You click a giveaway link, land on a slick page, and it says: "Sign in with your Instagram to enter." A familiar login box appears โ€” logo, colors, the works. You type your password. Nothing "wins," but the scammer just did: they now own your account. Credential-phishing giveaways are one of the fastest-growing scam types because they don't need to fake a prize, only a login. Here's how the trap works and how to walk past it.

Real giveaways never ask you to type a platform password

Here's the rule that ends most of these scams in one move: a legitimate giveaway is entered on the platform where it lives. You enter an Instagram giveaway inside Instagram โ€” where you're already logged in โ€” by liking, following, and tagging. You enter an email giveaway by submitting your email on the brand's own site. At no point does a third-party page need your Facebook, Google, or TikTok password to "verify" you or "confirm you're real." If a page that isn't the platform itself asks you to type that password, it is harvesting it. Full stop.

Scammers lean on urgency to short-circuit that instinct โ€” "log in within 10 minutes to claim," a fake countdown timer, "3 spots left." Slow down and read the address bar. The login box may look perfect, but the URL will be something like insta-rewards-claim.com or a random string, not instagram.com. A password box on any domain other than the real platform's is the single clearest red flag in the entire giveaway world, and it costs you nothing to notice it.

Know what genuine "social login" actually looks like

Real "Sign in with Google/Facebook/Apple" uses OAuth, and it behaves in a specific, checkable way. When you tap it, your browser opens the platform's own domain โ€” accounts.google.com, facebook.com, appleid.apple.com โ€” often in a separate popup window. You'll frequently already be logged in, so you never even retype a password; you just see a consent screen listing exactly what the app wants (usually "name, email address"). You approve, and it hands the site a token, never your password. The site never sees your credentials at all โ€” that's the entire point of the design.

A fake mimics the look but not the plumbing. Watch for the tells: the "Google login" opens inside the same page instead of a real browser popup, the URL stays on the scam domain, it asks for your password when you were already signed in elsewhere, or the consent screen requests scary permissions like "manage your account" or "post on your behalf." One strong defense is turning on two-factor authentication (2FA) on every social account โ€” even if a password leaks, the attacker still can't get in without your second code. A password manager helps too: it won't auto-fill your real credentials on a look-alike domain, and that silence is a warning worth heeding.

If you already typed it in, move fast

Assume the password is compromised the instant you realize the page was fake, and act like it. Change that password immediately on the real platform โ€” and if you reused it anywhere else (email, banking, shopping), change it there too, because attackers run stolen passwords against dozens of sites automatically. This is exactly why password reuse turns one bad click into a chain reaction; a unique password per site contains the damage to a single account.

Then turn on 2FA if it wasn't already, review your account's "active sessions" or "logged-in devices" and kick out anything you don't recognize, and check whether any connected apps were authorized without your knowledge. In the US, you can report the phishing page to the FTC at reportfraud.ftc.gov and forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org. Warn friends too โ€” these pages spread by posting "I just won!" from hijacked accounts.

No real giveaway ever needs your platform password on another website โ€” if a page asks for it, close the tab. ๐Ÿ”