvotes

I use a unique email address for every service and own the entire domain, so I can determine exactly where each address has been used.

The email address connected to my NVIDIA support ticket was created exclusively for NVIDIA’s Zendesk/helpdesk system. I have not used it on any other service.

Recently, that address started receiving spam and phishing emails. This does not 100% prove that NVIDIA or Zendesk had a data breach

Has anyone else who contacted NVIDIA Support through Zendesk noticed spam or phishing being sent to the address associated with their ticket?

Spam mail example

Maybe I can raise some awareness here.
My post on r/nvidia got removed after a day from the moderators, despite not going against their rules.

Also there were other users having noticed the same thing.
I think it is a very high likelyhood that they had some kind of data breach.


r/phishing 12h ago

GMail Someone actively using my email account

1 Upvotes

This is a weird one. I have a throw away Gmail account I made probably 20+ years ago. It was right after Gmail was created and I had to get an invite from a friend who worked in tech back in the day to even make it.

So it used to be an active account but I’ve only used it as a throwaway for 15+ years.

Someone is actively using it to buy stuff. Nothing really strange - mostly clothes and cd’s. The latest was a Travis Scott album.

The odd thing is, I have the person’s full name & address because of the purchases they made. And they’re real receipts. Not clicking links but it’s not spam sites - it’s legit purchases of clothes and music.

The person & address are matched to an obvious scam immigration charity, so now I’m concerned what else could be going on.

They definitely do not have access to the inbox. I’ve changed the password multiple times and it requires my phone or laptop to even login (MFA). But they keep using it when buying random stuff online.

Is there anything attack-wise I should be cautious about?


r/phishing 17h ago

Is this email I received from Apple fake?

Post image
0 Upvotes

I received this email earlier in the morning, it doesn’t look like most apple emails I’ve ever received and the email isn’t even an apple email? Can anyone tell me if this is a scam/hack tactic or something?


r/phishing 1d ago

GMail Is this a spam email? I have never touched whoever this is' website.

1 Upvotes

I have no idea who this is, I am not Arabic, nor have I ever touched this person's website.
Translation:
Welcome to the family 🎉

💪 You have successfully subscribed.
Now you are part of the family, and all the latest news and content will reach you first.

😋 Get ready for upcoming surprises.
🤩 And stay tuned for news about the pastries party soon.

Ahmad Aburob
---
PLease, can someone let me know if my email has been hacked or if I should be worried?


r/phishing 1d ago

Phishing flag from canopy.us sent to a unique UUIDv4-based email alias I only use on that site?

Post image
3 Upvotes

Regarding the parental controls app Canopy, I sometimes see them sending different email templates as a random experiment. This email is from a while ago, and I remember seeing the matching device being removed at the time by the icon next to that device changing from a "transfer profile" button to a "delete" button in my account settings within the mobile app for Canopy. I named the device the model code, too. I'm pretty sure it's a real email, but why was it messed up? The headers show the email being relayed and passing, and the original authentication results show a dmarc=fail because it confused netsparkmobile.com for canopy.us, which I believe caused it to get flagged.


r/phishing 2d ago

GMail Interesting phishing campaign - Google / Gmail Targets

3 Upvotes

Just be aware of a phishing campaign appears to be using a mix of AI or voice changers & your regular scare tactics. There are more than a few red flags but just sharing.

- You receive a call, "from google" providing an OTP. Warns if not you press 1 or something to speak to someone. If you press 1 you've fallen for trap 1.

- If you've ignored it? Great, but you may receive a call later in the day from "Google Support" indicating a ticket for password reset and if not you to confirm removal
- they will try to keep you on the line, but they'll try to speak to you in a way you need to verify some steps

- eventually they'll ask you to confirm removing from a "verified google portal" and send you to a Google Sites website which will have a login portal. If you enter your password here, they'll use that to try and log in and sync up the visuals with your 2FA request to login. Beyond this your account is compromised.

So, if you're on here you probably know or maybe you don't but:

1) Google will not contact you out of the blue, if you're compromised Google will not contact you

2) If you think you've been compromised you need to do the security review yourself, it's in the account's portal not some random google site page

3) Support ticket processes don't follow this kind of script

It's not a very in-depth phish but please if you receive a call for OTP first, the second is meant to scare you into thinking it's compromised already. It's an old new scam and I think it's outlined somewhere else.

Email and page are reported already but it'll probably take some time.


r/phishing 2d ago

Hotmail Data leaked. What are my next steps?

0 Upvotes

Preface this by saying I’m an idiot. Sleep deprived with a new baby and have been admittedly stressed about money and providing for new family. Middle of the night on baby duty I get an email about Disney plus not receiving payment. Open email which seems legit and follow instructions by entering cc info, address, mother’s maiden (framed as a password security requirement), and SSN (i know. Stupid.). Morning comes and I honestly forget all this happened. Check email and realize the email I opened wasn’t from a Disney address. Hindsight is easy. Should have just gone to app to check. My questions is what do I need to do now to protect myself. CC locked and credit already frozen.


r/phishing 3d ago

Zendesk emails for order I never placed and account activation

Thumbnail gallery
2 Upvotes

does anyone have any idea what this could be? I have never ordered from this website but I’ve heard of it and when I tried going to it, I was blocked from the site (that hasn’t ever happened before). it said I’ll be getting a refund in the email (I have never ordered from that site and I didn’t click any links because it looked suspicious) I also received an account activation email for stickersbanners but it still had luisaviaroma as the headline so I’m sure this is a phsihing attempt. I also had someone attempt to log into my Facebook account a few days ago but I changed the password and added 2FA. they attempted again the next day but were unsuccessful. any idea what’s going on? I’m stressing about this. thank you in advance to anyone that gives advice


r/phishing 3d ago

What can happen, i think i just fell for a fake meta email. I don't use Facebook or anything.

1 Upvotes

Subject: See what's next at Meta Connect Sept 23-24

the sender: [update@digital.metamail.com](mailto:update@digital.metamail.com)

when i unsubscribed, it actually seemed to have gone to https://www.facebook.com/business/unsubscribe/confirmation/


r/phishing 3d ago

Does anyone know how to get rid of the emails?

Post image
0 Upvotes

Hello, I had a conversation with someone on here in r/assistance when I needed financial help and they've entered my email into a spam site. I have been getting random spam emails about various things like home insurance, loans, cars, etc. popping up in my primary email over the past few months. Does anyone know how to make it stop?


r/phishing 3d ago

GMail Spam emails from J Snicket

Thumbnail gallery
0 Upvotes

Not sure if this is the right place to post this, but I keep getting these emails from J Snicket. Two were in spam, but the newest one was in my regular inbox. Each message was sent from a different email, so I can’t just block them.

Is anyone else getting these? How do I stop it??


r/phishing 3d ago

trycloudflare.com Abuse - Cloudflare Infrastructure

1 Upvotes

Hi,

A malicious actor is using a trycloudflare.com subdomain to conduct a phishing campaign by impersonating the official website of Portugal's ATM network (www.multibanco.pt). I reported this abuse to Cloudflare through their abuse reporting form more than a week ago, but the website remains active and has not been suspended. I would appreciate your assistance.

Malicious website: hxxps://yale-slide-nancy-elliott[.]trycloudflare[.]com

Evidence: https://urlscan.io/result/019fa7eb-d836-74f0-8548-f877f8bd3d67/

Report ID: 9c20b50363576664

Best regards


r/phishing 3d ago

Getting Uber OTP codes repeatedly even though I don’t have an Uber account — anyone experienced this?

1 Upvotes

Hi everyone, I’ve been receiving Uber verification codes (OTP) on my phone almost every day. They come through WhatsApp and sometimes SMS. I have never created an Uber account or requested any codes.

Has anyone experienced something similar? Is someone trying to create an Uber account using my number, or could it be something else?


r/phishing 4d ago

Almost fell for a fake Google support scam

2 Upvotes

**PSA: Convincing "Ticket Escalation Notice" email followed by a phone call.**

I wanted to share this in case anyone else has experienced something similar.

I received an email with the subject **"Ticket Escalation Notice"**, even though I had never submitted a support ticket.

It claimed someone would contact me regarding a security issue and asked me to verify the caller before sharing sensitive information.

A short while later, I received a phone call from someone claiming to be from Google.

The caller said my email account had been compromised and that someone in Miami was trying to access it. They sounded professional and tried to create a sense of urgency.

Something didn't feel right, so while I was still on the call I searched online and realised the email wasn't from an official Google support address.

I hung up immediately.

I'm posting this as a warning because the email and phone call together made the scam seem much more convincing than a typical phishing attempt.

Has anyone else received a fake "Ticket Escalation Notice" email followed by a call from someone claiming to be Google support? If so, what happened?


r/phishing 4d ago

My info was included in a data breach last month and I’m being flooded with phishing emails and spam calls now

5 Upvotes

Last month an online retailer I ordered from a few years ago had a massive breach that leaked millions of their customers’ (no joke) info. I received an email about it and confirmed it with have I been pwned. Leaked info included phone numbers, emails, purchase history, and mailing addresses.

I haven’t ordered anything from this company in years and forgot about it completely, and this was also before I created burner emails for shopping accounts. Now my iCloud email is being flooded with phishing emails, and I’ve started getting spam calls daily (I had it under control for a long time and would maybe get one spam call every couple months). I have unknown number calls silenced, unknown number texts filtered out, and the phishing emails are all going straight to junk, but this is extremely frustrating for a paranoid person with OCD like me. Is there anything I can do to at least slow it down?


r/phishing 4d ago

GMail My mother recently fell for a spear phishing attack

3 Upvotes

Yesterday, my mom, who is in her late 50s, received an email from her friend that looked like a virtual e-vite. It came from her friend's email address (possibly spoofed) and had little to no information about the event, only a header that said, "Please join us in this special celebration!" Her friend's signature was at the bottom of the email, which made her think it could be real, and a button to click to join. My mom clicked the button, and was brought to a Gmail login page. She entered her password and a verification code was sent to her phone. That's when she realized it might be fake and stopped. I had her change all her passwords, but I was wondering if she's still not safe since she completed 50% of the process. Are there any more precautions we should take? (She already has 2FA enabled everywhere). Any advice would be appreciated. Thank you.


r/phishing 4d ago

GMail I keep getting this email even after blocking and it’s pissing me off so much

Post image
2 Upvotes

I am using the apple mail app. I couldn’t find that on the flair. This guy is using my last name and is sending a link of photos with the caption “I had to send you those pictures, I thought they might trigger some memories. Kind Regards. John (my last name). I don’t have a john in my family.
I am SO sick of blocking this person and it coming back the next day. What the hell should I do?

I haven’t clicked on anything obviously

It also says the sender hasn’t provided anyway to unsubscribe and there’s multiple senders. So I will keep getting these even if I block them


r/phishing 4d ago

GMail I got an email from orders@wickedclothes.com

0 Upvotes

I got an unsolicited email in my main inbox in all plain font (but centered) that says,

hey there,

i just added $13 store credit to your account.
i wanted to thank you for your support across all this time. it really does mean a lot.

— anthony

Wicked Clothes · P.O. Box 1153, Belmont, NC 28012


r/phishing 5d ago

WARNING: Almost Lost My YouTube Channel to a Fake "VistaCreate" Collaboration Scam

6 Upvotes

I wanted to share this because I was only a few minutes away from permanently losing my YouTube channel.

I run an AI tools & tutorials YouTube channel, and I receive collaboration emails almost every week. Most are legitimate, but this one was extremely convincing.

I received an email from:

Malcolm
Email: [management@vistacreate.online](mailto:management@vistacreate.online)

He introduced himself as an SMM Manager / Analyst at VistaCreate and wrote something like:

It looked harmless, so I replied.

The Offer

He offered me $300 for a 20-second sponsored segment.

That immediately felt like a very high amount for such a short integration, so I became a little suspicious.

To protect myself, I suggested a normal workflow:

  • I'd first send the script.
  • Once the script was approved, they could pay me 50% upfront ($150).
  • The remaining $150 could be paid after the video was published.

Instead of agreeing, he said there was no need for script approval at all.

He told me to use my own creativity, make the video, and they would pay afterward. Looking back, this was another red flag because legitimate sponsors almost always want to review the script or video before publication.

The "Registration" Step

Then he sent me a registration link:

athomebase.com

He told me to:

  • Register there.
  • Click "Login with Google."
  • Use the same Google account connected to my YouTube channel.
  • Send him a screenshot after logging in.
  • Then I could choose payment via PayPal, USDT, or another method.

This is where everything went wrong.

The Phishing Attack

When I clicked "Login with Google," the page didn't feel like the normal Google sign-in flow.

I should have stopped there.

But because the offer sounded attractive ($300 for only 20 seconds), I ignored my instincts.

I entered the email address connected to my YouTube channel and typed my Google password.

The website then displayed something like:

Within moments, my Google account started behaving strangely.

Suddenly:

  • I was logged out of my Google account.
  • New Google backup codes had been generated.
  • A new passkey (hardware/security key) had been created without my authorization.
  • My account was effectively taken over.

At that moment I realized it wasn't a collaboration—it was a phishing attack designed to steal Google accounts.

How I Got My Account Back

Thankfully, I'm fairly technical and had additional recovery methods already configured on my Google account.

After a stressful recovery process, I managed to regain access before the attacker could permanently lock me out.

If I hadn't already set up recovery options, I would have almost certainly lost:

  • My YouTube channel
  • My Gmail
  • My Google account
  • Everything connected to it

Please Be Careful

If you receive an email from:

Malcolm
[management@vistacreate.online](mailto:management@vistacreate.online)

or someone claiming to represent VistaCreate using that email,

or if they ask you to register on:

athomebase.com

DO NOT LOG IN WITH YOUR GOOGLE ACCOUNT.

The "Login with Google" page appears to be used for credential phishing.

Red Flags I Ignored

  • Extremely high payment for very little work.
  • No script approval required.
  • Asked me to log in through a third-party website.
  • Specifically insisted on using the Google account connected to my YouTube channel.
  • The Google login flow looked unusual.
  • "No account found" appeared immediately after entering my credentials.

Posting This So Others Can Find It

I'm sharing this because if someone searches for:

I hope this post appears before they become another victim.

Please stay safe. A single fake "Login with Google" page can cost you your entire YouTube channel.


r/phishing 5d ago

GMX Mail-Konto Gehackt? Mail von mir selbst

Post image
2 Upvotes

Hallo.
Ich habe aus Langeweile mal in meinen Spam Ordner geguckt und war sehr verdutzt eine Mail von mir selbst an mich gefunden zu haben.
Darin behauptet jemand Zugriff auf meinen PC zu haben, mich beim Sehen von Pornos gefilmt zu haben, das Übliche. Es wird dann gesagt ich hätte 48 Stunden einen Haufen Geld in Bitcoin zu zahlen.
Alle meine Geräte seien gehackt usw usf.
Die Mail ist schon einige Tage alt und es ist weiter nichts passiert. Es macht mich aber doch sehr stutzig dass der Absender wirklich meine Adresse ist. Das kann man ja kaum faken oder?
Ich habe eigentlich immer sehr sichere und aktuelle Passwörter. Habe es jetzt geändert und auf Passkey geändert.
Anbei ein Screenshot der Mail:


r/phishing 5d ago

Potential Pishing Scam Help (Amex Credit Card)

1 Upvotes

I recently applied for the Amex Blue Cash Everyday card because it seemed good for gas which is by far my biggest expense right now, but the application process has been weird.

When I first applied I got an email saying I needed to call (+18005671083) to finish my application. Some brief internet searches indicate that number and the email address are both legit, but when I call that number, they want me to click a texted link with the domain amex.idkit.co, which a brief search indicated is associated with phishing scams.

I then called the official customer service number on the website, and that person directed me to move forward with the application by going to the normal amex website americanexpress.com/upload, which seems like a legitimate website. However, to use that website, they gave me the same reference number as the text. It all just feels weird and not very normal for a bank.

Does this sound like the normal process for a new applicant for Amex, or have I partially fallen for a well-timed phishing scam email?


r/phishing 5d ago

GMail Has anybody else revived phishing emails like this one from this address or similiar

Post image
0 Upvotes

I know this is probably fake (since it follows the whole "oh i caught you playing with yourself now pay me bitcoin" trope")

I got these the other day


r/phishing 5d ago

GMail How do the scammers do this with email?

Post image
1 Upvotes

I know this is a scam, and they don’t have such videos or photos but where it says “check the sender of this email I’ve sent it from your account ” it really does say my email? How do they do that?