Glossary

What is phishing in the growth world?

Phishing is credential theft by imitation: fake login pages, fake support messages, fake services whose real product is your password. In the growth world it wears one costume above all: the service that claims to need your login to deliver followers.

The one-line defence

Public metrics need only a public address. Followers, likes and views deliver to the handle anyone can see: that's how ordering works, here and at every legitimate provider.

So a "growth service" asking for credentials is asking for something delivery doesn't require. What happens after people hand them over is documented, with the receipts, in the password-asking write-up: hijacks, spam sent in your name, ransom.

The wider costume rack

  • Verification bait: "you're eligible for the blue badge, log in here" DMs, riding the checkmark's appeal.
  • Strike scares: fake copyright notices linking fake appeal portals.
  • Deal bait: brand-deal offers with credential-harvesting "contract portals".
  • Lookalike logins: domains one letter off the real one, pixel-perfect pages.

The boring defences that work

Type the domain yourself instead of clicking login links. Two-factor on everything, always: it turns a stolen password into a failed attempt. Treat urgency as the tell: real platforms don't give you 24 dramatic hours.

And if credentials did leak: change the password, revoke sessions and third-party app access, check email forwarding rules, then assess damage. Suspension recovery is much harder than five minutes of prevention.

Common questions

Why does a real growth service not need my password?

Because everything it delivers lands on public surfaces: your profile, your posts. Only actions FROM your account need credentials, and no delivery involves those. The @ is the entire requirement.

What do I do if I gave a fake service my login?

Immediately: change the password, enable two-factor, revoke unknown sessions and apps, check for changed recovery emails. Then watch for spam sent as you and warn your audience if any went out.

How do I recognise a phishing login page?

Check the domain letter by letter, distrust pages reached from DMs and emails, and remember platforms don't ask you to log in to RECEIVE something. When in doubt, navigate there yourself.

Every definition lives in the full glossary, and the services behind the vocabulary are on the services page.