Phishing and Clone Sites Using "Bonus" Bait

·

Phishing and Clone Sites Using "Bonus" Bait

How clone sites imitate the brand

Imitation is cheap and it always has been. Everything a visitor uses to recognise a brand is published on the open web, so visual resemblance carries no information about who is behind a page.

Copied layouts and logos

A page can be reproduced closely with no special access. Logos, brand colours, typefaces, product screenshots and even entire page structures are delivered to every visitor by design, which means they can be saved and re-served from anywhere. A convincing copy is a matter of an afternoon, not of skill.

The consequence is worth stating in one line: appearance is not identity. A layout you recognise tells you what the publisher chose to imitate, not who the publisher is. This matters because recognition happens fast and below conscious attention, so a familiar interface quiets suspicion before any of the text has been read.

Small imperfections are sometimes visible, such as dated screenshots, mixed languages, features that lead nowhere, or a support section that is a single form. They are useful when you notice them, but their absence means nothing, because a careful copy has none of them. Do not build a habit on spotting flaws in the copy.

Look-alike domain names

The address is the part the operator cannot take from the brand, so it gets approximated instead. Common approaches include a letter doubled or dropped, two letters swapped, a hyphen inserted, an extra word appended, characters that resemble others at a glance, the brand placed as a subdomain of an unrelated domain, or the brand used only as a path segment.

All of these rely on the same reading habit. People scan an address for a familiar word and stop when they find it, and on a phone the bar is short and often partly hidden while scrolling. The reliable alternative is to look only at the registrable domain, meaning the part immediately before the top-level suffix, which for this broker is iqoption.com. Everything to the left of it is controlled by whoever owns the domain and can say anything at all.

Fake bonus landing pages

The bonus page is the entry point rather than the destination. It exists to give a reason for the visit, and it is usually the most polished page in the whole operation, because it is the one that has to survive first contact. The offer on it will be generous, round and time-limited, since that combination performs best.

What follows the landing page is the actual mechanism: a sign-in form to "claim" the offer, a verification step that asks for documents, or a payment step described as activation. The landing page itself takes nothing, which is what makes it feel harmless to open. It is worth knowing that the offer it advertises contradicts the rulebook anyway, since CySEC's national measures prohibit a CFD provider from providing a retail client with a payment, monetary or excluded non-monetary benefit in relation to the marketing, distribution or sale of a CFD. The general pattern of fabricated code offers is set out in how fake promo code bait works.

Layouts, logos and certificates are all reproducible, so nothing visual identifies a site; only the registrable domain does.

What phishing pages are after

Clone pages want three things, and knowing which one a page is reaching for tells you how urgent your response needs to be. All three arrive dressed as a routine step.

Login credentials and passwords

The most common target is the sign-in itself. The page presents a familiar form, captures whatever is typed, and often shows an error or forwards you to the real site afterwards, so the experience feels like a mistyped password rather than anything unusual. That quiet ending is deliberate.

Two consequences follow. The first is direct: someone holds the credentials for an account that may contain funds. The second is broader, because a password reused elsewhere turns one exposure into several, and email accounts are the usual next target since they can reset everything else. Some pages also ask for a one-time code straight after the password, presented as a verification step; a one-time code exists to prove that the person holding it is you, so handing it over completes the impersonation.

Payment and card details

The second target is payment data, usually collected as a deposit step or an activation fee for the promised bonus. Sometimes it is framed as a small verification charge, which is persuasive because a small amount feels low-risk and the detail being surrendered is the card itself rather than the amount.

The structural check is easier than judging the page. A genuine deposit happens inside the platform cashier while you are signed in, and the methods available to your account depend on your country and are shown there. A payment collected on a landing page, sent to a wallet address, or routed to a personal account is outside that path entirely, and transfers of that kind are often not reversible.

Identity documents

The third target is documents: a passport or identity card image, a selfie holding a document, a utility bill, a bank statement. These are requested under the cover of verification, which is plausible because regulated firms do carry out identity checks.

The difference is where the check happens. A real verification step takes place inside your account on the broker's own site after you have signed in there, not on a page you reached from an advertisement or a message. Documents are also the hardest kind of exposure to undo, since a password can be changed in a minute and an identity document cannot. Treat any document request from a site you did not reach by typing the address as disqualifying.

Phishing pages reach for credentials, card details or identity documents; documents are the hardest exposure to reverse, so treat document requests most seriously.

Common lures they deploy

Lures are chosen because they explain why you are being asked for something. Each of the three below supplies a reason that feels ordinary, which is the whole of their design.

"Claim your bonus" prompts

The claim prompt is the most direct lure. A banner, message or advertisement says a bonus is waiting and a button collects it, and clicking leads to a sign-in form. The framing turns the sign-in from a request into a formality, because you are not being asked for anything, you are collecting something owed to you.

The reason this lure travels so well is that people are already searching for it. Bonus and promo-code demand outlived the offers themselves, so a page promising one meets an expectation rather than creating it. The honest position is narrow and easy to hold: no publicly verifiable official promo code could be found during research checked on 3 September 2026, EEA retail clients of the CySEC-regulated entity cannot be offered a monetary inducement, and whatever is live inside an individual account depends on entity, country and date.

Fake account-verification steps

The second lure inverts the emotional register. Instead of a reward, there is a problem: your account needs verification, a security check failed, a withdrawal is on hold, documents are missing, activity was detected. Urgency plus fear produces faster compliance than urgency plus reward, which is why this variant is common where a real account is known to exist.

The response is the same in every case and does not require you to judge the message. Do not use the link. Reach the platform by typing the address yourself or opening the official application, sign in, and look. A genuine account issue is visible inside the account, and a message that has no counterpart there was not from the broker.

Promised deposit-match rewards

The third lure asks for a payment before the reward. A deposit will be matched, a first payment doubled, a small activation charge will release a credit. This one collects money directly rather than only credentials, which makes it the most immediately expensive.

It also contradicts the rule it is invoking. ESMA's technical question-and-answer material describes the prohibition as covering "any form of monetary and non-monetary benefits that aim at incentivising retail investors to trade CFDs or to trade larger volumes of CFDs", naming account-opening bonuses inside that scope, and CySEC made the national measures permanent in Policy Statement PS-04-2019 on 27 September 2019. A deposit match offered to an EEA retail client of the regulated entity is not a promotion you have found early; it is a description of something that may not be provided. Why the regulated model works this way is covered in why there is no deposit bonus.

  • Reward framing: a bonus is waiting, sign in to collect it.
  • Fear framing: your account or a withdrawal is blocked until you act.
  • Payment framing: pay a small amount now to release a larger credit.
  • Authority framing: a message that appears to come from support or compliance.

Reward, fear and payment framings all supply a reason for the request; in every case the answer is to leave the message and check inside your own account.

Confirming the genuine platform

Confirming you are on the real platform is a two-second habit rather than an investigation. Three checks cover it, and the first one does most of the work on its own.

Typing the address directly

The strongest single habit is to arrive under your own steam. Type iqoption.com into the bar yourself, or use a bookmark you created while you were already on the correct site. This removes the entire class of attacks that depend on controlling the link you followed, and it works whether the link came from an advertisement, an email, a chat message, a comment or a search result.

It is worth being deliberate about search results as well. Advertisement slots above organic results are purchased, and a look-alike domain can appear there, so a habit of clicking the first result is weaker than a habit of typing the address. Once you are on the correct site, bookmark it and use the bookmark from then on.

Checking the certificate details

The second check is the padlock, used with its limits understood. Open the certificate information and confirm that the name it covers matches the domain in the bar. A warning, an expiry or a name mismatch is a stop, and it should never be clicked through on a page connected to money.

The limit matters as much as the check. A valid certificate proves that the connection is encrypted and matches the domain you are on. It proves nothing about who owns that domain, and certificates are freely available, so a clone will have one. Read the certificate as confirmation that you are talking privately to the domain in the bar; whether that domain is right is the earlier question.

Using official app-store listings

On a phone the address bar is the weakest part of the interface, so the application is the safer route. Install it from the official app-store listing, check the publisher name on the listing rather than the icon, and use that installed application for signing in rather than links that arrive in messages.

Two things to refuse. An installer file sent through a chat or downloaded from a web page has no distribution guarantees at all, and a "modified" or "bonus" build offering features the real platform does not have is describing itself accurately. Sticking to the official listing and the official platform covers both.

SignalWhat it actually proves
Familiar logo and layoutNothing. All of it is public and reproducible.
Padlock in the address barThe connection is encrypted and matches the domain shown, nothing about ownership.
Registrable domain typed by youYou are on the site you intended to reach.
Advertisement position in search resultsNothing. The slot is purchased.
Official app-store listing with the publisher nameThe application was distributed through a controlled channel.

Type the address or use the official app listing, then check that the certificate matches the domain; nothing about the page appearance adds to that.

Protecting your account and funds

Account hygiene matters more than vigilance, because habits keep working on days when attention does not. Four measures cover almost everything a clone operation could attempt.

Enabling strong authentication

Turn on the strongest sign-in protection the platform offers and treat the second factor as private in the same way as the password. This reduces the value of a captured password, since the credential alone stops being enough.

The habit that has to accompany it is refusing to pass a one-time code to anyone, in any circumstances, including someone presenting themselves as support. Codes are also requested by phone and in chat, framed as confirming your identity, and that framing is exactly backwards: the code proves identity to the platform, so giving it away transfers your identity to whoever asked. An authenticator application is generally preferable to codes sent by message, since it removes interception of the message itself.

Never reusing passwords

A unique password for the trading account and for the email address behind it is the measure that limits blast radius. Reuse is what converts a single exposure into access across several services, and it is the reason a leak on an unrelated site can reach a trading account months later.

A password manager makes this practical rather than aspirational, and it has a second benefit worth knowing: it fills credentials by matching the domain, so it will decline to fill on a look-alike address. That silence is itself a warning, and it is one you get for free without having to inspect anything.

Watching for unusual redirects

The last habit is noticing movement. A page that bounces through several addresses before settling, a sign-in that lands somewhere different from where it started, a link that opens an unexpected domain, or a form that appears in a pop-up window separate from the page beneath it are all worth stopping for.

Check the bar after any redirect rather than before, since the destination is what matters and shorteners hide it until arrival. If anything is unfamiliar, close the tab, reach the platform by typing the address, and see whether the situation the page described exists inside your account. It usually will not.

  • Enable the strongest authentication offered and never share a one-time code.
  • Use a unique password for the trading account and its email address.
  • Reach the platform by typing the address or through the official application.
  • Check the address bar again after any redirect, not before.
  • Report impersonation to the broker's official support channel and keep the details.

If the original attraction was a bonus, the honest alternative needs none of this risk: the free demo account carries $10,000 in virtual funds, is available immediately after registration with no deposit and no verification at that step, and can be recharged for free. This page reflects official CySEC, ESMA and IQ Option sources checked on 3 September 2026, and you should confirm anything that matters to you on the broker's own site before you deposit. The wider checklist for judging offers is in how to spot a fake bonus offer.

Strong authentication, unique passwords, arriving by typed address and checking the bar after redirects remove most of what a clone operation relies on.

Frequently asked questions

How can I tell a clone site from the real platform?

By the address, and only by the address. Logos, colours, layouts and screenshots are public and reproducible, so a copy can look identical, and a valid security certificate can be obtained for any domain, including a look-alike one. Read the registrable domain, meaning the part immediately before the top-level suffix, and ignore anything to the left of it, since that portion is controlled by whoever owns the domain. The reliable version of this check is not reading the address at all but typing it yourself, or using a bookmark you created while already on the correct site.

A page offered an IQ Option bonus and asked me to log in. Is that legitimate?

Treat it as not legitimate and leave. Signing in on a page you reached from an advertisement, message or comment is the exact step these operations are built to obtain, and the bonus prompt is the reason supplied for taking it. The claim also runs against the rulebook: CySEC's national measures prohibit providing a retail client with a payment, monetary or excluded non-monetary benefit in relation to the marketing, distribution or sale of a CFD, so a deposit bonus offered to an EEA retail client of the regulated entity is not something you have found early. If you want to know what is live for your account, reach the platform by typing the address and look at the Promo section once signed in.

Does a padlock icon mean a site is genuine?

No. The padlock means the connection is encrypted and that it matches the domain currently shown in the bar. It says nothing about who owns that domain or whether the content is honest, and certificates are freely available to anyone. The order of checks is what makes it useful: confirm the registrable domain is the broker's own first, then confirm the certificate matches it. A padlock on a look-alike domain is a private conversation with the wrong party.

I uploaded identity documents to a site that turned out to be fake. What should I do?

Act on the assumption that the material cannot be recalled, because it cannot. Report the incident to the broker through its official support channel so the account can be flagged, and report the page to the platform where you found it. Change the password on the real platform after reaching it by typing the address yourself, enable strong authentication, and change that password anywhere it was reused. Where your country provides a fraud or cybercrime reporting route, use it, and stay alert to later contact that references details from those documents, since that is how the material is typically reused.

Are mobile users more exposed to clone sites?

The address bar is harder to read on a phone, which is where most of the difference comes from: it is short, often truncated, and frequently hidden while scrolling, so a long look-alike address can present only its familiar-looking left-hand portion. Links also arrive more often through messaging on a phone, where checking is less convenient. The practical answer is to use the official application installed from an official app-store listing and to sign in through that rather than through links, checking the publisher name on the listing rather than trusting the icon.