Password-Reset / 'Was This You?' Credential Phish
A fake 'password reset requested' or 'was this you?' alert links to a lookalike login that captures your password and any code you enter.
Think a message like this reached you? You can check it right now.
What this scam is
You receive an alert that a password reset was requested or unusual activity was detected, urging you to click 'this wasn't me' or 'secure your account.' The link opens a fake login that harvests your username, password, and any one-time code you type — sometimes in real time so the attacker logs in immediately. The alarm is engineered to make you log in fast without checking the address.
What it usually looks like
- A 'password reset requested' or 'was this you?' message.
- A 'secure your account / this wasn't me' link.
- A login page that mimics the real service.
- A prompt to enter a verification code.
Common warning signs
- The link's address isn't the real service.
- You're rushed to log in to 'stop' access.
- Password and 2FA code requested on the same page.
- The alert is unexpected.
Example wording scammers use
“We received a request to reset your password. If this wasn't you, secure your account: account-secure-verify.net”
“Unrecognized sign-in attempt. Verify it's you within 10 minutes.”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- Your username, password, and one-time code.
- Immediate access to the account.
- Reusable credentials.
What to do
- Don't use the link; open the app or type the real address.
- Change your password from inside the real account if worried.
- Turn on app-based two-factor authentication.
- Delete and report.
What to do if you already responded
- Change the password and revoke unknown sessions immediately.
- Re-check/enable two-factor.
- Report at reportfraud.ftc.gov.