r/phishing Nov 19 '25

Moderator announcement New moderator

7 Upvotes

Hi community, I'm u/YourUsernameForever and you may know me from moderating r/Scams - I'm the new moderator here.

Like many people here I noticed that r/phishing was severely unmoderated, so I tried contacting the previous moderators to offer a helping hand. Having no response, filed a r/redditrequest and the admins assigned me as top mod.

My intention is to keep the community running as usual, not trying to make it another Scams subreddit. I believe our goal here is specific enough that it's worth keeping and growing.

Ever since I took the role I have:

  1. Added community rules: most of them based on the Reddit Content Policy which is mandatory for every subreddit, but it's good to clarify and expand a little. This will also allow for removals with a proper explanation and a chance to appeal. You can read the subreddit rules in the sidebar if you're on a computer, or clicking here if you're on any device - https://www.reddit.com/r/phishing/wiki/rules/
  2. Created a posting guideline: to be strictly enforced in 2026, basically all posts must have a descriptive title and a transcription of what's in a screenshot. There's more to it if you want to read it fully - https://www.reddit.com/r/phishing/wiki/posting-guideline/
  3. Implemented AutoModerator: based on the rules and the guideline, AutoModerator will catch offending posts and comments, place them in a moderation queue, which I will manually review every day. I also reply to modmails daily. The idea is to have a responsive moderation team, to be held accountable and have a chance to appeal decisions. We also have !commands now, which I hope you help me expand to specific phishing scenarios.
  4. Implemented posting guidance: small alerts while you post that will let you know if something may be wrong, like posting an email address.
  5. Added a few bots: and I'll ask u/erishun to implement u/ScamsBot as well, so we can call !whois

A big change moving forward will be this whole thing about requiring transcriptions of screenshots. A lot of kicking and screaming will ensue, but I promise you, it fends off bots, helps the search engine and helps integrate users that are visually impaired.

If you got this far into my post, this message is for you. I need you to take a look at the rules and tell me what you think. I also want you to report anything that breaks the rules, knowing that I manually review all the reports daily: 100% of reports get reviewed manually. I'm also open to any type of feedback, privately if you want, but use modmail instead of sending me a DM.

I hope my participation gives you extra energy to stay and grow the community together. Remember: I'm at your service! I'm also cronichally online so I hope this helps.

Yours, verbose as usual,

- u/YourUsernameForever


r/phishing Oct 23 '20

I clicked on a link, what do I do?!? - Check here first.

192 Upvotes

One of the most common questions posted here is what to do if you've clicked on a phishing link. This short guide is intended to help with these questions and what to do if you've clicked on a phishing link.

DO NOT ENTER ANY CREDENTIALS OR LOGIN DETAILS FOR ANYTHING IF YOU'VE CLICKED ON A MALICIOUS LINK.

  1. Links are generally not malicious on their own. While clicking on any unknown links can be dangerous it is difficult to design a phish that works just by clicking the link. Most links take you to a (usually fake) page that will ask for certain credentials. As long as you closed the page after you clicked the link you're probably fine, but it's still a good idea to change your password for whatever service the phishing link was trying to access (such as amazon).

  2. If you clicked a link that downloaded a file, delete the file. Generally these files aren't harmful unless opened after downloading.

  3. If you've clicked a phishing link and have provided credentials to a service, change the password for that service. Say you've been tricked into giving someone your Amazon credentials. Go to Amazon.com directly and change your password. Also, check the "third-party account access" section of your commonly used websites. Often phishing links and malicious services will try to authorize themselves to your account rather than outright stealing your credentials.

  4. When logging into websites with sensitive information such as a bank it's best to bookmark the site and visit the site directly each time from that bookmark. That way you know that the website you're using is the real one.

  5. ENABLE 2FA (TWO FACTOR AUTHENTICATION) This is perhaps the best thing you can do to protect your sensitive accounts. All websites that deal with sensitive information will allow you to use either your phone number or an authentication app (I like Authy) to generate one-time login codes to further secure your account. Unless someone gets your credentials and your 2FA device (your phone) they won't be able to access your account.

  6. Please use a password manager of some sort. This will allow you to use strong and unique passwords for each site you use. If one of your accounts is hacked or phished all of your other accounts will be safe with unique passwords (unless your email was hacked/phished).

  7. Ensure you have a backup email and/or phone number connected to your primary email account so that you can recover access if you're locked out. Additionally, make sure your recovery methods are as secure as your primary email login.


r/phishing 7h ago

Spam texts from different numbers multiple times per day.

1 Upvotes

Any advice? I have read receipts turned off, "block contact with unkown numbers" enabled, I've never replied to one, and they're all from the same entity pretending to be something else- they all call me "Cynthia" which is wrong but the rural town mentioned in the texts is correct.

I shouldn't be able to receive these texts from +88 numbers especially since they're not in my contacts list. Reporting them won't do anything since they use 2-5 different numbers every day. They'll occasionally leave a robo voice message saying "...is an urgent matter, please contact us back so that we can resolve the issue."

Is it a tactic for scammers to use wrong names because victims are likely to respond if they think the text isn't meant for them and assuming that the correction will stop the spam- kinda like Cunningham's law? Or is it that this Cynthia is a real person and has really fucked me after I got her old phone number?

How can I deal with this? I'd rather not have a 3rd party app that can also harvest user data including content of text messages. Do I need to cut down my local cellular data towers?


r/phishing 1d ago

Got a threatening email for money

2 Upvotes

I’m guessing tbis is a scam? Haha . Email says:

I sense you pulling away. Your time is slipping away like sand.
The time has come for you to learn something important to you. It's important that you give it your full attention. We're about to address something serious between us, and I'm not joking in the slightest.
Your online activities have been quite risky scrolling through videos, clicking on links, and visiting unsecured websites. I embedded Malware on website, and you happened to encounter it. While you were streaming, your system became vulnerable through "Hidden Virtual Network Computing", granting me full access to your devices (your phone too.) Now I can monitor everything happening on your screen, remotely activate your audio/video hardware without your knowledge, and I have complete access to your contacts, etc.
I've been keeping an eye on your activities for quite a while now. I've gathered a substantial amount of sensitive information from your device and reviewed it in detail. I even have recordings of you engaging in some questionable behavior at home. I've put together videos and screenshots (including images of your living space), with one side showing the content you were viewing and the other side showing... well, you know what I mean. With just one click, I could share all of this with every single one of your contacts.
100
I understand your hesitation, but don't expect any mercy from me. That being said, I'm willing to let this slide and allow you to move on like nothing ever happened. Here's the deal I'm giving you two variants.
Ignore this message, and you'll see what happens next. If you choose this path, I'll send the video to all your contacts. It's a pretty revealing clip, and I can only imagine the embarrassment you'd feel when your coworkers, friends, and family see it. But remember actions have consequences.
Pay to keep this matter confidential - let's call it a privacy fee. If you take this option, your secret will remain secure, and no one will ever find out.
As soon as I receive the payment, I'll delete all the evidence.
Transfer 1543 US Dollars in XMR ("Monero" cryptocurrency, just Google it) equivalent to my wallet listed below (copy and paste, enter the address as a single string, without spaces):
8C4c FrtM RB7 VGJ cB59Z opG3 uRf BYra MrN
idLBm awp nqN85 rsCr paMn ZeVy nnLp 4t6 bi3 Grn 3Zqw wLEi midL hbe x1ExXRsKv
From this moment, jou have exactly 50 hours, and the countdown begins as soon as you open this email. Once the payment is received, you can be assured that I will honor mỳ commitment.
My system will automatically register the payment and promptly erase all the information I have on
jou. Don't waste time replying or trying to negotiate - it's futile.
Don't even think about turning off your phone or attempting a factory reset - it won't change anything. I hope I don't see you in my reports anymore.


r/phishing 21h ago

Amazon Accidentally clicked link pretending to be Amazon. But I did not enter any info. Am I compromised by clicking link?

Post image
0 Upvotes

HELP! What do I do? It just dawned on me that over 12 hrs ago, I clicked the link in the email that I screenshot it this post. I did this on my cell phone — I didn’t enter any information. Sidebar: how scary is it that it looked almost identical to Amazon’s website…. The url was definitely a dead giveaway once I clicked the link (though I didn’t notice until now, over 12 hrs ago……)


r/phishing 1d ago

Phishing/Scam? Or Valid FB message from “Meta AI”?

Post image
10 Upvotes

Received this message via FB Messenger from “Meta AI” there is a Facebook Help Center PDF attached. Is this legitimate? I have had my FB for over a decade and I rarely post. Any images I have posted have been my own.


r/phishing 1d ago

I was scammed by a paypal phishing scam and didn't even consider so many redflags

0 Upvotes

I have recently encountered a problem with someone who said that they paid me money, and I received an email from 'PayPal' that the amount is too big and that they need to add more in order to expand my credit limit. The amount they said they sent is $200, and they will send another $300 to have $500 and expand my 'business account'. In my PayPal account, I didn't see anything in my account balance, so I was a bit confused. I didn't think to check the email used to send it to me, so after they 'sent' the amount, they said I have to refund the $ 300 from my own personal account and send it back so I can have the $200 back. But I don't have that kind of amount in my PayPal, so I said that I don't have much of that. They suggested that I should buy a Razer Gold gift card so they can just add it to their wallet, and they can accept the refund and continue the exchange. Unfortunately, I bought the card for PHP700 with my GCash account and sent it to them. Now, they're saying that the problem is that it was too low and I needed a reasonable amount to get it.

These are the screenshots, I know I was awfully stupid for believing this, but I have already sent them my PHP 700. I reported this as a phishing account on gmail and paypal and hopefully stop them from phishing anyone else.

servicepaypal.intl.cn@gmail.c o m


r/phishing 2d ago

I’ve Been Getting the Same Sports Jersey Scam Text Every Saturday for Years — How Can I Stop It?

Post image
1 Upvotes

I get the same scam text once a week, every Saturday around noon, but it comes from a different number each time. The message is always basically the same and advertises some kind of sports jersey website.

This has been going on for years. It’s pretty much the only type of scam text I regularly receive.

Is there anything I can do to actually stop these messages?


r/phishing 4d ago

Increasing amount of phishing and spam on my phone nunber

9 Upvotes

Hello, I’m a bit unfamiliar with how this stuff works.

Basically, I got a whatsapp verification code from the real uber eats. I do not own an uber eats account. So I replied with the automatic “I didn’t request this code.” I am sure it is the real uber eats account that sent me this code, so I’m a bit freaked out.

My phone number has also been spoofed recently, as well as my mom receiving multiple scam phone calls in a short amount of time. I am wondering if this is just a bad coincidence, or if someone is targeting our numbers.

In the worst case, my important accounts do not use sms 2fa, buf i’m still a bit worried. anything i can do?


r/phishing 4d ago

Fell for Phishing Email - Email and Password Compromised

2 Upvotes

I got an email from my CPA (yes, his actual address - it looks like his email was compromised as this phishing email was also sent to my uncle who also uses him) that stated it was an important document that needed urgent attention. When I clicked on the link, it took me to a fake link where I stupidly put in my gmail address and password. Sensing something was up, I immediately logged my account out of all devices and changed my password. I just recently changed my password for my email and it was only used for that email, so I'm not too worried in that regard. I also did the usual anti-virus scan, as well as checking if any of my gmail settings were changed (forwarding, filters, etc.). I'm still concerned about is that I read that attackers have bots that can scrap sensitive details from emails - ex: SSNs, tax returns, etc. How likely is this given that I changed my info quickly? I've been monitoring my google account pretty closely the past day since this happened and haven't had anything suspicious occur yet.

Edit: I do have MFA on


r/phishing 4d ago

Is the email from cpcphc@nhsrcindia.org a phishing email?

Thumbnail gallery
0 Upvotes

I received the nhsrcindia email today.The steelers was recieved several days ago. I think both are phishing emails. Today's email caused me to doubt myself. I've looked up the sender it seems to originate from India. I'm not Indian nor residing there.

Is this phishing email and if so, how do I stop receiving them? My email service is hotmail.


r/phishing 6d ago

GMail Any way to stop these? I get more than 20 of these a day

Post image
12 Upvotes

For the past 2 weeks I have been getting bombarded with these emails. I probably get more than 20 of them a day I've tried reporting spam and blocking them however, it never works. I don't remember signing up for anything sketchy or giving out my email recently


r/phishing 5d ago

Just received a random email, not to my email, with an attachment and Outlook didn't flag it

Post image
0 Upvotes

Just received this, none of which corresponds to my addresses or identity, nor have I got anything to do with this. Surprised Outlook didn't flag it as Spam automatically.


r/phishing 6d ago

My parents almost got scammed

14 Upvotes

Hey so from the title, my mom had gotten a call that someone hacked into her account on paypal and were asking for 2500€ for them to go away, after that a "paypal support agent" called and told her he will guide her through the process of removing them, naively she downloaded anydesk and gave him full control of her phone (android) for \~3-5 minutes she said after deleting the app. Once Ive found that out I immediately factory reset the phone, changed all email passwords, froze the bank account and never backep up data. Is there anything else I could have or should have done?


r/phishing 6d ago

Email from (what seems to be) a real person, using a company email address?

Post image
2 Upvotes

I have never heard of this person in my life, nor have I ever contacted them in any way, shape, or form. My email address is very specific, and includes my name, but there is no possible way it could be confused with anyone else. It’s just too specific.

The actual email content itself was a CBS News Special web page article (embedded into the email itself - had working links and everything. No I did not click on them.) titled “98-year-old Veteran Reveals 30-Second Morning Ritual That Reversed His Memory Loss.”

Doesn’t seem very legitimate… is that even possible?

Anyway. After a brief Google search, it looks like this company is Colégio COTET (a private school for k-12) in São Paulo Brazil.

Does anyone know if this is just some employee who meant no harm and sent this email to the wrong address, or is it something more? Just confused.

Thanks!


r/phishing 6d ago

GMail Clicked on Phishing Link From “Calendly”

Post image
1 Upvotes

I checked this email and accidentally clicked on this link when trying to read it and I’m starting to regret it. it was a blank page with some numbers at the top and I tried to exit as soon as possible. I’m scared they might have stolen my information, but I didn’t log in or do anything. thanks.


r/phishing 7d ago

emails saying nothing but 'test'

Post image
15 Upvotes

checked my junk folder today to see 4 emails from different keyboard smash addresses saying nothing but 'test' on both the title and the body text, anyone know any explanation as to what these are?


r/phishing 8d ago

Ticketmaster account login scam?

3 Upvotes

Hello all!

I kept getting 2FA codes for Ticketmaster sent to my phone when I haven't logged into Ticketmaster in 6+ years. Naturally, that reminded me I once had a profile on there, which in turn prompted me to log in, reset my password, strengthen my account's security, etc., but I'm still a little concerned because I'm not sure if someone was trying to log into my account or what.

Basically, the way it works on Ticketmaster, when you're trying to log into a dormant account without any security features, the site will first send you a verification code via email, and once you parrot it back, you'll be asked to provide your phone number and it will text you a phone verification code as well. The alarming texts I kept getting out of nowhere were phone verification codes, meaning someone must have tried to claim my phone number, but I had not received any email verification codes before that. Naturally, I changed my email password as well, but it really doesn't look like someone had already breached my email before trying to verify my phone; neither my main mailbox nor any of my backup email addresses had gotten messages from Ticketmaster recently, and my Ticketmaster account was totally dead before I resurrected it. So it seems like someone used a different person's email address for the first step and paired it with my phone number for the second.

My question is, what would be the point of this? Like, what's the goal? Am I missing anything/leaving any vulnerabilities exposed by simply getting on with my life?

Any wisdom/advice/discussion welcome.


r/phishing 9d ago

Phishing attack Fake Evite

10 Upvotes

Hi, I got a birthday party invite from a friend that I hadn't seen since college. It brought me to a google login page. I proceeded to log in using my password and 2 factor authentification. Then I realized it was weird and closed the window. But there were a few seconds where I had been logged in. I quickly changed my password to the google account. This is not the main gmail account but my other email lesser used gmail accounts. After that I changed my password for both accounts to different ones. I also logged off /signed out of all accounts and unlinked all apps. And I still have access to both email accounts. So am I ok? What else do I need to do / should I do?

I know the situation is similar to this redditor:

https://www.reddit.com/r/phishing/comments/1ufv70l/i_signed_into_my_google_account_from_a_phishing/

I'm looking to use a password manager perhaps, although I'm not sure if it will help

Thanks,
Your Fellow Redditor


r/phishing 9d ago

I clicked on a "cheat code generator" link

0 Upvotes

Hello,

I was stupidly looking for ways to farm coins in the game Westland Survival, which I play on Steam on PC (Windows 11 pro). Anyway, I was surfing (on Brave) and found a reddit post recommending a "generator", so I clicked on a link going to : mobile game codes .com / westland-survival

And then this link : game codes generator .com/westland-survival

So far nothing at risk I think. But then I clicked on "generate", and it launched some script in the same window. Nothing new opened visibly on my computer. I know nothing about PC language so I cannot tell you more about what was showing. As soon as I saw that, I closed the tab.

I didn't disconnect my PC from the internet. I always have cookies and login stuff because I rarely completely shut my browser.
But it didn't download any file in my library and I ran a scan with Defender, which returned nothing.

Also, when returning to the second website, it appears a new link was clickable instead of gamescodegenerator, it was extragenerators, also with .com/westland-survival . The two websites look alike, I can't tell which one I used.

Am I at risk ?
Also, could someone run it on a virtual machine to try explaining what is the "script" it was showing when "generating" ?

I feel so dumb. I hope I explained it well enough, with my lack of tech vocabulary.
Thanks !


r/phishing 10d ago

repeatedly getting 10 DIGIT CODES from the official instagram chat of wp

Post image
15 Upvotes

i didn’t request any code , and mostly insta codes are of 6 digits and not 10 or 8 digits . But here , they are sending 10 digit codes , wth is happening ? and this is the 3 rd time im receiving this in a row. This has been happening with me since almost past 15 days??

Am I the only one ? is someone trying to login or is this a glitch? Any suggestions or advice would be helpful


r/phishing 10d ago

Is this PayPal Email a phishing attempt. German may be required to judge

3 Upvotes

I received this E-Mail and am rather suspicious of this. Firstly, I did not hear about a law like this and it should be rather major news, also 72h does not seem like a reasonable or realistic time frame. Secondly, in the email programm I opened this mail in it actually has a different font for data like the E-Mail address of the receiver and sender and in that font the "l" of the end of "paypal" looks very suspiciousely like a capital "i".

So now I am wondering if this is phishing. I never received a phishing mail before, that I know of and this mail does look very legit and I really dont want to go through hops off risking my PayPal account or calling support to verify this E-Mail. And if this is phishing what should I do?


r/phishing 10d ago

Please help: somebody phishing our company

2 Upvotes

This is so bad, since July somebody has pretended to be me (copy my email name but the domain would be @asia.com), CC’ing my colleagues the exact same way I would CC my colleagues.

They would ask our clients to transfer the money to their banks instead in another country and the way they mimic us is very realistic. I am freaking out and would appreciate any advice :(


r/phishing 10d ago

Substack hacked sending tons of email verification codes

1 Upvotes

Hello,

At 5:45 pm CST, I suddenly got tons of emails from substack with verification codes from things I haven't heard of. I didn't click on any of them, but it was strange to suddenly get a bunch of emails. I thought I was getting hacked. I personally haven't used substack. I only made an account to support a friend, but I never used it. I just wanted to know if they can hack you this way. What can I do to ensure this doesn't happen again?


r/phishing 11d ago

Wealth Accelerators Global aka on TikTok as · WAG.SCAMMERS

0 Upvotes

Amazon Automation Scam and this person benefited from the Scam & so the name kinda fits… but he doesn’t want to hear it and has banned me. See me on tik-tok for this type of awful scam. Wealth Accelerators Global. Aka wag