Phishing defense center
Verify login alerts, support messages, OAuth prompts, QR codes and lookalike domains without trusting the message that created the urgency.
How to use this section
Use the Phishing defense center directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
The safest first move is to separate the message from the verification channel. Open the known app or type the provider address manually, then compare the claimed event with activity shown inside the real account.
Business Email Compromise
Verify executive, vendor and payment-change messages outside the email thread.
Open guide →Fake Password Manager Extensions
Verify browser-extension publishers, permissions and installation source.
Open guide →Fake Support Impersonation
Recognize unsolicited support, remote-access and one-time-code requests.
Open guide →Lookalike Domain Checks
Inspect the registrable domain and avoid trusting logos, subdomains or display names.
Open guide →MFA Push Fatigue Attacks and Prompt Bombing
Respond to repeated push prompts, calls or approval requests you did not initiate.
Open guide →OAuth Consent Phishing
Review app publisher, requested permissions and business need before authorizing.
Open guide →QR Code Phishing
Treat QR codes as links and verify the destination before signing in or paying.
Open guide →Recognize a Fake Login Page
Check context, domain, password-manager behavior and unexpected sign-in prompts.
Open guide →How to Verify a Security Alert
Confirm login, breach, password and payment alerts without using the alert’s link.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.