Radar · Emerging topics · 18+

Fake casino mirrors and phishing: how not to get caught

A real window and a fake clone window with a phishing hook, neon

Fake 'mirrors' and phishing copies are one of the most common threats a player faces. Scammers build a site that looks identical to the real casino, put it on a similar address and wait for a user to enter a login or make a deposit.

The scale is large: according to APWG, over 853,000 phishing attacks were recorded in the fourth quarter of 2025 alone. We'll look at how clones are built, how to recognise them and how to protect your account and money.

Key takeaways

  • A fake mirror is a clone site on a similar domain, made to intercept your login or deposit.
  • Two techniques: typosquatting (banking on a typo) and the homograph attack (swapping look-alike characters, e.g. a Latin letter for a Cyrillic one).
  • Signs: a typo in the domain, no HTTPS, a licence logo with no link to a register, 300–500% bonuses, and crypto-only payment.
  • Protection: use a bookmark to log in, check the licence on the regulator's site (UKGC/MGA), and enable 2FA (per CISA, about 99% less hacking risk).
  • Crypto transfers are irreversible; check the domain and licence before depositing. 18+.

Anatomy of the threat: clone, typo, character swap

Legitimately, a 'mirror' sometimes means an operator's backup domain — and scammers exploit that trust. A clone copies the design, the logos and the login form. The domain is chosen in one of two ways. Typosquatting banks on a typo during manual entry (an extra letter, a different TLD).

The homograph attack (IDN) swaps visually indistinguishable characters from another alphabet. Cyrillic is the main vector: about 11 letters are almost identical to Latin ones (а, с, е, о, р, х, у ≈ a, c, e, o, p, x, y). Examples: 'pаypal.com' with a Cyrillic 'а' (2005), 'adoḅe.com' carrying a trojan (2017). A browser may show such a domain as 'xn--…' (Punycode) — a sign of a swap.

How phishing arrives

A typical scenario: an email or message 'from support' — 'confirm your account via the link', 'your login is blocked' — with a link to a fake login form. The login and password you enter go straight to the attackers.

A distinct form of pressure is the demand to deposit specifically in cryptocurrency: as the FTC reminds us, 'only scammers insist on payment in cryptocurrency', because the transfer is irreversible and has none of the protection a card offers.

Signs of a fake

No single sign is a verdict on its own, but a combination of them is a signal to close the tab:

SignHow to check / why it's dangerous
Typo domain, an extra word, look-alike charactersCheck the address letter by letter; 'xn--…' is a sign of a swap
No HTTPS or a browser warningThe connection is unprotected — data can be intercepted
A licence logo with no link to a registerA licence is verified in the regulator's register, not by an image
300–500% bonuses with shifting termsBait; hidden, impossible withdrawal conditions
They demand crypto-only paymentTransfers are irreversible — almost impossible to recover
Text errors, someone else's rules in the T&CCopied terms give the clone away
An anonymous owner, offshore contact onlyNo traceable owner
A brand-new domain (under 6 months old)Scam domains are often registered for a year and abandoned
How to tell a fake mirror apart: real vs fake domain, the signs
Radar diagram: the anatomy of a fake domain (a look-alike letter) and the signs of a fake.

How to verify legitimacy

  1. Visit the site only via your own verified bookmark, not via links from emails, DMs or ads.
  2. Check the address character by character; 'xn--…' in the address is a sign of an IDN swap.
  3. Check the licence on the regulator's site: UKGC — the Public Register (the licence details, including the site's domain, must match); MGA — the Licensee Register (the MGA publishes warnings about impersonator sites).
  4. Confirm HTTPS and, if in doubt, check the domain's age.
  5. Contact support only through official channels from the verified domain.

How to protect your account

  1. Enable 2FA — according to CISA, it cuts the chance of a hack by about 99%.
  2. Prefer an authenticator app (TOTP) over SMS: NIST notes that SMS is vulnerable to interception and SIM swapping.
  3. Use a unique, long password (a passphrase is better) and a password manager; NIST endorses them.
  4. Never share your seed phrase or private keys with anyone — genuine support never asks for them.
  5. Don't keep large amounts of cryptocurrency on a gaming site.

If you've already been caught, and the key point

Act fast: change your password on the real site and on the linked email, log out of all sessions, and enable 2FA. If you entered card details, contact your bank straight away. Crypto transfers are harder: the network is irreversible and recovery is almost impossible. Report a suspicious site to the regulator (the UKGC/MGA maintain warning lists) and to site-checking services.

Clones and phishing exploit carelessness and haste. Two habits cover most of the risk: log in only via your own bookmark, and verify anything 'urgent' through official channels. A site's safety is determined by its licence and reputation, not by a copy of its design.

Enter Jetton Casino →

This material is for information only and is not legal advice. Gambling is 18+, involves the risk of losing your funds and is not a way to earn money. A site's safety is determined by its licence and reputation, not by a copy of its design; check the domain and licence and play responsibly.

More on Radar

Frequently asked questions

What is a fake casino mirror?

A clone site that copies the design and address of a real casino on a similar domain to steal your login or deposit.

What is a homograph attack?

Swapping look-alike characters in a domain (for example, a Latin letter for a Cyrillic one); a browser may show such an address as 'xn--…'.

How do you tell a fake site from a real one?

Check the domain letter by letter and the HTTPS, and the licence in the regulator's register; be wary of unrealistic bonuses and demands to pay in crypto.

How do you protect a casino account?

Enable 2FA (per CISA, about 99% less hacking risk), use a unique password and a password manager, and log in via a bookmark.

Can you recover money sent to a fake site?

With crypto it's almost impossible (transfers are irreversible); if you paid by card, contact your bank immediately.

Sources