Phishing is credential theft by imitation: fake login pages, fake support messages, fake services whose real product is your password. In the growth world it wears one costume above all: the service that claims to need your login to deliver followers.
Public metrics need only a public address. Followers, likes and views deliver to the handle anyone can see: that's how ordering works, here and at every legitimate provider.
So a "growth service" asking for credentials is asking for something delivery doesn't require. What happens after people hand them over is documented, with the receipts, in the password-asking write-up: hijacks, spam sent in your name, ransom.
Type the domain yourself instead of clicking login links. Two-factor on everything, always: it turns a stolen password into a failed attempt. Treat urgency as the tell: real platforms don't give you 24 dramatic hours.
And if credentials did leak: change the password, revoke sessions and third-party app access, check email forwarding rules, then assess damage. Suspension recovery is much harder than five minutes of prevention.
Because everything it delivers lands on public surfaces: your profile, your posts. Only actions FROM your account need credentials, and no delivery involves those. The @ is the entire requirement.
Immediately: change the password, enable two-factor, revoke unknown sessions and apps, check for changed recovery emails. Then watch for spam sent as you and warn your audience if any went out.
Check the domain letter by letter, distrust pages reached from DMs and emails, and remember platforms don't ask you to log in to RECEIVE something. When in doubt, navigate there yourself.
Related terms
Every definition lives in the full glossary, and the services behind the vocabulary are on the services page.