Refunds Direct logo Refunds Direct
Security Back to Insights

Phishing & Fake Support

Impersonation tactics to steal credentials, intercept 2FA, or push malware.

Red flags

  • Look‑alike domains or homoglyph characters in URLs.
  • Search‑ad traps that place fake support pages above real ones.
  • Urgent login/payment prompts with scare tactics.
  • Requests for 2FA codes or remote‑access installs.

What to do

  1. Close the page/app; do not enter credentials.
  2. Reset passwords from the official app/site you type manually.
  3. Rotate recovery codes; revoke sessions and app passwords.
  4. Check for unwanted extensions or remote‑access tools.

Evidence to collect

  • URL and full‑page screenshot.
  • Emails with full headers; SMS sender info.
  • Hashes of any files you downloaded (if known).
Start a free case review