What Is a Fake Login Page?
A copied login screen can send your password to a stranger.
Free video lesson · 1:11
What Is a Fake Login Page?
Phishing Awareness for Beginners
Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.
A copied login screen can send your password to a stranger.
Read the video transcript
A fake login page is a copy of a sign-in screen. It may copy the colors, logo, and password box. The difference is who receives what you type.
Imagine a link claiming to open your class notes. It takes you to a page that looks like your school login. You enter your password, but the page sends it to the person running the fake site.
Looking familiar is not enough. The copied page may even use an encrypted connection. Encryption protects information while it travels; it does not prove that the person receiving it is trustworthy.
If an unexpected message asks you to sign in, stop there. Open the school’s usual app or your saved bookmark. Find the notes from that trusted starting point.
If you already typed your password into a suspicious page, tell your school or support team promptly. Use the real service to change the exposed password. Getting help matters more than embarrassment.
For another clear example, watch How Do You Check a Link Without Clicking? Then try What Should You Do After Clicking a Phishing Link?
The short answer
A fake login page is a copy of a sign-in screen. It may copy the colors, logo, and password box. The difference is who receives what you type.
A simple example
Imagine a link claiming to open your class notes. It takes you to a page that looks like your school login. You enter your password, but the page sends it to the person running the fake site.
Looking familiar is not enough. The copied page may even use an encrypted connection. Encryption protects information while it travels; it does not prove that the person receiving it is trustworthy.
If an unexpected message asks you to sign in, stop there. Open the school’s usual app or your saved bookmark. Find the notes from that trusted starting point.
If you already typed your password into a suspicious page, tell your school or support team promptly. Use the real service to change the exposed password. Getting help matters more than embarrassment.
Put it into practice
- Stop when an unexpected message sends you to a login form.
- Open the service from your own bookmark or app.
- If you entered a password on the suspicious page, report it and change it through the real service.
Check your understanding
A copied login page has an encrypted HTTPS connection. Does that prove the owner is trustworthy?
Answer
No. Encryption protects the trip to that site. The site could still belong to a scammer.
Explore next
Follow the free video course one question at a time. Teams can practise these habits through security training. For the cryptography protecting your systems, explore a cryptography audit.