5 min read

5 Real Examples of Fake Login Pages (and How to Spot Them)

Facebook logo
Facebook logo
X (formerly Twitter) logo
X (formerly Twitter) logo
LinkedIn logo
LinkedIn logo
Reddit logo
Reddit logo

Key takeaways

  • Visual inspection doesn't work anymore. Branding and layouts can look genuine, while browser-in-the-middle attacks can render the legitimate login page itself.

  • Check how you got there. AI recommendations, device codes, attachments, redirects, and unfamiliar domains can reveal phishing attacks.

  • MFA doesn't make every login safe. Browser-in-the-middle and OAuth phishing can capture authenticated sessions or tokens after multi-factor authentication (MFA).

  • Follow the delivery path. Infrastructure monitoring can identify phishing-kit fingerprints, suspicious domains, redirects, and authentication flows.

A fake login page can have the right logo, the right layout, the right fonts, and every other detail you expect to see.

Sometimes, it may be a cloned portal, a phishing page surfaced by AI tools, or even a legitimate login page rendered through an attacker-controlled browser..

At that point, checking whether the page “looks right” doesn't get you very far. The clues are increasingly in how you got there: the malicious link that sent you, the domain name in the address bar, the redirects along the way, or an authentication request you didn't initiate.

These five real examples show what fake login pages look like now, and what still gives them away.

Fake login pages examples at a glance

Example

Platform

Delivery lure

Key warning sign

Wells Fargo via AI summaries

Copilot

AI chatbot recommends the phishing link directly

Unusual domain and an AI answer supplying the login destination

Microsoft via Bluekit BitM

Microsoft 365

Legitimate page streamed through an attacker-controlled browser

Marginal latency and a custom CAPTCHA

BambooHR via Same cloning

BambooHR

AI-cloned page targeting a specific subdomain

AI-generated logo and public chat logs

Docusign via OAuth device code

Docusign

Device code lure sends the victim to legitimate Microsoft authentication

Unsolicited device code for a sign-in the user did not initiate

Gmail via SVG attachment

Gmail

Confluence page leads through a weaponized SVG to the phish

Redirect chain through unrelated infrastructure

1. Wells Fargo phishing login page surfaced in an AI summary

Phishing pages are increasingly targeting both people and AI-assisted workflows.

In this incident, when asked how to log in to a Wells Fargo account, Copilot’s first response was a phishing page impersonating the bank’s login portal. The user never even needed to type a URL, because the AI recommended it.

Copilot chat response presenting a phishing page impersonating Wells Fargo’s login portal as the first link.

Watch for:

  • Delivery source: Treat an AI-generated login recommendation as a search result, not proof that the destination is legitimate.

  • Domain: The recommended URL used wellfargoss[.]com, rather than a Wells Fargo domain name. Check the address bar before entering any login information.

AI summaries increasingly sit inside normal search and browsing workflows, giving malicious links another route to potential victims. Netcraft researchers found this example while testing thousands of responses across four major AI answer engines.

Read the full analysis: Threat Actors are Finding Their Way into Your AI Summaries

2. Microsoft login streamed through Bluekit

Bluekit uses browser-in-the-middle (BitM) technology to load Microsoft's legitimate login page inside an attacker-controlled browser and stream it to the victim in real time.

Victims log into their accounts on the attacker's machine. Bluekit can capture the authenticated session after they enter their login credentials and complete MFA, creating a route to account takeover.


A Microsoft login page rendered inside a live Bluekit deployment.

Watch for:

  • Marginal latency: Streaming the page can introduce a small delay between the victim's actions and what appears on screen.

  • Custom CAPTCHA: Bluekit deployments often use CAPTCHAs that aren't native to Google or Cloudflare.

This is where visual inspection reaches its limit. 

Netcraft researchers identified Bluekit through signatures including its rrweb DOM-streaming library, custom CAPTCHA HTML, and WebSocket traffic patterns, detecting roughly 70 hostnames running the kit in one week.

Read the full analysis: Bluekit Phishing-as-a-Service: Browser-in-the-Middle (BitM) Analysis

3. BambooHR login page cloned with AI

Same is an AI website cloning chatbot that can recreate a website's appearance and behavior and deploy the result to Netlify.

Netcraft researchers found threat actors using it to clone the BambooHR login page for Wildix, an IT and communications provider. The public chat showed the clone being created in minutes.

A spoof login page with a suspicious AI-generated logo.

Watch for:

  • Public chat logs: Same projects were public by default, exposing the request to clone the BambooHR login page.

  • Suspicious logo: When Same found multiple possible logos for Wildix, it generated one rather than reproducing the company's real logo.

AI cloning reduces the work needed to reproduce branded layouts and entire phishing websites for credential harvesting. What once required a web development project can now take little more than a prompt. Netcraft used the investigation to improve its classification systems and identify new Same staging URLs.

Full analysis: AI-Powered Website Cloning: Same Tool Enables Automated Phishing at Scale

4. Docusign OAuth phishing without a stolen password

In this attack, cybercriminals abuse OAuth to compromise accounts (specifically, Docusign accounts) without using stolen credentials.

The attacker sends a lure containing a device code. When the victim enters that code on Microsoft's legitimate verification page, the attacker's client receives access and refresh tokens that can provide ongoing API access under the victim’s identity and enable full account takeover (ATO).

A spoof Docusign login page showing a two-factor authentication code.

Watch for:

  • Unsolicited device code: Treat a code for a sign-in or document workflow you didn't initiate with suspicion.

  • Unexpected authorization: Check what you're being asked to authorize, even when the verification page itself is legitimate.

This form of OAuth consent phishing targets authorization rather than conventional credential theft through a spoofed login form. The lure uses familiar document-signing social engineering tactics to persuade the victim to complete the authorization flow. 

Netcraft researchers have identified thousands of EvilTokens attacks through shared infrastructure, domain patterns, and lure characteristics.

Full analysis: EvilTokens and OAuth Abuse.

5. Fake Gmail login delivered through an SVG attachment

A phishing email offering an RFP or document to sign sends the victim to a legitimate public Confluence page.

That page links to a malicious SVG hosted on AWS. Obfuscated JavaScript inside the SVG generates a fresh subdomain and redirects the victim to Sneaky 2FA, a phishing kit that imitates Microsoft 365 and Google login pages.

A fake Gmail login page.

Watch for:

  • Redirect chain: Follow where the link actually takes you. In this campaign, the journey runs from Confluence through an SVG and unrelated infrastructure before reaching the credential prompt.

  • Final domain: Check the address bar at the final login page rather than assuming the trusted service that started the workflow also hosts the destination.

The trusted Confluence page gives the attack a familiar starting point, while dynamically generated infrastructure and anti-analysis techniques make detection more difficult.

Full analysis: Confluence SVG RFP Phishing Scam

What these fake login pages examples reveal

The techniques behind phishing campaigns are becoming increasingly sophisticated, extending beyond brand impersonation to highly convincing login and authentication experiences. The same attention to detail seen in social media impersonation scams now extends to the login experience itself.

The useful impersonation signals appear throughout the journey: the domain an AI tool recommends, streamed-session latency, an unsolicited device code, or redirects before a credential prompt.

For brand protection teams, domains, authentication flows, phishing-kit fingerprints, and related infrastructure can reveal connections between individual fake login pages and the campaigns behind them.

How you act on those signals matters, too. Netcraft has applied this phishing and scam protection approach across more than 50,000 takedowns, with a 99.8% success rate and phishing URL takedowns as fast as 2.1 hours.

That wider view gives brand protection teams more to act on than a single reported URL.

Don't leave your brand protection up to chance. Work with Netcraft today. Get a demo

FAQs about fake login pages

What is a fake login page?

A fake login page is a sign-in experience used for credential harvesting, credential theft, or account takeover. Cybercriminals can create phishing websites that copy branded layouts or use BitM techniques to capture authenticated sessions.

How can I tell if a login page is fake?

Check the domain name in the address bar, how you reached the page, and any redirects. A padlock icon or SSL certificate shows that the connection is encrypted, not that the site is legitimate.

Treat links delivered through a phishing email, smishing, attachment, AI answer, or QR code carefully. Unexpected device codes, MFA requests, custom CAPTCHAs, or unusual latency can also reveal phishing.

Can a fake login page steal my account if I have MFA enabled?

Yes. Multi-factor authentication (MFA) and two-factor authentication help prevent many attacks, but BitM can capture authenticated sessions and OAuth phishing can obtain tokens after authentication. An authenticator app doesn't make an unexpected request automatically safe.

What should I do if I find a fake login page impersonating my brand?

Capture the URL, screenshots, and lure, warn affected users, report the phishing website at report.netcraft.com, and monitor for related or replacement pages.

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.