Recognising a Phishing Message About a Companion App Account

The rule that defeats every one of these, without you having to judge whether the email looks convincing: never sign in from a link in a message. Open the app yourself, or type the address you already know, or go to the store’s subscriptions screen. If the message was genuine, whatever it wanted you to do is waiting for you there. If it was not, you have just declined to hand over your password without having to spot anything.

Everything else here is about why this category attracts these messages, and how to recognise them when the writing is good — because the modern ones are.

Why companion app accounts are a favoured target

Two reasons, and both are about the victim rather than the technology.

Reluctance to check. Someone who would forward a suspicious bank email to a colleague may not want to ask anyone about this one. Phishing depends on the recipient deciding alone and quickly, and a private subject supplies both.

A believable pretext already exists. Subscriptions, plan changes, content policies, and sign-in alerts are all ordinary events in this category, so a fabricated one does not have to be inventive.

Neither reason implies that anything has actually gone wrong with your account. The message arriving is not evidence about the account.

The four shapes

The billing failure. Your payment did not go through, your premium features are about to end, update your card. Effective because it is plausible and because it manufactures a deadline. The check is not in the email: if a subscription was bought through a platform store, the store’s own subscriptions screen is the authority and the operator cannot even see your card details — see who you actually bought the subscription from.

The policy violation. Your account has been flagged, your conversations are under review, confirm your identity or appeal here. This one leans on embarrassment rather than deadline, and the appeal form is the trap.

The sign-in alert. Someone signed in from an unfamiliar place; if this was not you, secure your account. The cruel elegance is that the correct response to a real alert and the desired response to a fake one look identical. Handle it by going to the app’s own sessions screen, which is where a genuine problem would be visible anyway; the inventory of what a real intrusion reaches is in what someone else in your account would reach.

The offer. Free premium, an early feature, a gift from the operator. Older and cruder, still working, and it also arrives as a store listing or an in-app advert rather than an email — the app-impersonation version of the same trick is covered in spotting a lookalike companion app.

The tells that still work when the writing is fluent

Spelling mistakes and awkward grammar were never the real signal, and they have largely gone. These four are structural, so they survive good writing.

Where the link actually goes. Long-press it on a phone or hover on a desktop and read the destination before the first slash. Everything after that first slash is chosen by whoever built the page and can say anything, including the operator’s name. The part that matters is the domain itself, and the common trick is to put the real name in a place that looks authoritative but is not — a subdomain, a hyphenated variant, or a lookalike spelling.

Who sent it. Same reading skill applied to the sender address. A display name is free text; the address after it is the fact. Note that a genuine notice may legitimately come from a bulk-mail provider’s domain, so an unfamiliar sender is a reason to verify rather than a verdict either way — which is precisely why the never-sign-in-from-a-link rule is better than trying to judge.

Urgency plus a link in the same message. Real account problems are rarely time-critical to the minute, and legitimate operators can afford to say “open the app”. A countdown attached to a button is the signature of the genre.

Any request for a code. A second-factor code, a store verification code, an email confirmation code. Nothing legitimate ever needs you to relay one, and a message asking for one means someone is standing at a login screen with your password, waiting. This is the point at which a message stops being suspicious and becomes proof.

The awkward case: a real breach notice looks like this too

After an incident, genuine notices and opportunistic fakes arrive in the same week, formatted the same way, both urgent. Do not try to tell them apart by reading them.

Verify by going to the source yourself. The operator’s own site, opened by you, and the app’s in-app messages. A real disclosure is published somewhere, not only emailed.

Do the response the same way regardless. Change the credential, end other sessions, harden the recovery inbox — all inside the app or the identity provider, none of it through a link. The ordered version is when a companion app is breached, what to do first, and doing it after a fake notice costs you nothing.

If you already typed it in

Assume the password is now in someone else’s hands and move immediately.

Change it at the app, and change it anywhere you reused it. Reuse is what turns one mistake into several.

End every other session from the app’s own devices screen, so that a session opened with the stolen password dies.

If you also relayed a code, treat the account as entered rather than merely at risk, and check whether the email on file has been changed.

Then check the account the credential could unlock next. If the password matched your email account, that inbox is the priority over the companion app, because it is the reset route to everything else.

Report the message to your mail provider and, if a payment was taken, to the payment provider. Keep the original message rather than deleting it.

None of this requires knowing whether the page you visited was fake. Acting as though it was, when you are unsure, costs a few minutes and is the correct default every time.