"Possible phishing detected on user login": Chrome's password reuse warning

Google describes this issue as pages on your site that are "suspected of containing phishing," where "a pop-up password reuse warning was triggered when a user attempted to login." In other words, someone typed a password they have saved for another site into a form on your page, and Safe Browsing judged the page suspicious enough to warn them.

Attackers do this by building pages that look like official logins so people reuse their real passwords. On a WordPress site that is either a hacked site hosting a fake login for some other service, or a login form of your own that looks too much like someone else's. Hydrogen SEO is not a security plugin and does not scan login pages; this is work for you, your host or a security service.

Three ways a WordPress site ends up here

A planted phishing page. The most common case: an attacker uploads a copy of an email, bank or cloud storage login into a folder on your site, then emails the link to victims. People enter their real password, the warning fires, and your domain is recorded. These kits often live in wp-content/uploads/, a folder named after the brand being copied, or a fake plugin directory.

A cloned version of your own login. A lookalike of wp-login.php or your WooCommerce account page placed somewhere else on the site to harvest your customers' credentials.

A legitimate login that resembles another brand. A membership login styled like a big provider's page, or a hand-built "Sign in with" screen that copies a provider's logo and layout. Users reuse that provider's password, and the page looks like phishing even though you meant none.

Tracking down the page

Start with the example URLs. Google suggests URL Inspection to see them in mobile and desktop views. For a planted kit, look for folders containing their own index.php or index.html and a form posting somewhere unexpected:

bash
# HTML or PHP files under uploads (neither belongs there)
find wp-content/uploads -type f \( -name '*.php' -o -name '*.html' -o -name '*.htm' \) | head -40
# Forms whose action points off-site
grep -rlE '<form[^>]+action="https?://' --include='*.php' --include='*.html' . | grep -v -E 'wp-admin|wp-includes' | head
# Recently created directories
find . -type d -mtime -30 -not -path './wp-content/cache*' | head -40

Phishing kits often include a script that emails captured passwords to the attacker or posts them to a remote server, so any file sending form data off-site deserves a close look.

Cleaning up, or redesigning your login

For a planted kit, delete the whole folder, then clean the site properly, because someone had write access. Change all passwords, reinstall core, plugins and themes from clean sources, remove unknown administrators, rotate salts, update, and find the entry point; Hacked: Malware has the full order. Google's help for this issue also points hacked site owners to its hacked sites guide.

For your own login pages:

  • Keep logins on your own domain and brand, over HTTPS.
  • Use identity providers' official sign-in buttons and flows, rather than copying their look.
  • Do not ask for credentials from another service on your pages, such as an email account password to "verify" a user.
  • If your users are likely to reuse passwords, prompt for two-factor authentication.

If you are sure the page is legitimate and nothing looks like another brand, Google provides a way to report a Safe Browsing error.

Requesting review and protecting users

Once the page is removed or redesigned, select Request Review in the Security issues report:

text
A phishing kit imitating a webmail login was uploaded to
/wp-content/uploads/2024/02/mail/ via a compromised editor account.
We deleted the kit, removed the account, reset all passwords, enforced
two-factor login for editors, and reinstalled plugins and theme.

Google puts security reviews at a few days to a few weeks. Separately from the review, think about the people affected. If the fake page copied your own login, anyone who entered details there should change their password; tell your users plainly what happened. Depending on where you and your users are, a credential leak can carry legal notification duties, so check with whoever handles privacy for your business.

Common questions

What is the password reuse warning?

Chrome can warn users when they enter a saved password on a page that Safe Browsing suspects of phishing. Google reports this in the Security issues report as possible phishing detected on user login.

My login page is real. Why was it flagged?

Pages that resemble a well-known provider's login, or ask for another service's password, can look like phishing. Keep your own branding, use official sign-in buttons, and report an error to Safe Browsing if you are sure the page is legitimate.

Where do phishing kits usually hide on WordPress?

Often in folders inside wp-content/uploads or directories named after the brand being copied, each with its own index file and a form that sends data off-site.