Back to Blog

What Is Phishing and How to Spot a Fake Website in Chrome

PB

Patrick Bushe

September 29, 2024 ยท 5 min read

Phishing is when criminals pretend to be a company or person you trust to get your passwords, card numbers or money. Most attacks lead to a fake website that looks like the real one. Chrome gives you several ways to spot them.

How phishing reaches you

  • Emails or texts about a problem with your account, a delivery or a payment.
  • Ads and search results that lead to lookalike sites.
  • Messages from hacked friends' accounts.
  • Pop-ups claiming your computer is infected.

Check the real address

The address bar is the most reliable clue. Look at the part just before the first single slash:

  • Lookalikes: paypa1.com, amaz0n-support.com, micros0ft.co.
  • Extra words: secure-paypal-login.com isn't PayPal.
  • Tricky subdomains: paypal.com.account-verify.net belongs to account-verify.net.

Click the icon to the left of the address to see site details. Chrome replaced the padlock with a neutral icon in 2023 because the padlock made people think a site was trustworthy; it only means the connection is encrypted, and phishing sites have encryption too.

Warning signs

  • Pressure: "your account will be closed in 24 hours".
  • A login page you reached from a link rather than by typing the address.
  • Requests for codes, card details or passwords you wouldn't normally give.
  • Prices far below everywhere else.
  • A page telling you to copy and run a command to "verify you're human". No real site asks for this.

Let Chrome help

  • Safe Browsing: Chrome shows a red warning page for known phishing sites. Turn on Enhanced protection in Settings โ†’ Privacy and security โ†’ Security.
  • Password manager: Google Password Manager fills passwords only on the site where you saved them. If it doesn't offer your password, look closely at the address.
  • Passkeys: they only work on the real site, so they can't be phished.

The safe habit

When a message asks you to sign in, don't use its link. Open the site yourself by typing the address or using a bookmark, then check for the issue there.

If you entered your details

  1. Change the password on the real site, and anywhere you reused it.
  2. Call your bank using the number on your card if you gave card details.
  3. Turn on two-factor authentication. See setting up two-factor authentication.
  4. Check recent account activity and sign out other sessions.
  5. Report the site through Google's Safe Browsing report form to help protect others.

About your clipboard

Clipboard Guard stops web pages from reading your clipboard. It doesn't stop a page from putting text into it, so never paste commands a website gives you. See also fake Chrome update popups and checking for leaked passwords.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy