Fake 'mirrors' and phishing copies are one of the most common threats a player faces. Scammers build a site that looks identical to the real casino, put it on a similar address and wait for a user to enter a login or make a deposit.
The scale is large: according to APWG, over 853,000 phishing attacks were recorded in the fourth quarter of 2025 alone. We'll look at how clones are built, how to recognise them and how to protect your account and money.
Key takeaways
- A fake mirror is a clone site on a similar domain, made to intercept your login or deposit.
- Two techniques: typosquatting (banking on a typo) and the homograph attack (swapping look-alike characters, e.g. a Latin letter for a Cyrillic one).
- Signs: a typo in the domain, no HTTPS, a licence logo with no link to a register, 300–500% bonuses, and crypto-only payment.
- Protection: use a bookmark to log in, check the licence on the regulator's site (UKGC/MGA), and enable 2FA (per CISA, about 99% less hacking risk).
- Crypto transfers are irreversible; check the domain and licence before depositing. 18+.
Anatomy of the threat: clone, typo, character swap
Legitimately, a 'mirror' sometimes means an operator's backup domain — and scammers exploit that trust. A clone copies the design, the logos and the login form. The domain is chosen in one of two ways. Typosquatting banks on a typo during manual entry (an extra letter, a different TLD).
The homograph attack (IDN) swaps visually indistinguishable characters from another alphabet. Cyrillic is the main vector: about 11 letters are almost identical to Latin ones (а, с, е, о, р, х, у ≈ a, c, e, o, p, x, y). Examples: 'pаypal.com' with a Cyrillic 'а' (2005), 'adoḅe.com' carrying a trojan (2017). A browser may show such a domain as 'xn--…' (Punycode) — a sign of a swap.
How phishing arrives
A typical scenario: an email or message 'from support' — 'confirm your account via the link', 'your login is blocked' — with a link to a fake login form. The login and password you enter go straight to the attackers.
A distinct form of pressure is the demand to deposit specifically in cryptocurrency: as the FTC reminds us, 'only scammers insist on payment in cryptocurrency', because the transfer is irreversible and has none of the protection a card offers.
Signs of a fake
No single sign is a verdict on its own, but a combination of them is a signal to close the tab:
| Sign | How to check / why it's dangerous |
|---|---|
| Typo domain, an extra word, look-alike characters | Check the address letter by letter; 'xn--…' is a sign of a swap |
| No HTTPS or a browser warning | The connection is unprotected — data can be intercepted |
| A licence logo with no link to a register | A licence is verified in the regulator's register, not by an image |
| 300–500% bonuses with shifting terms | Bait; hidden, impossible withdrawal conditions |
| They demand crypto-only payment | Transfers are irreversible — almost impossible to recover |
| Text errors, someone else's rules in the T&C | Copied terms give the clone away |
| An anonymous owner, offshore contact only | No traceable owner |
| A brand-new domain (under 6 months old) | Scam domains are often registered for a year and abandoned |

How to verify legitimacy
- Visit the site only via your own verified bookmark, not via links from emails, DMs or ads.
- Check the address character by character; 'xn--…' in the address is a sign of an IDN swap.
- Check the licence on the regulator's site: UKGC — the Public Register (the licence details, including the site's domain, must match); MGA — the Licensee Register (the MGA publishes warnings about impersonator sites).
- Confirm HTTPS and, if in doubt, check the domain's age.
- Contact support only through official channels from the verified domain.
How to protect your account
- Enable 2FA — according to CISA, it cuts the chance of a hack by about 99%.
- Prefer an authenticator app (TOTP) over SMS: NIST notes that SMS is vulnerable to interception and SIM swapping.
- Use a unique, long password (a passphrase is better) and a password manager; NIST endorses them.
- Never share your seed phrase or private keys with anyone — genuine support never asks for them.
- Don't keep large amounts of cryptocurrency on a gaming site.
If you've already been caught, and the key point
Act fast: change your password on the real site and on the linked email, log out of all sessions, and enable 2FA. If you entered card details, contact your bank straight away. Crypto transfers are harder: the network is irreversible and recovery is almost impossible. Report a suspicious site to the regulator (the UKGC/MGA maintain warning lists) and to site-checking services.
Clones and phishing exploit carelessness and haste. Two habits cover most of the risk: log in only via your own bookmark, and verify anything 'urgent' through official channels. A site's safety is determined by its licence and reputation, not by a copy of its design.
This material is for information only and is not legal advice. Gambling is 18+, involves the risk of losing your funds and is not a way to earn money. A site's safety is determined by its licence and reputation, not by a copy of its design; check the domain and licence and play responsibly.
More on Radar
Frequently asked questions
What is a fake casino mirror?
A clone site that copies the design and address of a real casino on a similar domain to steal your login or deposit.
What is a homograph attack?
Swapping look-alike characters in a domain (for example, a Latin letter for a Cyrillic one); a browser may show such an address as 'xn--…'.
How do you tell a fake site from a real one?
Check the domain letter by letter and the HTTPS, and the licence in the regulator's register; be wary of unrealistic bonuses and demands to pay in crypto.
How do you protect a casino account?
Enable 2FA (per CISA, about 99% less hacking risk), use a unique password and a password manager, and log in via a bookmark.
Can you recover money sent to a fake site?
With crypto it's almost impossible (transfers are irreversible); if you paid by card, contact your bank immediately.
Sources
- MGA — notice on impersonator sites + Licensee Register — www.mga.org.mt
- UKGC — Public Register (licence and domain check) — www.gamblingcommission.gov.uk
- APWG — Phishing Activity Trends Report Q4 2025 — docs.apwg.org
- Wikipedia — IDN homograph attack (examples, Punycode) — en.wikipedia.org
- CISA — More than a Password (2FA cuts risk by ~99%) — www.cisa.gov
- NIST SP 800-63B (overview) — SMS risk, password managers — netwrix.com
- FTC — paying in crypto and where to report — consumer.ftc.gov
