AGN LMS
Learning Management System

← Discord account security and phishing

What actually happened

Almost every Discord compromise follows the same three moves.

1. A message arrives from somebody you trust. Usually a friend whose account was taken first. That is the whole trick: you are not judging a stranger, you are reading a name you know.

2. It gives you a reason to hurry. Free Nitro that expires. A report against your account. A server that needs a vote in the next hour. Urgency is not a side detail of these attacks, it is the mechanism - it stops you doing the one thing that would save you, which is looking properly at the address bar.

3. It asks you to log in, or to run something. The login page is a copy. It may be a very good copy. What it does with your password is send it somewhere else.

A newer version skips the password entirely and shows you a QR code, asking you to scan it with your phone's Discord app to 'verify'. Scanning it hands over a live session. Two-factor authentication does not stop that one, because you did the authenticating for them.

The important thing to take from this: you were targeted by something designed to work, and it worked the way it was designed to. The rest of this course is about the handful of signals that give these away, which are the same signals almost every time.