Is this 'unusual sign-in, was this you? verify identity' text a scam?
Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →
Part of our guide: How to secure and recover a hacked account →
Very likely. An 'unusual sign-in, if not you verify your identity within 24 hours' text that links to account-verify.example is a credential-phishing lure. Genuine security alerts send you back to the service's own app or site to check; they don't drop you onto a look-alike domain. Line up the three tells, the threat to 'lock everything,' the 24-hour deadline, and that odd host, and the pattern is unmistakable. The login you'd type in to 'protect' your account is exactly what they're fishing for.
Got a message like this? Paste it here →
Anyone who's ever gotten a real 'new sign-in' alert is primed for this, the format is familiar and reassuring, so a fake one slides right in. It leans on our instinct to protect an account under attack, turning that instinct against us: the 'verify' link leads to a fake login that hands over the keys. Vague wording ('your account') lets it fit whatever service you're most anxious about.
Illustrative example of the pattern, not a real message someone received.
How to verify it yourself
- Ignore the link and open the actual service (email, bank, whatever it claims) by app or typed address.
- Check your account's real security or sign-in activity page, genuine alerts show up there.
- A generic account-verify.example domain belongs to no real provider; that's the giveaway.
- When unsure, contact the service through its official support, not the text.
Common questions
is account-verify.example a legitimate security page
No. Real providers use their own domains for security. A nameless 'account-verify' on .top is a phishing page that copies the login you enter.
do real sign-in alerts ask you to verify on a link
They tell you to review activity inside the app or on the official site, not to 'verify your identity' by tapping a link in a text. That step exists only to steal credentials.
why is the alert threatening to lock everything in 24 hours
The threat is pressure. Fear of losing access makes you act before you check the domain; a real provider doesn't nuke your account overnight to force a click.
is 'unusual sign-in' text a phishing scam
Yes, when it comes with a look-alike link and a deadline. The 'was this you?' framing is designed so protecting yourself and getting phished look like the same action.
If you already responded
- Change the password for the account it targeted right away, from the real app or site.
- Enable two-factor authentication and sign out all other sessions.
- Report it at reportfraud.ftc.gov and warn anyone who shares the account.