JILILUCK Phishing Scam: How a Copied Login Page Gives Itself Away
A phishing scam copies a casino login page so you type your username, password and codes into the thief's form.
Key facts and contents
- JILILUCK Account Hacked
- If your account is hacked, change the login password first, then the fund password, then contact Customer Services from the lobby menu.
- JILILUCK Account Verification Steps
- Account verification asks you to prove who you are: a valid government photo ID, a selfie with ID, and a mobile number confirmed by SMS code.
- JILILUCK and PAGCOR E-Games
- PAGCOR e-games are electronic games such as eBingo and eCasino games.
- JILILUCK and PAGCOR Licensed Sites
- PAGCOR publishes two lists of registered brands and domain names, both headed 17 September 2026.
- JILILUCK and the PAGCOR Self Exclusion Form
- File through PAGCOR's OSEA portal at osea.pagcor.ph, or use the Self-Exclusion Application Form on pagcor.ph with your ID and photos.
- JILILUCK Smishing
- Smishing is phishing by SMS: a text that pushes you to open a link or read out a code.
- JILILUCK Two Step Verification
- Two step verification asks for a second proof after your password, such as a code from an authenticator.
A phishing scam works because the copy looks right and the address bar is the one thing nobody reads. The thief builds a page that matches a casino’s login screen, sends you there by text, chat or an advert, and waits for you to type your username and password. This page shows what the copy gets wrong, using the checks you can run in under a minute, and it sits inside the wider PAGCOR online reference on how the regulator’s own pages help you.
How a phishing scam copies a casino login page
The copy is cheap to make: the thief saves the look of the real page and points the form at a server that records whatever you enter. Nothing about the page itself is clever. The cleverness is in getting you to arrive without checking where you are.
Three routes bring people to a copy.
- A text or chat message with a short link and an urgent reason to log in, covered on the smishing and text scam page.
- A search advert or social post that uses a brand name with an extra word, a swapped letter or a different ending.
- A “support agent” who messages you first and sends a login link to “fix” a balance or a withdrawal.
| What the copy needs | What it does with it |
|---|---|
| Your username and password | Logs in to the real lobby as you |
| The SMS or authenticator code | Beats a second step, if you hand it over quickly |
| Your fund password | Tries a withdrawal in the same session |
Red flags on a fake gambling site
A fake gambling site has to look finished, so it spends effort on logos and badges and none on the things only the real lobby has. Work down this list before you type anything.
- The address is not one you reached yourself. You arrived from a message, an advert or a chat, not from an address you typed or a bookmark you made.
- The page checks fail. The real lobby shows the JILILUCK wordmark top left, an Abiso notice with a Tanggapin button on a first visit, and the Mag-login and Magrehistro pair.
- The form asks for more than a login does. The real login form holds Username, Password, a Tandaan tick box and Mag-login. A page that also wants your fund password, a bank card number or a code at login is collecting what it can use to withdraw.
- A PAGCOR logo is the proof. A logo is an image anyone can copy, and the next section explains why PAGCOR itself says so.
- Someone is rushing you. A deadline, a “frozen account” or a “verification fee” is the oldest pressure line there is.
- The “support” contact is outside the menu. Customer Services in the lobby menu is the only support channel the Terms of Service recognise, and any other channel claiming to be support is fake.
What PAGCOR itself has warned about
PAGCOR publishes its warnings on its own site, and two of them match the copies described above. On 29 June 2026 it warned the public against illegal offshore gaming websites that claim to be licensed or accredited by the agency, use the PAGCOR logo and show fabricated licence certificates. On 25 February 2025 it warned that fraudsters were sending Viber messages that falsely claimed to come from its chairman and its president, using mobile numbers registered in their names.
The lesson from both is the same: a badge or a famous name inside the page or the message proves nothing. Look the brand and its domain up on PAGCOR’s own lists, which the PAGCOR online reference explains how to read, and treat anything that reaches you unasked as unproven.
| Warning | Date | What the scammers used |
|---|---|---|
| Illegal offshore gaming sites | 29 June 2026 | PAGCOR logo, fabricated licence certificates |
| Impersonated executives | 25 February 2025 | Viber messages from numbers registered in the executives’ names |
Check the lobby address yourself in under a minute
You do not need a tool for this, only the habit of reading the page before the form. On 2 October 2026 the lobby opened at jililuck.com, and the same page was also served at jililuck1.com, jililuck.app, jililuck22.com and jililuck88.com. An address with a word in front of the lobby’s own address, such as jililuck22.jililuck.com, opens the same lobby and carries that word as an agent’s referral code.
- Type the address yourself or open your bookmark, never the link in a message.
- Read the whole address: the part just before the final ending is the part that counts.
- Confirm the wordmark, the Abiso notice and the Mag-login and Magrehistro pair.
- Open Customer Services from the menu, not from a chat that found you.
- Log in only when all four match, and use the JILILUCK casino overview to see what the real lobby lanes look like.
Addresses can change, so the page itself, not the list above, is what you trust.
If you already typed your details into a copy
Speed matters more than certainty. Open the real lobby from an address you typed and use the steps below, then read the first-hour account hacked steps for the full order.
You entered a username and password on a page you now doubt
Log in to the real lobby and change the login password at once, then change the fund password, because the Terms tell members to change both regularly.
You also gave away a code
Treat the session as taken: change both passwords, then ask Customer Services in the menu to review the account.
FAQ
What is a phishing scam on a casino login page?
It is a copy of a real login screen on an address the thief controls. You enter your username and password, the copy passes them on, and the thief logs in as you.
Does a PAGCOR logo on a site prove it is genuine?
No. PAGCOR warned on 29 June 2026 that fake offshore gaming sites use its logo and display fabricated licence certificates. Check the brand and address against PAGCOR's own published lists instead.
Can I trust a Facebook chat that says it is JILILUCK support?
No. The lobby's Terms of Service say Customer Services in the menu is the only way to contact support and that any other channel claiming to be support is fake.
Anong gagawin ko kung nailagay ko na ang password ko sa fake site?
Change the password on the real lobby right away, change the fund password too, and follow the first-hour steps on the account hacked page.