Blog/Phishing

Fake Login Pages: How They Copy the Real Thing

Phishing login pages can look pixel-perfect and even relay your two-step code in real time. How fake sign-in pages work and the signs that reveal them.

CyberWatch AI1 October 2026 · 2 min read
A laptop on a sofa showing a web dashboard

The goal of most phishing is a fake login page. It copies the real sign-in screen of your email, bank or work account, down to the logo and fonts. Modern phishing kits go further: they pass your details to the real site in real time, so you may even appear to log in successfully.

How fake login pages work

  • Cloning: the real page's design is copied exactly.
  • Pre-filling: your email address is included in the link, so the page greets you by name.
  • Relaying: "adversary-in-the-middle" kits forward your password and two-step code to the real site, capturing your session.
  • Redirecting: after you enter details, you are sent to the real site so nothing seems wrong.
  • Hosting: pages sit on lookalike domains or on legitimate cloud services. See cloud storage links.

Signs you are on a fake page

  1. The domain is not the service's real domain. See how to read a URL.
  2. Your password manager does not offer to fill in. See password managers as a phishing alarm.
  3. You arrived from a link in an email, text or ad.
  4. You are asked to sign in when you should already be signed in.
  5. After signing in, you are sent back to the start or shown an error.

Text codes and app approvals can be relayed. Passkeys and security keys only work on the real site, so fake pages cannot use them. See passkeys vs phishing.

If you entered details

Change the password immediately from the real site, sign out of all sessions, and check for new devices and forwarding rules. See entered your password on a phishing page.

Unsure about a sign-in page? Paste its address into CyberWatch AI Scan for a free check.

For more, read our phishing guide.

Frequently asked questions

Can a fake login page steal my two-step code?

Yes. Some phishing kits relay your password and code to the real site in real time, logging the attacker in. Passkeys and security keys resist this.

The page even showed my email address. Is it real?

Not necessarily. Phishing links often include your email address so the fake page can pre-fill it.

What is the quickest tell?

The web address, and your password manager not offering to fill in your password.

Sources

  1. Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
  2. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  3. Report a phishing page, Google Safe Browsing
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.