Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a fake login page?

A fake login page imitates a genuine service so that the victim will enter credentials, codes or other sensitive information.

The visual appearance is often the least interesting part. Logos, colours and wording are easy to copy.

The useful evidence is in the URL, infrastructure, page behaviour and where submitted data goes.

Look beyond the screenshot

A fake page investigation may involve:

  • domain name;
  • URL path;
  • hosting;
  • certificate;
  • HTML/form behaviour;
  • submission endpoint;
  • redirects;
  • page capture;
  • time the site was live.

A page may look exactly like Microsoft 365 while sitting on unrelated infrastructure.

Some fake pages relay to the real service

A victim may enter credentials into the fake page, which then passes them on to the genuine service.

That can make the interaction look plausible to the victim while exposing the submitted information or session material.

The technical route might be:

VictimOpens fake login pagePage copies genuine branding.
SubmissionCredentials enteredForm sends data to attacker-controlled endpoint or relay.
Relay / redirectReal service may appear nextVictim may not realise anything happened.

Preserve before interacting

Where possible, preserve:

  • original link;
  • page capture;
  • page source where authorised;
  • hosting/domain information;
  • submission endpoint;
  • time and context.

Do not enter genuine credentials into the page simply to see what happens.

Visit, submission and later use are separate

The victim may visit without submitting.

They may submit data that never reaches the attacker.

The attacker may receive it but never use it.

So build the stages separately.

What is credential harvesting? explains the collection stage.

The practical point is: prove the fake page from its infrastructure and data flow. Then establish visit, submission, receipt and later account use as separate events.

Reference: CIM-035Cyber Incidents & Offender Methods