# depop.id1294.cfd — SUSPICIOUS > PhishDestroy identifies depop.id1294.cfd as a fake Depop login page hosting a phishing scam. VirusTotal shows 0/95 detections for this active threat. ## Summary PhishDestroy analysts have identified depop.id1294.cfd as a live phishing domain masquerading as the Depop login portal, designed to harvest user credentials and payment details. This domain was flagged as an active phishing threat on March 18, 2026, and was registered through Global Domain Group LLC. The site resolves to IP 188.114.96.3 and leverages a Let's Encrypt SSL certificate to appear legitimate, increasing the risk of user deception. Threat intelligence confirms depop.id1294.cfd remains undetected by security vendors, with 0 out of 95 VirusTotal engines flagging it as malicious at the time of analysis. This low detection rate highlights the sophistication of the threat, relying on freshly registered domains and trusted SSL infrastructure to bypass traditional defenses. The domain’s recent creation and clean reputation profile make it a credible vector for credential theft, particularly targeting Depop users seeking to access their accounts. If you or someone you know has visited depop.id1294.cfd, immediately cease interaction, do not enter any login or payment information, and inspect device activity for signs of compromise. Change passwords for all accounts using the same credentials elsewhere, enable two-factor authentication where possible, and scan your device with updated antivirus software. Report the domain to your email provider, browser flagging systems, and platforms like Google Safe Browsing or PhishDestroy to help protect others from this active threat. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-18 14:41:47 - Registrar: Global Domain Group LLC - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/a83aa627-0066-45bf-989c-449348c03150 - PhishDestroy: https://phishdestroy.io/domain/depop.id1294.cfd/ - LLM endpoint: https://phishdestroy.io/domain/depop.id1294.cfd/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/depop.id1294.cfd/ Last updated: 2026-03-21