How to Spot a Pharming Site

Typing the correct web address is not always enough protection β€” here is how pharming works and how to catch it before you type in anything sensitive.

What pharming actually is

Pharming is an attack where malware secretly alters your computer's local settings or hijacks a DNS lookup, so that even when you type the exact correct address, you get redirected to a fake site instead of the real one.

The key difference from phishing

Phishing tricks you into clicking a fake link, but pharming can redirect an infected device to a fake site even from a saved bookmark or a manually typed address, which means checking the link itself is not enough to catch it.

A request for your entire security code is a red flag

A legitimate bank will never ask you to enter your full security code, a full one-time password sheet, or several codes at once on a single screen. A page that asks for this is almost certainly fake, and you should stop entering anything immediately.

Check the address bar lock icon and certificate details

A fake site can copy the look of a real one very convincingly, so it is worth clicking the lock icon in the address bar to confirm the certificate is genuinely issued to the financial institution it claims to be.

Run regular antivirus scans on your device

Since pharming starts with an infected device, running an up-to-date antivirus scan regularly helps catch the kind of malware that alters local settings before it can be used against you.

If anything feels off, close the page and verify independently

The moment something looks even slightly wrong, close the page immediately and confirm what is going on by opening the official app fresh or calling the institution's published customer service number directly, rather than trusting anything on the suspicious page.

Why a correct address is not proof of safety

Most people are trained to check a link before clicking, which is good defense against ordinary phishing. Pharming defeats that habit entirely, since the redirection happens at the device or network level rather than through a deceptive link, meaning the address bar alone can no longer be trusted as proof you are on the real site.

Shared and public computers carry extra risk

A device used by many different people, such as a shared or public computer, is more likely to pick up the kind of malware pharming relies on, so avoid logging into banking or financial accounts on shared machines whenever possible, and keep security software updated on any device you do use for that purpose.

Frequently Asked Questions

Am I at greater risk using a shared or public computer?

Yes. A device used by many people is more likely to be infected with the kind of malware pharming relies on, so avoiding financial logins on shared or public computers is one of the simplest precautions you can take.

What should I do if I already entered information on a pharming site?

Contact your bank immediately to freeze the account and stop any pending payment, then change your password and reissue any codes or security credentials you entered. Reporting the incident to your local police and financial regulator is also worth doing right away.