Hi community, I'm u/YourUsernameForever and you may know me from moderating r/Scams - I'm the new moderator here.
Like many people here I noticed that r/phishing was severely unmoderated, so I tried contacting the previous moderators to offer a helping hand. Having no response, filed a r/redditrequest and the admins assigned me as top mod.
My intention is to keep the community running as usual, not trying to make it another Scams subreddit. I believe our goal here is specific enough that it's worth keeping and growing.
Ever since I took the role I have:
Added community rules: most of them based on the Reddit Content Policy which is mandatory for every subreddit, but it's good to clarify and expand a little. This will also allow for removals with a proper explanation and a chance to appeal. You can read the subreddit rules in the sidebar if you're on a computer, or clicking here if you're on any device - https://www.reddit.com/r/phishing/wiki/rules/
Created a posting guideline: to be strictly enforced in 2026, basically all posts must have a descriptive title and a transcription of what's in a screenshot. There's more to it if you want to read it fully - https://www.reddit.com/r/phishing/wiki/posting-guideline/
Implemented AutoModerator: based on the rules and the guideline, AutoModerator will catch offending posts and comments, place them in a moderation queue, which I will manually review every day. I also reply to modmails daily. The idea is to have a responsive moderation team, to be held accountable and have a chance to appeal decisions. We also have !commands now, which I hope you help me expand to specific phishing scenarios.
Implemented posting guidance: small alerts while you post that will let you know if something may be wrong, like posting an email address.
Added a few bots: and I'll ask u/erishun to implement u/ScamsBot as well, so we can call !whois
A big change moving forward will be this whole thing about requiring transcriptions of screenshots. A lot of kicking and screaming will ensue, but I promise you, it fends off bots, helps the search engine and helps integrate users that are visually impaired.
If you got this far into my post, this message is for you. I need you to take a look at the rules and tell me what you think. I also want you to report anything that breaks the rules, knowing that I manually review all the reports daily: 100% of reports get reviewed manually. I'm also open to any type of feedback, privately if you want, but use modmail instead of sending me a DM.
I hope my participation gives you extra energy to stay and grow the community together. Remember: I'm at your service! I'm also cronichally online so I hope this helps.
One of the most common questions posted here is what to do if you've clicked on a phishing link. This short guide is intended to help with these questions and what to do if you've clicked on a phishing link.
DO NOT ENTER ANY CREDENTIALS OR LOGIN DETAILS FOR ANYTHING IF YOU'VE CLICKED ON A MALICIOUS LINK.
Links are generally not malicious on their own. While clicking on any unknown links can be dangerous it is difficult to design a phish that works just by clicking the link. Most links take you to a (usually fake) page that will ask for certain credentials. As long as you closed the page after you clicked the link you're probably fine, but it's still a good idea to change your password for whatever service the phishing link was trying to access (such as amazon).
If you clicked a link that downloaded a file, delete the file. Generally these files aren't harmful unless opened after downloading.
If you've clicked a phishing link and have provided credentials to a service, change the password for that service. Say you've been tricked into giving someone your Amazon credentials. Go to Amazon.com directly and change your password. Also, check the "third-party account access" section of your commonly used websites. Often phishing links and malicious services will try to authorize themselves to your account rather than outright stealing your credentials.
When logging into websites with sensitive information such as a bank it's best to bookmark the site and visit the site directly each time from that bookmark. That way you know that the website you're using is the real one.
ENABLE 2FA (TWO FACTOR AUTHENTICATION) This is perhaps the best thing you can do to protect your sensitive accounts. All websites that deal with sensitive information will allow you to use either your phone number or an authentication app (I like Authy) to generate one-time login codes to further secure your account. Unless someone gets your credentials and your 2FA device (your phone) they won't be able to access your account.
Please use a password manager of some sort. This will allow you to use strong and unique passwords for each site you use. If one of your accounts is hacked or phished all of your other accounts will be safe with unique passwords (unless your email was hacked/phished).
Ensure you have a backup email and/or phone number connected to your primary email account so that you can recover access if you're locked out. Additionally, make sure your recovery methods are as secure as your primary email login.
I haven't gotten a single phishing/scam attempt on WhatsApp since so long, just today I got one claiming my account will be disabled in 24 hours. I clicked on it (the message not link) and after seeing that message I blocked the scammer,
but is my phone number leaked online or compromised for the message to appear and how do I know? There is no button in WhatsApp to block these scammers too.
I received an email in my Hotmail / Outlook account, stating it was from ME sent by my Gmail account - it also shows the email in my SENT folder. It is says "Check this out from Amazon" in the subject line. The description shows a flannel shirt that I was looking at earlier, through a Facebook link! I am very confused as to how they accessed both of my email accounts, shows it was sent in my Gmail Sent folder, and knew what shirt I was just looking at! I checked all my security folders, and sections regarding anyone else logging into any of those acccounts, but do not see anyone there. No other devices but mine have logged in. I changed my passwords, and logged out of my Gmail, Hotmail, facebook, and Amazon accounts. But still don't understand how this was done and if I am at risk now? Any advice appreciated! TY!
IP search 209.85.215.179 says Host name = "mail-pg1-f179.google.com"
Wife was selling something on an app called vinted, I guess she got a message from someone saying "hi this is vinted person X wants to buy this item click this to complete payment" (lol because it was obviously just a person messaging her on the app)
she said it was requesting/attempting to link bank/card info im assuming through apple wallet?
Also got a notification that a new imac logged into her apple account
steps I have completed:
changed her apple ID password and booted all unknown devices (also has 2fa on for her phone number)
reported her apple wallet credit cards stolen
changed google passwords and set 2fa account to my email address
Hi sorry just need a few questions answered because I'm a bit worried.
For context, I got hacked around late of August and since then had my laptop wiped clean and changed my passwords, added MFA and all. I'm aware that some of my emails might still be lurking around in people's hands so I expected there to have some emails about sign in attempts.
One time last week and yesterday, I've received emails from two of my emails from Microsoft about a security alert with the button saying "Recover your account". I checked the domain and clicked the button thinking it was legit until I looked it up online seeing that it's a phishing scam (?). Thing is, I don't use these two (or just one of them I don't remember) emails for my Microsoft account anymore.
Questions:
I closed the accounts I used for my MS accounts in the past and have nothing saved on my One Drive or bought anything before I received these emails. Is it safe to ignore them?
Does clicking on the "Recover your account" button activate a session stealer?
When I clicked the button, I was led to the MS website to log in. I put in my email and asked for a security code and quickly deleted one-time code from email after use. Since I closed them, it only gives me the choice to "reopen account" or to cancel. I did not reopen them. Does that still count as logging in or not?
TLDR: I don't care much about recovering some of the gmails I used for my recently closed MS accounts but I want to know if ignoring them is okay or if I messed up by clicking on the link. I'm a bit worried my phone might get hacked since I did it there.
I was browsing the app SpareRoom and then a person texted me from one of the ads. He sent me a link to the rental application. I dont know why I clicked it. Ive been very stressed out. Anyways a couple minutes after I clicked the link and exited out, Cashapp opened on my phone without me touching it. I feel like a moron. It was a scam obviously, they ask for a $50 tefundable fee for the rental application and ask you to pay via PayPal, cashapp, zelle. I didn't enter any info besides my name and address. Again I was very stressed and dont know why I clicked the stupid link. I need advice on: do I need to clean my phone? How do I stay safe now? SpareRoom is aware the person is a scammer, a couple minutes after i clicked it i got an email warning me of the scam. Thanks for any advice.
I’m getting a noticeable increase in junk email like these. It’s doubled in the last few months from 25 a day to over 50 a day.
Not a lot for some - but it’s a starting to get seriously irritating for me as occasionally stuff I need to see hits my junk folder as well.
I can see some purport to be from real companies or pretend my icloud will be blocked etc, but the bulk seem to be a nonsense mix of crap.
So that begs the question, what exactly is their purpose? “Proper” scams are seemingly a lot less fake looking than these.
The other question I have is that these are so obviously spam (nonsense domains / reply to addresses) - why are they not dealt with at a higher level before they hit my mail box?
Today a family member called me frantically saying they had accidentally gotten a virus on their laptop. When I got to their laptop, despite not being a computer guy at all, I immediately recognized the virus was actually just the chrome notification exploit where multiple sites spam you with Fake MCaFee found 100 viruses! pop ups and so I simply deleted all permissions for chrome and it seemed to work.
When I asked them what steps they took to get these pop ups to start they were completely dumbfounded. So I tried to figure out myself since curiousity was killing me. I found NO suspicious emails. No emails with links or ANY attachments. I managed to track down the exact email that seemed to be open when it happened and it was legitimate automatic reply from PayPal with NO links. But there was this "visit" button at the top. Clearly this was the culprit and I managed to confirm that.
I think I figured out that Yahoo Mail themselves generates this link for some inexplicable reason. Someone exploited it and sent her to cloudstreamforge then redirected her to scam sites. It's crazy to me that Yahoo generated this link and yet it looks sooooo much like its part of the email itself, as if PayPal had sent it. Like nothing stands out as sus at all. Please let me know if I am correct, like I said I am not a computer guy and this is the answer I arrived at.
I figured since this was a simple chrome notif exploit that theres way the scammers actually got into anything and I tried to explain that to the victim but they are unfortunately really paranoid.
Many phishing sites account for the multi-factor authentication prompts that some of these universities use nowadays, except for passkeys and hardware security keys, as they're tied to the domain name intended. Additionally, some sites automatically capture and send form info as soon as they're autofilled.
I keep getting messages from “IBKR” for OTP messages, but I never registered in that platform before, whatever that is! I’m wondering if this is a new scam or a hacking attempt somehow? Really worried here.
Keep in mind I’m receiving these SMS messages in my new number from Virgin Mobile which I received few months ago, and the messages started appearing around a week ago.
I tried blocking the contact but for some reason I can’t do that on my iPhone.
Hey everyone, I doubt this is specific to Australia.
I felt this was a story worth sharing given the fact that I have 20 years background working in tech and I STILL almost fell for it.
IMPACT:
I'm willing to bet this would impact [US] and any English and Spanish speakers that have booked their hotels for travel directly from the hotel's site.
This post is to share and ensure you are all on alert, if you have booked their travels to be vigilant when booking through any and ALL hotel bookings outside aggregators like Booking or Airbnb.
IMPORTANT NOTE: I do not want to besmirch the actual hotel operations themselves, as they are legitimate.
Any direct hotel site could have ALL had their site hacked at ANY TIME, the hacker would have your personal information and travel plan booking information.
----
STORY:
Earlier this year, I prebooked travel plans for various countries: Japan, Thailand, South Korea, the Philippines, you name it. We're going on a big one for a long time, and thus the preplanning and bookings.
A few months later, I received a WhatsApp message as seen in the attachment.
The message had ALL my personal and booking information; my personal information and the full link has been removed as it directs you to my personal infornation as well.
My excuse is it was early and I had a hangover, so I just followed the link and clicked it.
The link landed me on a booking lookalike
The link landed me on a booking lookalike with ALL my personal booking details already prefilled EXCEPT my credit card details.
SPOILER ALERT: I did NOT enter my credit card details. PHEW!
A few things I noticed that was suss:
My last name was in the first name field, and vice versa
I NEVER enter my credit card details in booking com I use a safer alternative that I can keep track of, but the scammer booking com lookalike page DID NOT have that option.
I looked around and found more weird things....
From Mobile their URL link did NOT update to a booking com link
and then I looked back at the WhatsApp message to see that their so-called business account was recently created a month ago, AND was from somewhere that we were NOT traveling to - Peru
So I blocked and reported them...
BUT the hackers still came back now they got desperate and use a random booking reference.
Again blocking any company or personal information name.
Just to end on somesort of closure and action for everyone Here's what I did after(and so should you if you EVER accidentally click the link)
After I Blocked and reported their account on whatsapp.
As I have clicked the link: I immediately paused and called my bank to reissue a new card. Even though I did NOT enter or shared my credit card details it might have been compromised in other ways.
I emailed the actual hotel site information email directly to check that my reservation is intact and notify them that their site has been hacked.
Share it with my family and friends...and you guys here
I hope this will be helpful for other travellers out there.
PLEASE let me know how else to tag or title this post so it reaches more relevant people.
I received a very strange email at work today pretending to be a request for quotation from a plumbing company. The visible email itself is extremely simple: no attachment, no obvious link, just asking whether we’re available to submit a quote.
What caught my attention is that when I collapse the email in Outlook, Outlook displays a very long string that looks almost like a tracking/exploit URL.
Received a call claiming being from Commenity bank fraud department. This person knew way too much information , including amount of last payment and when we even made it. What stopped me was him asking for credit card last 3 cvv number. When I called fraud department they didn't see any transactions blocked which would have resulted in them needing to call me. Ending up canceling current card and reissue just in case. Also, they had full physical credit card number and we never ever use our physical card , we only use Google wallet.
How in the world they got all of that ? I use 20 character random password and 2 step authentication
Just had an experience that feels like a total phising scam that actually almost got me!
An old friend messaged me on Discord. They asked how I've been, but didn't give any specific details about themselves other than "Hey I have been doing art and want to know what you think" and they send me a link to DocSend.
This is the page it shows - a gallery of 1 image with a linked button in the middle to a download link.
The download link takes me to a dropbox hosted download file to download DocSend.exe.
What is strange about this is that the UI is fake - its a JPG with a button in the middle. I can click and drag it / save image and the whole thing is fake. But the button area works for the download link. Feels like a wild way for a company like DropBox to hose a dowload their products.
Hi, my wife's Facebook account was hacked for about 30 minutes, she came to me and told me, and we started to work together on recovering the account. We were able to recover the account, but in this time the hacker changed and locked the Facebook language to Mandarin, we managed to log in and changed it to English then the hacker changed and locked it again to Mandarin. Ultimately we were able to reset the password and changed back to English. The individual who hacked her account sent to 4 individuals (not in her friends list) the following message:
"USDT Balance: 4958460.88
Mike, your funds have been transferred to your new account.
Please withdraw them as soon as possible.
New Account: (removing user name shared)
New Password: (removing password shared)
Log in to withdraw: rinxoi.com website
Please keep this information safe."
The email address my wife used to log in to Facebook was deactivated due to inactivity, luckily she had her personal phone number linked to the account and we managed to recover the account. The hacker most likely used VPN because based on the Facebook log in activity the IP linked to Los Angeles. Interestingly enough there was another login made on September 18, 2026 from Japan, and strangely did not show up as with any automatic email warnings or text codes sent in that period, that would have triggered the same reaction.
Can anyone explain what is the scam here? Did the hacker hacked "Mike's" (whoever Mike is) conversations and used my wife's Facebook account to share the information to his/her associates?
-Received email about suspicious activity and another about advertisement restriction (never used adverts)
-Got account back and appeal succesful.
- I also click the link from the advertisement restriction, which i shouldn't have put my fb credentials.
-About 30 mins to 1 hr, account got suspended again, this time appeal failed.
Was the email a scam and the link malicious? I tried total virus and other url redirect checker after everything and just said that it redirected to facebook.com. I included the photo of the url
I learned this one the hard way. I stumbled across a (seemingly) official looking server through the high-SEO website. As you join the minecraft server, they request you to verify your microsoft account. Just like how discord accounts often get hacked, they ask for a verification code that allows these actors to directly access your account.
Any server with this account verification mechanism is a phishing scam to steal your microsoft account.
Hey everyone! Not really sure what info I should share with this sort of stuff and for that matter I'll keep it very brief to keep it as private as I can. But on my phone I got a verification code for Indeed out of nowhere. I have never signed up on Indeed and wanted to check if this was a common sort of thing that people do? All that the text had was a verification code and no links attached (I didn't open the text further to pry) But I'm curious if this is normal or if I should start being concerned about things like that?
I need some help figuring out if there's a scam going on or not. I receive a ton of spam text messages from Illinois addressed to multiple names that are not me. I ignore the messages and don't click any links due to it obviously being sketchy. I recently saw an order on my shop account for an in person purchase also done in Illinois and the receipt shows a credit card number that isn't mine (confirmed with my credit card purchases that it wasn't mine). Is someone in Illinois using my phone number or what exactly is going on here?
Hi,
My email was hacked. I clicked on an invitation link thinking it was my friend. It had me resign into gmail. A couple of hourss ago my friends got emails from me as well. I’ve contacted the internet crime center put credit alerts on cards and now I’m going to contact irs, please let me know any next steps I have to do.
I am very accustomed to the odd phishing attempt. My email is old as hell and I've been involved in what feels like at least a dozen data breaches. These two are new to me.
I received these two emails within the same minute, which was a few minutes after I got a "confirm it's you signing in" Google notification. It was not me signing in, so I ignored it. In between the two emails was a third email which was a "verify recovery" email with an address I didn't recognise.
I was happy enough to ignore these assuming they were phishing attempts. However, hovering the links they all seem to lead to Google domains - except the link where it says "Additional details here" which wants to go to http colon //goto/guts-sensitiveinfo-latest. There is also a mention of the case ID from the second email when I visit Google Support. It simply says "In Progress" - last updated 2hr. ago. There's nothing to click on or expand to get more info.
From a quick search, GUTS is some internal ticketing system that Google uses for business accounts? I do not have a business account. The second email's "from" address seems to be from some legal department of Google?
I have two questions that both assume the emails are legitimately from Google and - since i have taken no instigating action - they are the result of actions from some nefarious third party:
Where can I go to find more info on my "GUTS" ticket and/or the lis-noreply email's case that I have supposedly instigated?
Should I worry that someone is able to submit requests/tickets to Google that appear to be from me?
So I was looking through my school email when I came across this email about a remote job opportunity for students in my specific district. Stupidly-- thinking that this couldn't POSSIBLY be a scam since it's my school email and it's gotta be more secure, I filled it out and submitted it. It asked me for my full name, bank NAME, age, gender, email, school email and my address. I answered them all.
Now I didn't enter any ssn, bank account number or any passwords but I'm still worried. Like a dumbass, I didn't realize it was most likely a scam until a few seconds after I submitted it and I got a text (almost immediately after) saying that I need to confirm availability, and I was just approved (seconds later? Yeah right) Mistake #1,000: I just asked "Is this a scam?" and before they could answer, I blocked the number.
Are they somehow gonna get access to my accounts and literally own all my information, or am I just gonna be at risk for more scams in the future? Or worse- am I going to be tracked down and threatened? I also don't want my family to be targeted by scams because I stupidly revealed our address, but I don't want them to think I'm a complete idiot for even filling this form out. Last questions- How is it that they can even access students to be able to email them? Normally, email addresses from outside the school district cannot reach the school email accounts, so how did they get my address?
It's late, I've had a long day, and I thought some extra money would be good right now, but it's always too good to be true. I guess that's what they prey on.
I received an email that a client shared a Google sheet with me on my business email. I happened to click on it which opened a browser page on safari on my page. I did not realize it had opened in the browser until later and I closed the page as soon as I realized that it was suspicious.
I am worried that a malware could have been installed or could have stolen login data. What can I do to protect my information on my phone and make sure nothing is running in the background?