The filter scam that asks you to log in first
The filter is the packaging; the login is the product. Why a real effect never needs your social password on another website, and what to do in what order if you gave it.
Short answer
A filter scam is a page offering a lens, filter or effect that asks you to log in with a social account to use it — the login is what it wants. Real effects run inside the app that hosts them, so a legitimate discovery site opens the app rather than asking for your password. If you signed in: change the password, sign out all sessions, then check whether the recovery email was changed.
On this page
A friend sends a link to a filter everyone is using this week. The page looks right, the preview shows the effect, and a button says to sign in with your Snapchat, Instagram or TikTok account to try it. You sign in. The filter never loads, or loads once and does nothing, and a day later your account is messaging your contacts with the same link.
A filter scam is a page that offers an effect, a lens or a preset and asks you to log into a social account to use it. The login is the product. The filter is the packaging, and it frequently does not exist at all.
Why this one works so well
A filter scam succeeds for three reasons, and none of them is carelessness on the victim's part.
- The request looks proportionate. Logging in to use a feature is normal. Nothing about the ask is unusual, which is precisely why it does not trigger the suspicion a payment request would.
- The referral is genuine. The link arrives from a friend whose account was taken the same way. It carries their name and their trust, and the person who sent it did not choose to.
- Urgency is built into the format. Trends expire. "Everyone is using this today" makes checking feel like missing out, and the whole mechanism runs on people not pausing.
Nothing legitimate needs your social password to apply a filter. The platform never asks another site for it.
That last sentence is the entire defence, and it holds regardless of how convincing the page looks, because it is a statement about how the systems work rather than about how the page appears.
How lenses and filters actually reach you
Understanding the real path makes the fake one obvious.
Effects are hosted inside the app that runs them. A Snapchat lens runs in Snapchat; an Instagram effect runs in Instagram. A link to an effect opens the app, and the app applies it — you are already logged in there, so nothing asks you for a password.
Discovery sites are legitimate and common. They list effects, show previews, and hand you off with an "open in app" link. The distinction is that a real discovery service sends you to the app; a fraudulent one asks you to bring your account to it. A directory such as Viral Lenz works the first way — browsing needs no account at all, and tapping a lens opens it in Snapchat where the lens actually runs.
| Legitimate discovery | Filter scam |
|---|---|
| Browse without an account | Login demanded up front |
| Opens the app to apply | Applies "on the website" |
| Any account you make is its own | Wants your social password |
| No urgency | Trend expiring, act now |
If a page claims to run a platform's effect in the browser using your account, that is not a technical shortcut. It is the tell.
What happens after the login
Credentials taken by a filter scam are usually not used immediately, which is why the connection to the filter is missed.
- They are tested elsewhere first. The same email and password are tried on other services, because reuse is common and one working pair often opens several accounts.
- The account is used to spread the same link. Messages go to contacts, because the referral from a real friend is the most effective delivery there is. This is the stage most victims notice, and by then the damage has propagated.
- Recovery details are changed — email and phone — so you cannot take the account back through the normal route.
- The account is sold or used later. An aged account with real followers has resale value, and nothing may happen for weeks.
If a login page also asked for a two-factor code, treat that as confirmation rather than a possibility. A code entered on a fraudulent page is used immediately to complete a real login, and the delay before consequences appear may be minutes.
Where these pages are promoted
Knowing where a filter scam is placed makes it recognisable before you have read a word of the page.
Comment replies under trending posts. A post about an effect collects replies pointing at "the working link", often from accounts created that week. The comment sits under genuine content, which is what lends it credibility.
Direct messages from taken accounts. The most effective channel, because the sender is real. A message that is only a link, or a link with a line of text that does not sound like the person, is worth a second look regardless of who appears to have sent it.
Sponsored posts. Paid placement is not vetting. Ads for these pages run regularly and are removed after reports, which is to say after they have worked.
Short-form videos demonstrating the effect. The footage is usually real — captured from the genuine lens — and the link in the profile goes somewhere else entirely. Seeing the effect work proves the effect exists, not that the link leads to it.
The fourth is the one worth internalising, because it explains why the page feels verified. You watched proof that the filter is real, and then followed a link that has nothing to do with it.
There is one more variant that targets people who make effects rather than use them: a message offering to feature your lens, with a login to a "creator dashboard". The audience is smaller and the accounts are more valuable, so the pages are better made.
The checks that take ten seconds
Four, in the order they are quickest to perform.
- Look at the domain. Read it right to left: the real domain is the last two parts before the first single slash.
snapchat.lens-gallery.cobelongs tolens-gallery.co, and the brand at the front is a subdomain anyone can create. - Ask what the page needs the account for. Browsing a directory does not require your identity. If the login gates the browsing, the login is the point.
- Check whether the login is a real platform screen or a form drawn to look like one. A genuine sign-in on iOS or Android opens a system sheet or the platform's own app, not a text field on the page.
- Search for the effect in the app instead. If it exists, it is findable there — and applying it from inside the app was always the shorter path.
Check three is the strongest technical signal and the least known. Real federated login hands you to the platform; a fake one keeps you on the page and collects what you type.
If you already signed in
Order matters, and speed matters more than completeness.
- Change the password on the real platform, from its own app, and use a password not reused anywhere.
- Sign out all active sessions. Every major platform has this in its security settings. Without it, an existing session persists after the password change.
- Check email and phone in account settings. If either was changed, use the platform's recovery flow immediately — the window before recovery becomes difficult is short.
- Turn on two-factor authentication if it was off, preferably with an authenticator app rather than SMS.
- Change the password anywhere you reused it, which is where most of the real damage happens.
- Warn your contacts, since the link is now going out under your name and they will trust it exactly as you did.
Step two is skipped almost universally. A password change alone does not always end sessions already established, and this is how people find themselves locked out again an hour after "fixing" it.
More on the pattern in social media scams, the underlying page-inspection habit in suspicious links, and brand imitation generally in impersonation. Snap publishes guidance on account safety covering the recovery steps for its own platform.
The short version
A filter scam sells a login, not an effect. Real lenses and filters run inside the app that hosts them, so nothing legitimate needs your social password on another website.
Browse effects without signing in, check that any login hands you to the platform's own screen rather than a form on the page, and if you did sign in — change the password, then sign out all sessions, then check whether the recovery email was changed, in that order.
Frequently asked questions
- How can I tell a real login from a fake one?
- A genuine sign-in hands you to the platform — a system sheet or the platform's own app — rather than a text field drawn on the page you are already on. If you are typing your password into the page itself, it is collecting it.
- Why did the link come from my friend?
- Because their account was taken the same way and is now sending the link to their contacts. The referral is genuine, which is what makes it effective, and they did not choose to send it.
- I entered a two-factor code as well — does that matter?
- Yes. A code entered on a fraudulent page is used immediately to complete a real login, so treat the account as compromised now rather than possibly. Change the password and sign out all sessions straight away.
- Why am I locked out again after changing my password?
- Because a password change does not always end sessions that are already established. Use the platform's sign out of all devices setting, and check whether the recovery email or phone was changed.
Sources
- My account is compromised — Snap Inc.
- Recognising phishing attempts — UK National Cyber Security Centre
- Viral Lenz on Google Play — Tecno Blocks
Scamiro
Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.
About the publication