The Scariest Fake Discord Login Phishing Scam!

Sdílet
Vložit
  • čas přidán 5. 06. 2024
  • A lot of Discord scams are based on tricking the user to log into a phishing website (or a fake website disguised as discord). A lot of these websites are easy to detect though, you just look at the URL bar and make sure it's discord.com.
    However, what happens when you get a popup that has the normal discord URL and looks legit?
    Well surprisingly there are some fake discord login pages that can disguise their URL by using some HTML trickery. Thankfully, there is one very easy way to tell if we are about to be phished.
    Use promo code: ISubscribedToNTTS for 0% off your Walmart order.
    SOCIALS
    -----------------------------------------------------------------------------
    Discord Server
    / discord
    TIMESTAMPS
    -----------------------------------------------------------------------------
    00:00 - Introduction
    00:36 - The scam
    02:04 - Explaining the popup
    05:42 - Conk clue shun
    07:00 - How to recover your account
    08:03 - Outro
    MUSIC
    -----------------------------------------------------------------------------
    C418 - Minecraft - Volume Alpha (Minecraft music)
  • Zábava

Komentáře • 1,6K

  • @Parsa0
    @Parsa0 Před rokem +6206

    The funny thing is that they used a backslash "\" in the fake URL instead of a forward slash "/" which gives away the entire scam easily if you pay a little bit of attention.

    • @ultraracer
      @ultraracer Před rokem +120

      I know right like it’s so easy

    • @amongleAcc
      @amongleAcc Před rokem +422

      Also, "Scan this with the Discord mobily app to log in instantly." That seems a little... off.

    • @sinxzx7172
      @sinxzx7172 Před rokem +78

      @@amongleAcc thats a real thing discord has.

    • @natec1
      @natec1 Před rokem +448

      @@sinxzx7172 discord doesn’t say “mobily” lmao

    • @LegoClara01
      @LegoClara01 Před rokem +16

      lol you are correct, i would not fall for this

  • @ethanrushbrook3314
    @ethanrushbrook3314 Před rokem +1070

    Scammers are getting really good these days but I think that takes the cake. Very impressive. Its a shame skilled devs are doing stuff like that, what a waste of skills

    • @peeteee
      @peeteee Před rokem +126

      its like being able to run faster than usain bolt but using it to bump into people

    • @EASIllinois
      @EASIllinois Před rokem

      @@peeteee or using shaq's strength to kill people instead of play basketball

    • @TyKoz825
      @TyKoz825 Před rokem +64

      @@peeteee A TRAIN BABY

    • @winninggaming1683
      @winninggaming1683 Před rokem +15

      its like being able to jump higher than a kangaroo but using it to crush people

    • @feritperliare2890
      @feritperliare2890 Před rokem +9

      @@peeteee I mean it’s average plus skill like it’s good design and all but also it requires very little functionality so mostly it’s about coping the design that is not too hard to do

  • @WanderingShogun3142
    @WanderingShogun3142 Před rokem +508

    the fact that he didn't even realize the backslash instead of forward slash speaks levels about how dangerous these scams can be

    • @tonypatino1765
      @tonypatino1765 Před rokem +9

      no, some people aren't braindead

    • @U20E0
      @U20E0 Před rokem +11

      @@rewrite1239 the changing the / to \ does literally not do anything. It’s literally just a piece of text that’s not used for anything.
      Also changing \ to / automatically is bad design. What if the site actually has a resource called “/some
      andom\file”

    • @mangopie7602
      @mangopie7602 Před rokem

      @@tonypatino1765 how the fuck is someone not realizing that backslash is supposed to be a forward slash braindead???

    • @CrystalisedWorld
      @CrystalisedWorld Před rokem +1

      sadly did fall for one of these last month, and can tell you discord didnt give a shit xD

    • @peterestol800
      @peterestol800 Před rokem

      how do you even use a backslash

  • @yellowtapes
    @yellowtapes Před rokem +53

    "Just take a look at the URL and you will see a few odd things..."
    That HUGE danger sign looks convenient

  • @dummmonke4269
    @dummmonke4269 Před rokem +2665

    Also love how he doesn't mention the backslashes in the URL of the fake popup. But on a serious note, this dude is doing God's work 🙏

    • @baldability
      @baldability Před rokem +126

      Exactly, I can’t tell if he didn’t realize or just ignored it

    • @shadowimpostor1990
      @shadowimpostor1990 Před rokem +13

      same

    • @shadowimpostor1990
      @shadowimpostor1990 Před rokem +7

      same

    • @NoTextToSpeech
      @NoTextToSpeech  Před rokem +711

      @@baldability Honestly, didn't even realize. Too focused on narrating and uhh brain didnt work.

    • @MystiqueChevalier
      @MystiqueChevalier Před rokem +122

      @@NoTextToSpeech Didn't notice until the comments pointed out aswell. These scams are really dangerous

  • @ThatCarrotGuy
    @ThatCarrotGuy Před rokem +606

    Great job at describing how you can tell it's a fake pop-up, but you forgot one thing, a pop-up of the actual Discord website takes time to load, instead of this pop-up instantly appearing.

    • @NoTextToSpeech
      @NoTextToSpeech  Před rokem +177

      That's a good point. The animations were a bit off.
      Maybe in like 5 years we will all have insane internet speeds and there will be next to no delay opening the page. We can only dream lol.

    • @theairblow
      @theairblow Před rokem +58

      @@NoTextToSpeech it's not actually internet speed that matters.
      1) WM animations. The window appearing would be animated
      2) Any program, even on a very good computer, would take at least some milliseconds to load.
      ^ even with good internet, as it still requires for the browser to setup encryption and stuff.

    • @alexanderhurst1998
      @alexanderhurst1998 Před rokem +19

      It's important to note that even if that gives this scam away, it is not a silver bullet.
      It is very possible for websites to replicate the delay and window spawn animation. So just because that trick works here right now, does not mean it will work in a few days or on a different website doing the same trick.

    • @Theunicorn2012
      @Theunicorn2012 Před rokem +1

      Great job at describing how you can tell it's a fake pop-up, but you forgot one thing, a pop-up of the actual Discord website takes time to load, instead of this pop-up instantly

    • @unaincreibleroca3427
      @unaincreibleroca3427 Před rokem +2

      @@NoTextToSpeech me with my 50kbps speed

  • @zephyfoxy
    @zephyfoxy Před rokem +35

    Glad to see a honest to god legitimate explanation of a fairly sophisticated phish, instead of the usual fear mongering and outright lies usually spread on social media about Discord phishing. Need more of this!

    • @Theunicorn2012
      @Theunicorn2012 Před 11 měsíci +1

      Glad to see a honest to god legitimate explanation of fairly sophististicated phish, instead of the usual fear mongerig and outright lies usually spread on social media about Discord phishing. Need more of this!

  • @LeslieCosmik
    @LeslieCosmik Před rokem +64

    I love how this guy explains so good and doesnt use music that bleeds our ears

    • @KatieHuni
      @KatieHuni Před rokem +9

      Yeah the minecraft music in this video fitted so well to

    • @NotBest713
      @NotBest713 Před rokem

      who does?

    • @Unnamed922
      @Unnamed922 Před rokem

      You just have sensitive hearing. No one fucking doesn't. Get a life.

  • @SpeedstersUnited
    @SpeedstersUnited Před rokem +425

    Thank you, NTTS. Thank you for making us aware of the phishy (I'll see myself out) Discord scams.

    • @ChannelsRed
      @ChannelsRed Před rokem +9

      A reminder that this fake URL uses backslashes "\". It's supposed to be a forward slash "/".

    • @slippers365
      @slippers365 Před rokem +6

      @@ChannelsRed well if the scammer noticed it and change it to forward slash, if you don't pay attention, well, you know what will happen next... (I think u are smart enough to understand)

    • @alluseri
      @alluseri Před rokem +4

      I read "NTFS"

    • @vlaanx
      @vlaanx Před rokem +1

      Wait a sec, does that mean that I should change my Roblox password from kittenlover569 to something else before I click on the link to add the cute hot anime bot to my discord server?

    • @IAmGodHimself777
      @IAmGodHimself777 Před rokem

      @@vlaanx Aahaha of course not kittenlover569 is a great password haah

  • @charuseTV
    @charuseTV Před rokem +275

    One of the oldest Steam Account scams finally moves to discord, love to see it

    • @lelofahon
      @lelofahon Před rokem +1

      @War Room dont advertise
      its only gonna get you dislikes

    • @stanleybochenek1862
      @stanleybochenek1862 Před rokem +5

      @@lelofahon it's a bot anyway didn't youtube nerf the dislike button?

    • @terrawolf
      @terrawolf Před rokem +2

      yeah

    • @lelofahon
      @lelofahon Před rokem

      @@stanleybochenek1862 doesn't matter.he ain't getting fans that way

    • @tacokoneko
      @tacokoneko Před rokem

      i have a steam account with a lot of valuable DOTA 2 items and i have seen like 20+ of these pages for steam accounts from opening the links the bots send me. obviously i open them in virtual machine which makes it so difficult for any virus to escape that it is borderline impossible. it would require multiple zero days for each of the specific software i use

  • @maximats
    @maximats Před rokem +159

    You can also tell it’s a phishing attempt because the whole authorisation is made on the official discord website and not on a third-party-site.

  • @xipherzen
    @xipherzen Před rokem +7

    Not gonna lie, this would've caught me off guard. I was pretty lost until you pointed out the whole window not leaving the window bit and I went from "Wtf" to "OH SHIT YOU RIGHT!" moment. Thankyou for this!!

  • @IWickDev
    @IWickDev Před rokem +70

    Another way to tell if the Popup is real is to check your programs bar on the bottom of the screen in Windows. If it is a real popup you should see chrome or whatever browser you are using showing two windows, the main browser, then the popup. Or just look for the popup in general if you already have more than one browser window open.

    • @Dexzler
      @Dexzler Před rokem

      "Connection not secure"

  • @FairPlay137
    @FairPlay137 Před rokem +42

    As a web developer, I can say the explanation was pretty accurate here (and yeah "src" does refer to the source URL) - this particular tactic isn't limited to just Discord either; I believe other phishing scams have started to adopt the "fake browser window" strategy as well, so that's definitely something to watch out for.
    In addition, it seems the developer of the login page _might've_ goofed up the loading icon for the QR code login method.

    • @FairPlay137
      @FairPlay137 Před rokem +6

      @twinqle I...literally coded a Windows 10 error message generator in PHP, and I'm currently working on several projects for various groups (in both C# and Java). -_-
      And don't say I'm not a real developer either.

    • @FairPlay137
      @FairPlay137 Před rokem +6

      @twinqle I'd say you aren't a real developer either - only thing I've seen you do is Roblox game development (which i mean isn't bad, but). Of course, everyone has their own interpretation of who is and isn't a real developer, so if you really want to have your opinion shoved in my face, go ahead. I won't be replying anymore to this thread.

    • @iwant2tryhard337
      @iwant2tryhard337 Před rokem +12

      @@FairPlay137 He's probably just there to annoy you

    • @FairPlay137
      @FairPlay137 Před rokem +5

      @@iwant2tryhard337 Judging by that user’s comment history on this video I figured that was the case.

    • @rice8864
      @rice8864 Před rokem

      meh php is really outdated

  • @redtomik3852
    @redtomik3852 Před rokem +1

    Thank you so much! The part about dragging pop up outside of browser is super useful!

  • @astropgn
    @astropgn Před rokem +4

    Asides from not carrying about details, that scam was actually pretty clever. I couldn't see what was going on until you mentioned that it was a fake pop up window.

  • @notduomar
    @notduomar Před rokem +6

    Exactly when he said "so" ( 3:29 ) a wix ad popped up saying "question, would you build a website"

  • @Ommoo
    @Ommoo Před rokem +71

    I just noticed on the 'scam' discord login page, they somehow failed to spell "Mobile" correct on the QR code area lmao
    you'd think that given how accurate they wanted their scam to look they made a spelling error

  • @sneharghya7732
    @sneharghya7732 Před rokem +18

    This is actually a somewhat new phishing technique. Its called BiTB attack (Browser in the Browser attack) in cybersecurity terms. One can modify that embed depending on the target's browser and easily social engineer someone into thinking its legitimate, as it is very deceiving.

    • @dramurgy6120
      @dramurgy6120 Před rokem +1

      “new” have you ever seen steam scams

  • @SCOBBY123
    @SCOBBY123 Před rokem

    This man is the best youtuber ive seen and hes also so nice to inform us around these scams

  • @AryX2004
    @AryX2004 Před rokem +15

    This is so scary, because i always login on google and literally everyday
    Thanks for the info:))

  • @SpaceGuy101
    @SpaceGuy101 Před rokem +10

    Thanks ntts for informing and helping us all. As someone who is kinda tech savvy most of the videos are not useful to me but I still love watching them. However you did make me fall into the trap of having 20 Rainmeter skins.

  • @ProjSHiNKiROU
    @ProjSHiNKiROU Před rokem +4

    A subtle anti-phishing protection of password managers: The password manager will not autofill your Discord password on phishing websites. This lack of auto-fill can give users a few seconds to remind them which website they are ACTUALLY on.

  • @lxbilol
    @lxbilol Před rokem +16

    Also, one thing that I noticed that is also odd is that, where it says "Log in with QR Code" below that it says "Scan this with the Discord *MOBILY* app to log in instantly". In the original it goes "Scan this with the Discord *MOBILE* app to log in instantly". Its a grammar mistake that is bearly noticeable, but still can give off if the website is a scam or no.

  • @e1psych0
    @e1psych0 Před rokem +13

    I just love the way he talks and explains everything, what a chad

  • @ApolloSnip3s
    @ApolloSnip3s Před rokem +59

    Its absurd how many scams there are on discord and yet discord wont dont anything

    • @irian3x3
      @irian3x3 Před rokem +3

      *absurd

    • @kawaiikiwi.1820
      @kawaiikiwi.1820 Před rokem +6

      They actually did add some warnings for some suspicious sites to confirm you would like to go there, and they did add a warning with the QR code. So they have done a little bit.

    • @cumjesus
      @cumjesus Před rokem +5

      they're actually doing something about it
      its just that when a scammers thing gets taken down
      its easy to make another one

    • @ApolloSnip3s
      @ApolloSnip3s Před rokem +1

      @@irian3x3 shush, i dont care about spelling

    • @ilmunti_
      @ilmunti_ Před rokem

      they are, are u at a cave or smthn

  • @Pamven
    @Pamven Před rokem

    Thank you for reminding us to keep safe, NTTS :> That outro was adorable I had to do a double take

  • @swatishaw1351
    @swatishaw1351 Před rokem +1

    okay, as a guy who is actually into cybersecurity.. these are a couple of good peices of advice u wanna follow... like the simple explanation and the advice its just great

  • @therealshiv
    @therealshiv Před rokem +60

    you should try trolling scammers by spamming "@everyone" on as many username and password fields on pishing login sites

    • @drakewasaloverboy
      @drakewasaloverboy Před rokem +12

      @Moxxie yep they use a Webhook in a custom server.

    • @codyryan9789
      @codyryan9789 Před rokem

      nah just put

    • @roshanprabu
      @roshanprabu Před rokem +4

      if they have it on an embed, it's useless
      and even if it actually pings them, who cares about pings I mean come on

    • @UCmDBecUtbSafffpMEN3iscA
      @UCmDBecUtbSafffpMEN3iscA Před rokem

      They'll probably patch that method

    • @coolguyroblox2168
      @coolguyroblox2168 Před rokem

      You can find the webhook their using to send the usernames and passwords to their discord server if you check the websites source code, sometimes its hidden or it's in plain sight.

  • @rpe
    @rpe Před rokem +22

    THAT IS SO SMART!
    I’ve never thought of this.
    Using Iframes to simulate popups is gonna be so effective.

    • @ChannelsRed
      @ChannelsRed Před rokem +3

      Notice the backslash "\" on the fake URL. Websites uses "/".

    • @BOOHBAH
      @BOOHBAH Před rokem +4

      theyve been doing this a long time ago, for steam too

    • @linuxization4205
      @linuxization4205 Před rokem +1

      @@ChannelsRed That means nothing, some actual web browsers do that.

    • @XENON2028
      @XENON2028 Před rokem

      @@linuxization4205 browsers which are stupid do that

    • @linuxization4205
      @linuxization4205 Před rokem

      @@XENON2028 exactly how are they """""sTuPiD?""""

  • @krystal1119
    @krystal1119 Před rokem +8

    please do one about this!! It's so easy to be fooled....
    it's about a person sending server invites to people in dms while saying something along the lines of "check main chat" or "watch general", and when you do end up joining the server you have to verify with a qr code / go to a link and if you end up "verifying", your account is gone and used to do the same scam to fool your friends.
    2 of my friends fell for it.

  • @MitchySlic
    @MitchySlic Před rokem

    thx man, I sometimes get these scams, you are good when giving details.

  • @raylikespvz
    @raylikespvz Před rokem +11

    Hackers are getting desperate now

  • @costin88boss74
    @costin88boss74 Před rokem +37

    This is how I almost fell for a Steam scam too. thankfully I recovered all my accounts (as all accounts had the same pass) and no account (that I'm aware of) got hijacked.
    Edit: I did found out the window was a fake pop-up after putting the password. it was 11 PM anyway.

    • @ZeyReal
      @ZeyReal Před rokem +1

      I've seen those Steam Scams for like 3 years. Now they're coming to Discord.

    • @blocksource4192
      @blocksource4192 Před rokem

      @@ZeyReal they've come to everywhere

    • @void_bucket
      @void_bucket Před rokem +1

      gotta say, steam securityis airtight, saved my account from, well a scam ofcourse

    • @Nicanor2051
      @Nicanor2051 Před rokem

      I fell

    • @Mariocat99
      @Mariocat99 Před rokem

      Got to me last year, didnt lose my accounts fortunately

  • @xard64
    @xard64 Před rokem +2

    This is one of the rare occasions where using custom theming for browser counts as a security feature: no matter which browser or platform you are using this kind of attack will stick out like a sore thumb if you use a custom theme.

  • @BRLX0731
    @BRLX0731 Před rokem

    Thank you so much and you got 100K Subscribers CONGRATS!!!!

  • @Seilock
    @Seilock Před rokem +4

    Let's go we got the MC music

  • @yolomcswag0
    @yolomcswag0 Před rokem +8

    POV: you are a scammer that somehow uses only backslashes

  • @PiercedLight
    @PiercedLight Před rokem

    thank you for making this, now i know what to look for on weird "discord" links and stuff. etc etc

  • @fadedquill7
    @fadedquill7 Před rokem

    WOAHHH! These new scammed are getting TRICKY... so glad I watched this video, I'm sharing this with my friends!

  • @rodaguj5718
    @rodaguj5718 Před rokem +49

    5:59 instead of dragging outside of the popup window you can drag it to the url bar in your browser(Not the fake one), that way you don't have to leave full screen mode

  • @muajbinkarim
    @muajbinkarim Před rokem +142

    As a web developer I know sometimes can be dangerous.

    • @muajbinkarim
      @muajbinkarim Před rokem

      Yes

    • @boem231
      @boem231 Před rokem +6

      almost all websites with a login system (like CZcams and discord) have a setting enabled, that disables people from iframing their website

    • @undefinedchannel9916
      @undefinedchannel9916 Před rokem +4

      @@boem231 reread his comment. The loads another page on their server.

    • @undefinedchannel9916
      @undefinedchannel9916 Před rokem +6

      Iframes are not really dangerous if you know what you're doing

    • @boem231
      @boem231 Před rokem

      @@undefinedchannel9916 you're right, I edited my comment

  • @vailecia
    @vailecia Před rokem +6

    as a soon-to-be a web designer i would absolutely fall for this if i was in a rush

    • @swayzeg0t1t
      @swayzeg0t1t Před rokem

      what’s ur web gonna look like, will i see it in the upcoming spider-man movies?

    • @Dexzler
      @Dexzler Před rokem

      Making a social media is way easier than trying to become a celebrity

  • @cloxz2527
    @cloxz2527 Před rokem

    Thank you so much for informing about this lmao ima subscribe and like.

  • @feefre
    @feefre Před rokem +5

    Oh god, they finally realized what steam scammers has been doing for years, they finally learnt about the fake modal window

  • @jonaslovesharper
    @jonaslovesharper Před rokem +3

    Another note on the fake popup login page: It says "Discord Mobily App." Keep up the good work NTTS

  • @FatheredPuma81
    @FatheredPuma81 Před rokem +3

    Yea I saw this around about a year ago as a Steam phishing scam. Was pretty convincing too so I can see why the guy that sent it fell for it.
    Makes me sad when I see the normal crappy phishing scams now.

  • @astaspasta8406
    @astaspasta8406 Před rokem +3

    also a very good tip when logging in, is to go to the official website, log in, and then refresh the other login page. If its official, it will log you into your account (from the session you made from the official website)

  • @itsoutchy
    @itsoutchy Před rokem +3

    Also, make sure that the pop up window plays an animation when it gets opened. If it doesn’t then that’s already a huge red flag.

  • @sathvikreddy6138
    @sathvikreddy6138 Před rokem

    adv congrats on 100k u will hit it soon :) u really deserver it thanks for saving our accounts

  • @nottoo2818
    @nottoo2818 Před rokem

    this guy helps so much and explains everything perfectly, im surprised he only has 100k

  • @Torbikini
    @Torbikini Před rokem +42

    Use a theme on your browser that isn’t just dark/light. There’s no way a scammer can know your theme. :)

    • @JustJory
      @JustJory Před rokem +2

      im pretty sure that websites can see if your using dark or light theme on windows.

    • @epicmines33
      @epicmines33 Před rokem +9

      @@JustJory they are talking about browser themes not windows

    • @JustJory
      @JustJory Před rokem +1

      @@epicmines33 ohh my bad.

    • @qwertyuiop.lkjhgfdsa
      @qwertyuiop.lkjhgfdsa Před rokem

      kiwi browser doent have those

  • @Stridsvagn69420
    @Stridsvagn69420 Před rokem +3

    1:45 And it's even funnier when you use a Linux distro with a custom GTK theme (that's basically your system theme with colors, icons and even buttons), and it shows a window that doesn't match your theme or even is a fake window in the style of Windows 10.

  • @FirstLast-fl7mo
    @FirstLast-fl7mo Před rokem

    Good work, not as technical as I would like but I'm a huge nerd too. It's great that there's all this cyber-sec educational content these days.

    • @cozyrain410
      @cozyrain410 Před rokem

      bro chill, this is nothing too technical.

    • @star_light143
      @star_light143 Před rokem

      Nobody was being rude... it was just a statement

  • @iinstixnt6351
    @iinstixnt6351 Před rokem

    Beautiful man, you're the only one who could help me, I watched 8 videos and yours was the only one that saved me

  • @IAteYourCookiez
    @IAteYourCookiez Před rokem +3

    I was instantly suspicious of how fast it opened and that it didn’t actually open another chrome (since there is almost always a short loading time when opening a new tab)

  • @matthew001
    @matthew001 Před rokem +10

    Also, just something small; you are always asked to log in before you authorize a bot, there is no scenario where you click authorize and then log in.
    If you attempt to authorize a bot and you're not logged in, it will redirect you to the login page, not allow you to authorize it first.

  • @santiago94nn
    @santiago94nn Před rokem

    THANK YOU SO MUCH THIS WAS EXTREMELY HELPFUL :D

  • @Hex430
    @Hex430 Před rokem

    Didn't know this, thank you. Will look out for it.

  • @Oasherr
    @Oasherr Před rokem +6

    This is actually smart and scary at the same time. I could probably fall for this. Thank you

  • @coder436
    @coder436 Před rokem +3

    As a web developer, I can confirm src means source. 2:44

  • @elisfeatplayboicarti
    @elisfeatplayboicarti Před rokem

    bro literally had minecraft open we could hear the music on the background xD nice video keep it up

  • @FoeFear
    @FoeFear Před rokem

    Very informative, thanks for letting me know!

  • @DM-gj9ft
    @DM-gj9ft Před rokem +4

    Another way to know if the account authorization page (where you click on `Authorize`) is legit, is to check if the domain is *actually* discord, and not anything else.
    Unlike what 0:50 says, if an application wants to "access your account" make sure that it's the *discord* domain, and not *discordtrackers* , and not any other domain at all.

    • @EragonShadeslayer
      @EragonShadeslayer Před rokem +2

      The point of this video is that this circumvents that so if you only rely on that it's not going to end well for you.

    • @DM-gj9ft
      @DM-gj9ft Před rokem +2

      ​@@EragonShadeslayer My point was that the beginning of this video calls the "authorization" page (where you click on `Authorize`) that uses the discordtrackers domain legitimate, although the domain should be discord's official domain.

  • @nsa3967
    @nsa3967 Před rokem +3

    7:40 Actually I don't recommend using random characters. You should use something like Diceware, which is random words seperated with spaces. Much easier for a human to memorize and harder for a computer to crack.

  • @Nwonku
    @Nwonku Před rokem

    Thank you for informing me! I could’ve fell for this scam easily cause I am used to loggin my account when setting up a bot and I could’ve lost alot of money. I own a server and I’ll inform my members about this. Thanks!

  • @Versakyle
    @Versakyle Před rokem

    Excellent video. Clearly explained all the basics to get started on soft soft. Thanks

  • @MultiDarkZen
    @MultiDarkZen Před rokem +2

    discord should buy all the fake url links and make them redirect to the official website

    • @NoTextToSpeech
      @NoTextToSpeech  Před rokem +1

      There will be a ton of variations of spelling discord and it's simply a losing battle for Discord. Also it's expensive.

  • @kbhasi
    @kbhasi Před rokem +3

    I kinda wonder how the scam works in other Web browsers, at least if you use a user agent spoofer extension. I've a feeling the scammers are probably only spoofing Chrome as it's the most popular.
    Edit: answered at 4:16

  • @_koby
    @_koby Před rokem

    That is actually extremely smart on the scammers end lol

  • @Ghostenox
    @Ghostenox Před rokem

    Really usefull, thanks a lot and keep up the good work.

  • @mixica_
    @mixica_ Před rokem +12

    I sadly fell for this earlier, I was adding a bot I saw in a technoblade reddit server and tried adding it to my server, it asked for my account information which is weird since it never happened to me before but I logged in and it instantly disabled my account. I wish I had seen this sooner :/

  • @scrp1o
    @scrp1o Před rokem +3

    bruh, they make this insanely convincing scam website but mess up the forward slashes in the URL...

    • @XENON2028
      @XENON2028 Před rokem

      @@zerobytey its even easier just have an with the fake link, and make that fake link change what link is said in the browser (since browsers allow that for some stupid reason)

  • @fr3shy532
    @fr3shy532 Před rokem

    i love that you've put the most relaxing / best music on the world minecraft

  • @UltimatePota
    @UltimatePota Před rokem +1

    5:32 He has got a point. It wasn’t computers class, but I was using a website for information on my assessment. I could access it at home, but schools internet didn’t allow it. So I changed it to “The biggie cheez has blocked you.” Im just glad no one saw it.

  • @h2oant546
    @h2oant546 Před rokem +5

    Got my discord account hacked right when summer break happened. I felled into on of those fake discord add-ons in desperate for revenge for my friend leaking my public ip (yes, I was really that salty over my friend leaking my public ip despite it having no real consequences). Ended up getting a bunch of things in return for downloading it.
    1 - A unusable gaming pc
    2 - Discord account hacked and being used for nitro
    3 - Loosing almost 200 USD
    4 - PayPal account info getting stolen
    I was able to get my gaming pc usable again but the windows accounts were hacked and the passwords changed. And once I did actually fully stop it, my main windows account had the anti virus destroyed, left me feeling paranoid for 3/4ths of my summer, took over a week to get my stolen money back (from discord support), and more other things. I just factory reset my pc during the ending of summer break just to make sure the virus wasn't still roaming around on the computer. I am much more open minded and thinking before I do both online and offline (mostly online). Discord really needs to fix their security problem.

  • @SCRT
    @SCRT Před rokem +3

    7:17 how did you know my password

    • @Axinah.
      @Axinah. Před rokem

      Helo

    • @redditus
      @redditus Před rokem

      big ass shit (from my arse) not my ass.

  • @GATHUGHDxD
    @GATHUGHDxD Před rokem +1

    i've fallen for a steam scam like this once, first scam i fell for in like 10 years

  • @mohamedgaber7560
    @mohamedgaber7560 Před rokem

    Man, That Saved my Discord account. Thank you so much!

  • @WiktorIziWkizi
    @WiktorIziWkizi Před rokem +3

    hello! i have question. in link they used "\" not "/", cant they use / ? or they can

    • @kaitoarief
      @kaitoarief Před rokem +3

      they can, the scammer just less smart than you thought i guess

    • @jerrytu0916
      @jerrytu0916 Před rokem +2

      That's a pretty easy fix on the scammers' part, if they know what they're doing and they are not just copy/paste script kiddies

    • @NoTextToSpeech
      @NoTextToSpeech  Před rokem +1

      Well the scammer for this website is just an idiot. They can easily switch it to /

  • @JK-qk8rh
    @JK-qk8rh Před rokem +3

    I like how he did not point out to pay attentipon to the backslashes being incorrect and that normal URLs have forward slashes lol

  • @Fishion.
    @Fishion. Před rokem

    This is actually the first video on youtube I fell asleep from.

  • @thatsplayer
    @thatsplayer Před rokem

    Finally someone explain and recommend random letters and numbers passwords, like these are the best passwords to not get hack. Even if it hard to learn it you'll get there eventually, just try write your password many time. Anyway great video!

  • @tntiscool5730
    @tntiscool5730 Před rokem +4

    is it me or do i hear minecraft music at 4:21

  • @notfloyedd
    @notfloyedd Před rokem +3

    Lol Mobily, 3:35

  • @TheN3on
    @TheN3on Před rokem

    One of the best phishing scams I've seen so far

  • @brawlhallagod
    @brawlhallagod Před rokem

    Thanks you man for sharing this stuff.

  • @635_
    @635_ Před rokem +3

    one quick fix is to just block all popups, unless you actually care about popups...

    • @Emily_Bondevik_Official
      @Emily_Bondevik_Official Před rokem

      Can't do that on mobile

    • @ChexExists
      @ChexExists Před rokem

      @@Emily_Bondevik_Official than use commen sense on mobile and a blocker on pc

    • @leflo_
      @leflo_ Před rokem

      This is not a popup in this case, so this solution won't work

    • @Cautioned
      @Cautioned Před rokem

      this isn't a real popup so that won't work

    • @ctyn
      @ctyn Před rokem

      just check the link isnt had

  • @maciejkag2735
    @maciejkag2735 Před rokem +3

    1:02 anyone except for me noticed it says "...Discord mobily app..." below the QR code?

    • @cardero-tj5mt
      @cardero-tj5mt Před rokem +1

      I didn't notice and nice 🙈 you got dam eyes 😂

  • @azularrr
    @azularrr Před rokem

    THANK YOU SO MUCH! I WAS JUST ABOUT TO LOG INTO MY DISCORD. SO I DOUBLE CHECKED TO SEE IF IT WAS THE REAL SITE

  • @Koharuu.
    @Koharuu. Před rokem +1

    Thank you for the Nostalgia Musik 🎶

  • @HazzyDevil
    @HazzyDevil Před rokem

    Worth mentioning, even for those who look at the url bar, should look at those slashes. Normal url’s will use forward slash. However the fake pop up you showed was using backslash.

  • @TheTrueMichael
    @TheTrueMichael Před rokem +1

    I love how Volume Alpha is the background

  • @iluvpidgeons
    @iluvpidgeons Před měsícem

    yo thanks ntts, I just got the same exact scam but with steam and without for your video, I 100% would have fallen for that shit.

  • @tacticaltoad5258
    @tacticaltoad5258 Před rokem

    Thanks for the vid bro!

  • @Fr4nk4000
    @Fr4nk4000 Před rokem +2

    1:55 words cannot descirbe the facial expression I made when I realized that that's not a pop up when you tried to drag it out the broser tab

  • @Pixiuchu
    @Pixiuchu Před rokem

    A phishing scam I could have fallen for, hmmmm...... well, thanks for the info!

  • @themagic8ball
    @themagic8ball Před rokem

    i just love fact that in every video like this there must be something from Minecraft
    music/gameplay in backround etc

  • @TheAutoRecorder
    @TheAutoRecorder Před rokem

    It’s funny how, at first, I heard you say that the ‘/login’ part was for like PC, so I thought it was unused except for the embed. I visited the website on my tablet, got like a million reports, and then instead of popping something up, it just pulled up the website.

  • @avikerry
    @avikerry Před rokem

    thanks so much! embarrassed to say i would have totally fell for that, LOL