Kinda related—I once saw a honeypot trap that mirrored a real banking site.
Dude logged in with his *actual* credentials because he thought he was "testing" a bug.
The admins just laughed and sent him a screenshot of his own login attempt.
Moral: Never trust a URL you didn’t type yourself.
Dude logged in with his *actual* credentials because he thought he was "testing" a bug.
The admins just laughed and sent him a screenshot of his own login attempt.
Moral: Never trust a URL you didn’t type yourself.
