Fake 'New Device Login' Alert
A 'new device signed in — was this you?' alert links to a fake login page designed to steal your password and one-time code.
Think a message like this reached you? You can check it right now.
What this scam is
You get an alert that a new device or unusual login was detected, urging you to click 'this wasn't me' to secure your account. The link opens a lookalike login page that captures your username, password, and any two-factor code you enter. The alarm is engineered so that fear makes you log in fast without checking the address.
What it usually looks like
- A 'new sign-in detected' or 'was this you?' message.
- A 'secure your account' or 'this wasn't me' link.
- A login page that mimics your bank or provider.
- A prompt to enter a one-time code.
Common warning signs
- The link's web address is not the real provider.
- You are rushed to log in to 'stop' access.
- It asks for your password and 2FA code on the same page.
- The alert arrives out of context.
Example wording scammers use
“New device signed in to your account from a new location. If this wasn't you, secure your account: account-security-check.net”
“Suspicious login detected. Verify it's you within 15 minutes or your account will be locked.”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- Your username and password.
- Your one-time 2FA code (in real time).
- Full access to the account.
What to do
- Do not use the link; open the app or type the real address yourself.
- Check active sessions and change your password from inside the real account.
- Turn on app-based two-factor authentication.
- Delete the message.
What to do if you already responded
- Change the password immediately and revoke unknown sessions.
- Enable/re-check two-factor authentication.
- Report at reportfraud.ftc.gov.