Recognising impersonation
How phishing clones, fake mirrors and lookalike identities work, and the habits that defeat them.
Updated
Impersonation works on the hidden web for a structural reason: addresses are long, unmemorable and impossible to sanity-check by eye, so people rely on whichever list or link they happened to find. Whoever controls that list controls where they land.
The common forms
- Phishing clones — a pixel-for-pixel copy of a login or front page at a different address, built to capture credentials or payments.
- Fake mirrors — pages that present themselves as an “official mirror” the real operator never announced.
- Fake profiles — accounts on other platforms claiming to speak for a service or its staff.
- Lookalike identities — a new service that adopts the name of a well-known one, often after the original was seized or closed.
- Identity conflicts — two or more parties each claiming to be the legitimate continuation of something.
Habits that help
- Treat “it loads” as meaning nothing. Availability is not authenticity.
- Take an address from the operator's own verified channel — for a newsroom or a software project, its established clearnet site — and treat any list, including this one, as a pointer to check against that.
- Compare the whole address, not the first few characters. Clones are generated to match the beginning.
- Be most suspicious of anything using the name of a service that has been seized or closed. A revived brand is the commonest lure there is.
- Where an operator publishes signed statements, check the signature against a key you obtained earlier and elsewhere.
- Urgency is a tell. “The old address is compromised, use this one” is the standard opening line of an impersonator.
What WikiHidden does about it
Profiles carry a visible warning when lookalikes have been reported, with the number and the confirming evidence. Official addresses are shown with their source so they can be checked; lookalike addresses are never published, so the record cannot be used to find them. Browse confirmed reports on Scam Alerts.