Skip to content
ScamiroScamiro
Social Media Scams9 min read1,421 words

The filter scam that asks you to log in first

The filter is the packaging; the login is the product. Why a real effect never needs your social password on another website, and what to do in what order if you gave it.

ScamiroScamiro
A lens discovery gallery that can be browsed without an account and opens effects in the app that runs them
A lens discovery gallery that can be browsed without an account and opens effects in the app that runs them

Short answer

A filter scam is a page offering a lens, filter or effect that asks you to log in with a social account to use it — the login is what it wants. Real effects run inside the app that hosts them, so a legitimate discovery site opens the app rather than asking for your password. If you signed in: change the password, sign out all sessions, then check whether the recovery email was changed.

On this page
  1. Why this one works so well
  2. How lenses and filters actually reach you
  3. What happens after the login
  4. Where these pages are promoted
  5. The checks that take ten seconds
  6. If you already signed in
  7. The short version

A friend sends a link to a filter everyone is using this week. The page looks right, the preview shows the effect, and a button says to sign in with your Snapchat, Instagram or TikTok account to try it. You sign in. The filter never loads, or loads once and does nothing, and a day later your account is messaging your contacts with the same link.

A filter scam is a page that offers an effect, a lens or a preset and asks you to log into a social account to use it. The login is the product. The filter is the packaging, and it frequently does not exist at all.

Why this one works so well

A filter scam succeeds for three reasons, and none of them is carelessness on the victim's part.

  • The request looks proportionate. Logging in to use a feature is normal. Nothing about the ask is unusual, which is precisely why it does not trigger the suspicion a payment request would.
  • The referral is genuine. The link arrives from a friend whose account was taken the same way. It carries their name and their trust, and the person who sent it did not choose to.
  • Urgency is built into the format. Trends expire. "Everyone is using this today" makes checking feel like missing out, and the whole mechanism runs on people not pausing.
Nothing legitimate needs your social password to apply a filter. The platform never asks another site for it.

That last sentence is the entire defence, and it holds regardless of how convincing the page looks, because it is a statement about how the systems work rather than about how the page appears.

How lenses and filters actually reach you

Understanding the real path makes the fake one obvious.

Effects are hosted inside the app that runs them. A Snapchat lens runs in Snapchat; an Instagram effect runs in Instagram. A link to an effect opens the app, and the app applies it — you are already logged in there, so nothing asks you for a password.

Discovery sites are legitimate and common. They list effects, show previews, and hand you off with an "open in app" link. The distinction is that a real discovery service sends you to the app; a fraudulent one asks you to bring your account to it. A directory such as Viral Lenz works the first way — browsing needs no account at all, and tapping a lens opens it in Snapchat where the lens actually runs.

Legitimate discoveryFilter scam
Browse without an accountLogin demanded up front
Opens the app to applyApplies "on the website"
Any account you make is its ownWants your social password
No urgencyTrend expiring, act now

If a page claims to run a platform's effect in the browser using your account, that is not a technical shortcut. It is the tell.

What happens after the login

Credentials taken by a filter scam are usually not used immediately, which is why the connection to the filter is missed.

  • They are tested elsewhere first. The same email and password are tried on other services, because reuse is common and one working pair often opens several accounts.
  • The account is used to spread the same link. Messages go to contacts, because the referral from a real friend is the most effective delivery there is. This is the stage most victims notice, and by then the damage has propagated.
  • Recovery details are changed — email and phone — so you cannot take the account back through the normal route.
  • The account is sold or used later. An aged account with real followers has resale value, and nothing may happen for weeks.

If a login page also asked for a two-factor code, treat that as confirmation rather than a possibility. A code entered on a fraudulent page is used immediately to complete a real login, and the delay before consequences appear may be minutes.

Where these pages are promoted

Knowing where a filter scam is placed makes it recognisable before you have read a word of the page.

Comment replies under trending posts. A post about an effect collects replies pointing at "the working link", often from accounts created that week. The comment sits under genuine content, which is what lends it credibility.

Direct messages from taken accounts. The most effective channel, because the sender is real. A message that is only a link, or a link with a line of text that does not sound like the person, is worth a second look regardless of who appears to have sent it.

Sponsored posts. Paid placement is not vetting. Ads for these pages run regularly and are removed after reports, which is to say after they have worked.

Short-form videos demonstrating the effect. The footage is usually real — captured from the genuine lens — and the link in the profile goes somewhere else entirely. Seeing the effect work proves the effect exists, not that the link leads to it.

The fourth is the one worth internalising, because it explains why the page feels verified. You watched proof that the filter is real, and then followed a link that has nothing to do with it.

There is one more variant that targets people who make effects rather than use them: a message offering to feature your lens, with a login to a "creator dashboard". The audience is smaller and the accounts are more valuable, so the pages are better made.

The checks that take ten seconds

Four, in the order they are quickest to perform.

  1. Look at the domain. Read it right to left: the real domain is the last two parts before the first single slash. snapchat.lens-gallery.co belongs to lens-gallery.co, and the brand at the front is a subdomain anyone can create.
  2. Ask what the page needs the account for. Browsing a directory does not require your identity. If the login gates the browsing, the login is the point.
  3. Check whether the login is a real platform screen or a form drawn to look like one. A genuine sign-in on iOS or Android opens a system sheet or the platform's own app, not a text field on the page.
  4. Search for the effect in the app instead. If it exists, it is findable there — and applying it from inside the app was always the shorter path.

Check three is the strongest technical signal and the least known. Real federated login hands you to the platform; a fake one keeps you on the page and collects what you type.

If you already signed in

Order matters, and speed matters more than completeness.

  1. Change the password on the real platform, from its own app, and use a password not reused anywhere.
  2. Sign out all active sessions. Every major platform has this in its security settings. Without it, an existing session persists after the password change.
  3. Check email and phone in account settings. If either was changed, use the platform's recovery flow immediately — the window before recovery becomes difficult is short.
  4. Turn on two-factor authentication if it was off, preferably with an authenticator app rather than SMS.
  5. Change the password anywhere you reused it, which is where most of the real damage happens.
  6. Warn your contacts, since the link is now going out under your name and they will trust it exactly as you did.

Step two is skipped almost universally. A password change alone does not always end sessions already established, and this is how people find themselves locked out again an hour after "fixing" it.

More on the pattern in social media scams, the underlying page-inspection habit in suspicious links, and brand imitation generally in impersonation. Snap publishes guidance on account safety covering the recovery steps for its own platform.

The short version

A filter scam sells a login, not an effect. Real lenses and filters run inside the app that hosts them, so nothing legitimate needs your social password on another website.

Browse effects without signing in, check that any login hands you to the platform's own screen rather than a form on the page, and if you did sign in — change the password, then sign out all sessions, then check whether the recovery email was changed, in that order.

Frequently asked questions

How can I tell a real login from a fake one?
A genuine sign-in hands you to the platform — a system sheet or the platform's own app — rather than a text field drawn on the page you are already on. If you are typing your password into the page itself, it is collecting it.
Why did the link come from my friend?
Because their account was taken the same way and is now sending the link to their contacts. The referral is genuine, which is what makes it effective, and they did not choose to send it.
I entered a two-factor code as well — does that matter?
Yes. A code entered on a fraudulent page is used immediately to complete a real login, so treat the account as compromised now rather than possibly. Change the password and sign out all sessions straight away.
Why am I locked out again after changing my password?
Because a password change does not always end sessions that are already established. Use the platform's sign out of all devices setting, and check whether the recovery email or phone was changed.

Sources

  1. My account is compromisedSnap Inc.
  2. Recognising phishing attemptsUK National Cyber Security Centre
  3. Viral Lenz on Google PlayTecno Blocks
Scamiro

Published by

Scamiro

Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.

About the publication

Related reading

Keep going

Browse everything
A bought billboard standing beside a California highway in 1940, advertising a film to everyone who passes

Social Media Scams9 min read

When the scam is the advert

Nearly a third of people who lose money say it started on social media, and a growing share of the rest started with a search. The result you clicked was bought, not earned.

Impersonation / Online safety
A message being started from a number copied from official material rather than from a chat window

Impersonation10 min read

The support chat that opened by itself

Because you arrived rather than being contacted, every instinct about unsolicited approaches is disabled — and searching for a helpline is how most people get there.

Account takeover / Impersonation
NASA shutdown notice in web browser

Website Safety8 min read

How to read a URL properly

The part of a web address that decides where you are going is not where most people look. Reading it correctly takes five seconds and defeats most phishing.

Impersonation / Online safety