How to spot phishing sites built with AI website builders

AI builders made fake sign-in pages cheap to make and quick to publish. The tells are still there if you know where to look.

Phishing sites built with AI website builders are now a routine part of the scam landscape. The same tools that let a florist build a site in an afternoon let a scammer clone a bank's sign-in page in minutes and publish it for free. The email security company Proofpoint has reported seeing tens of thousands of Lovable URLs flagged as threats each month, in campaigns impersonating brands such as Microsoft and UPS.

The builder is not the problem, and most sites made with these tools are honest. But AI-built phishing pages share a set of tells. This guide covers them, in the order you can check them.

Why scammers use AI builders

  • Speed. A prompt such as "a login page that looks like this screenshot" produces a convincing copy in seconds.
  • Free hosting with a clean reputation. A new page on a well-known builder domain may not be on any blocklist yet, and some filters trust the parent domain.
  • Disposable. When a page is reported and removed, another takes its place a minute later.

1. Check the address before anything else

Real companies host their sign-in pages on their own domains. Be suspicious of:

  • A brand's page on a builder domain. microsoft-login.lovable.app or ups-delivery.bolt.host is not Microsoft or UPS. No large company runs its sign-in on an AI builder's free hosting.
  • Look-alike spellings. paypa1.com with a digit one, amazom.com with one letter changed, or rnicrosoft.com where rn imitates m.
  • Lookalike characters from other alphabets. A Cyrillic а looks identical to a Latin a. Some browsers show these addresses as xn-- codes, which is a warning in itself.
  • The brand's name on an odd ending. paypal.top or chase-secure.xyz.

On a phone, tap the address bar to see the full address. Mobile browsers often show only part of it.

2. Notice what the page asks for

A page that only shows information can't do much harm. The danger starts when it asks you for something: a password, a one-time code, a card number, or a crypto wallet's recovery phrase. Combine that with a doubtful address and you have the classic phishing pattern.

A real company will never ask for your wallet's recovery phrase, and almost never needs a one-time code typed into a page you reached from an email or text.

3. Treat "paste this to verify" as an attack

A newer trick, sometimes called ClickFix, shows a fake CAPTCHA that asks you to press Win+R (or open Terminal on a Mac), paste something and press Enter "to prove you're human". The page has already copied a command to your clipboard. Running it installs malware.

No real CAPTCHA ever asks you to open the Run dialog or a terminal. If a page does, close it. More in the fake CAPTCHA scam.

4. Look for signs it was thrown together

These do not prove phishing on their own, but they add up on a page that is asking for credentials:

  • Builder fingerprints on a big brand's page. A sign-in page with Lovable's gptengineer.js script or a Made with Bolt badge is not the brand's real page. Our builder fingerprint guide lists what to look for, and how to tell if a website was built with an AI builder has the fingerprints builder by builder.
  • Template leftovers. A tab title of Vite + React + TS on a page claiming to be your bank.
  • Links that go nowhere. "Forgot password", "Privacy" and the footer links lead back to the same page or to #.
  • Only one page. Real sign-in pages sit inside a whole site. Phishing pages often have nothing behind them.

5. Where the data goes

You can't see this without the developer tools, but it is worth knowing: many phishing kits send what you type straight to a Telegram bot or a Discord webhook rather than to any real server. Security tools, Kitsuvo included, look for those destinations in the page's code. A sign-in form that posts to api.telegram.org is not a sign-in form.

If you already entered your details

  1. Go to the real site by typing its address yourself, and change the password you entered.
  2. Change it anywhere else you used the same password.
  3. If you entered card details, call your bank using the number on the back of the card.
  4. If you ran a command from a fake CAPTCHA, disconnect from the internet and run a full scan with your security software, or get help from someone you trust.
  5. Report the page to Google Safe Browsing and to the builder that hosts it, so it can be taken down for everyone. Our guide on how to report a phishing website lists every place to send it.

How Kitsuvo handles impersonation

Kitsuvo keeps "built with AI" and "impersonating a brand" as separate questions, because one is context and the other is danger. Built with AI only ever gets a neutral note. A page is stopped behind a warning only on high-precision rules, for example a password or card field on a look-alike address, a brand's sign-in page on builder hosting, a form that sends data to a Telegram bot, or a fake CAPTCHA asking you to paste into the Run dialog. Go back is always the first button. The checks run on your own computer, and sign-in pages are never sent to any AI service.

To learn how to read a site's build evidence in general, see how to tell if a website was made with AI.

Questions people ask

Are all lovable.app or bolt.host sites dangerous?

No. The great majority are ordinary projects by people who used those builders. The danger sign is a page on builder hosting that claims to be a well-known company and asks you to sign in or pay.

How can I check if a website is fake before I enter my password?

Read the full address and make sure it is the company's real domain, spelled correctly. If you arrived from an email or text, close the tab and type the company's address yourself instead. Password managers help too: they will not autofill on a look-alike domain.

What is a ClickFix or fake CAPTCHA attack?

It is a page that pretends to be a human check and tells you to press Win+R, paste and press Enter. The page has put a malicious command on your clipboard. Real CAPTCHAs never ask you to run anything.