English
Back
Download
Need Help?
Log in to access Online Inquiry
Back to the Top

Warning: Fake Moomoo Emails and Login Pages

We have identified an emerging phishing scam in which criminals impersonate Moomoo using convincing emails and fake login websites.

These scams can be difficult to recognise because the fraudulent email and website may closely copy Moomoo’s branding, layout and wording. The scam is designed to capture your login information and security verification codes in real time, allowing the criminal to access your actual Moomoo account.

This type of attack is sometimes known as a “man-in-the-middle” or “adversary-in-the-middle” phishing scam.

 

How does the scam work?

The scam commonly follows these steps:

1.A convincing email is sent

The scammer sends an email designed to look like an official Moomoo notification. It may use Moomoo branding and refer to a plausible or time-sensitive account matter.

For example, the email may claim that you need to log in to update your W-8BEN form, confirm your tax information, complete a security review or prevent restrictions from being placed on your account.

2.The email directs you to a fake login page

The email contains a link inviting you to log in. The link opens a fraudulent website designed to closely resemble Moomoo’s genuine login page.

The website address may differ from the genuine address by only a few letters, symbols or additional words.

3.Your login details are relayed in real time

When you enter your username and password into the fake website, the scammer simultaneously enters or relays those details to Moomoo’s genuine login system.

Because the scammer is attempting to log in to your real account, Moomoo may then send a genuine one-time password or security code to your registered mobile number.

4.The scammer captures your verification code

The fake website asks you to enter the security code sent to your phone. The scammer then immediately relays that code to the genuine Moomoo login page.

Receiving a genuine security code does not mean the website you are using is genuine. The code may have been triggered by the scammer’s attempt to access your account.

5.You may be asked to approve a new-device login

You may also receive an authorisation request in the Moomoo App on an existing trusted device.

Because the fraudulent website has created the impression that you are completing a legitimate Moomoo process, you may be persuaded to approve the request. Doing so may authorise the scammer’s device to access your account.

6.The criminal takes control of the account

Once access is obtained, the criminal may attempt to change account details, place unauthorised trades or use other methods to remove value from the account.

One method may involve coordinated trading in thinly traded overseas securities, where transactions are used to move value from the compromised account. These transactions can be difficult to trace or recover, particularly where overseas markets and multiple jurisdictions are involved.

 

Why might security codes not stop this scam?

Security codes and trusted-device approvals provide important protection against many forms of unauthorised access. However, they cannot protect an account where the client is deceived into providing the code or personally approving the scammer’s login attempt.

Never enter a one-time code or approve a new-device request unless you independently initiated the login through the genuine Moomoo App or official website.

Moomoo staff will not need you to disclose your password or one-time security code to them.

 

Warning signs to watch for

Be cautious if an email or message:

  • asks you to urgently log in to update tax, identity or account information;

  • threatens withholding tax, account restrictions, suspension or loss of access;

  • contains a login link you were not expecting;

  • directs you to a website that looks genuine but has an unfamiliar address;

  • asks for your password, SMS code or other security information;

  • causes an unexpected new-device authorisation request to appear in your Moomoo App; or

  • pressures you to complete several authentication steps without giving you time to independently verify the request.

The sender’s name, logo and visual appearance are not proof that an email is genuine.

 

How can I protect myself?

For sensitive account actions, open the Moomoo App directly or access Moomoo through the official website rather than using a login link in an unexpected email.

Before entering any information, check the full website address carefully. Do not rely only on how the page looks, as fraudulent websites may closely reproduce genuine branding and content.

Never provide your password or one-time security code to another person. Do not approve a login or new-device request unless you personally initiated it through an official Moomoo channel.

If you are unsure whether a communication is genuine, stop and contact Moomoo using the contact details available in the Moomoo App or on our official website.

 

What should I do if I entered my details?

If you believe you may have entered information into a fraudulent website or approved an unfamiliar login request:

1.Contact Moomoo immediately through the customer service function in the Moomoo App or email support@au.moomoo.com

2.Change your Moomoo password from a trusted device.

3.Change the password for your email account, particularly if the same or a similar password was used.

4.Do not approve any further login, device or transaction requests.

5.Preserve the suspicious email, website address, screenshots and any related messages.

6.Report the incident to Scamwatch and ReportCyber. IDCARE may also assist if your identity or personal information has been compromised.

Acting quickly may help prevent further unauthorised activity.

 

Stay alert

Phishing scams are becoming increasingly sophisticated. An email, website or security prompt can appear genuine even when it forms part of a coordinated attempt to access your account.

Always access your account through the official Moomoo App or website, independently verify unexpected communications, and never approve an authentication request that you did not initiate.

You may also want to read our separate scam awareness article about Pump and Dump Share Scams

 

Market Insights
Star Tech Companies
View More
Warren Buffett Portfolio
View More