Nano-lesson · usually takes 2–3 minutes
Fake login pages & MFA scams
When a login page is fake — and why you never approve an unexpected MFA prompt.
An exact copy of the login page
The page you land on looks just like the real login page — the rota system, Microsoft, your online banking. But it's a copy: everything you type goes straight to the scammer. Your login credentials are phishing's most common target — and only the address gives the copy away.
So where does the link actually go?
https://login.microsoftonline.com.account-confirm.ru/signin
Look at the domain right before the first forward slash (/) — here account-confirm.ru, not microsoft.com. The genuine Microsoft login is never on such a foreign domain.
Watch out for
- A login page you reached via a link in an email/text — always check the domain in the address bar.
- MFAMulti-factor authentication (MFA/2FA): an extra step beyond your password — such as a code or a tap on your phone — so a thief can't log in with the password alone. prompts or codes you didn't trigger yourself — if your phone asks "Approve login?" when you're not in the middle of logging in, someone else is trying with your password.
Do
go to the site yourself — via the app, a bookmark, or by typing the address. Let your password manager fill it in — it will refuse on a fake domain. Reject any MFA prompt you didn't start, and change your password.
Remember
What the research says
Bombarding a phone with approval prompts works: about 1% approve even the very first unexpected prompt — and Microsoft measured 382,000+ attacks of this kind in a single year. So: reject any MFA prompt you didn't trigger yourself, and report it — it usually means someone already has your password.
Question 1 of 3
Your phone keeps beeping with "Approve login?" — but you're not trying to log in. What do you do?
✓ Correct!
The prompts mean someone already has your password and is trying to get in. Approving even once lets them in — and silencing your phone doesn't undo the fact that your password is compromised. Reject, report, change your password.
Question 2 of 3
Your password manager won't fill in the login on a page you reached via an email link. What does this usually mean?
✓ Correct!
A password manager only fills in details on the genuine address. When it refuses, it's often because the page is fake — never type the password in manually instead.
Question 3 of 3
An email from "Microsoft" asks you to log in and review a warning. What's safest?
✓ Correct!
Fake addresses often have "microsoft" somewhere in the name (login.microsoftonline.com.fake-domain.ru) — and a fake page can forward your MFA approval instantly. Go there yourself, your own way.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.