JILILUCK Phishing Scam: How a Copied Login Page Gives Itself Away

A phishing scam copies a casino login page so you type your username, password and codes into the thief's form.

Key facts and contents
JILILUCK Account Hacked
If your account is hacked, change the login password first, then the fund password, then contact Customer Services from the lobby menu.
JILILUCK Account Verification Steps
Account verification asks you to prove who you are: a valid government photo ID, a selfie with ID, and a mobile number confirmed by SMS code.
JILILUCK and PAGCOR E-Games
PAGCOR e-games are electronic games such as eBingo and eCasino games.
JILILUCK and PAGCOR Licensed Sites
PAGCOR publishes two lists of registered brands and domain names, both headed 17 September 2026.
JILILUCK and the PAGCOR Self Exclusion Form
File through PAGCOR's OSEA portal at osea.pagcor.ph, or use the Self-Exclusion Application Form on pagcor.ph with your ID and photos.
JILILUCK Smishing
Smishing is phishing by SMS: a text that pushes you to open a link or read out a code.
JILILUCK Two Step Verification
Two step verification asks for a second proof after your password, such as a code from an authenticator.
  1. How a phishing scam copies a casino login page
  2. Red flags on a fake gambling site
  3. What PAGCOR itself has warned about
  4. Check the lobby address yourself in under a minute
  5. If you already typed your details into a copy

A phishing scam works because the copy looks right and the address bar is the one thing nobody reads. The thief builds a page that matches a casino’s login screen, sends you there by text, chat or an advert, and waits for you to type your username and password. This page shows what the copy gets wrong, using the checks you can run in under a minute, and it sits inside the wider PAGCOR online reference on how the regulator’s own pages help you.

How a phishing scam copies a casino login page

The copy is cheap to make: the thief saves the look of the real page and points the form at a server that records whatever you enter. Nothing about the page itself is clever. The cleverness is in getting you to arrive without checking where you are.

Three routes bring people to a copy.

  1. A text or chat message with a short link and an urgent reason to log in, covered on the smishing and text scam page.
  2. A search advert or social post that uses a brand name with an extra word, a swapped letter or a different ending.
  3. A “support agent” who messages you first and sends a login link to “fix” a balance or a withdrawal.
What the copy needsWhat it does with it
Your username and passwordLogs in to the real lobby as you
The SMS or authenticator codeBeats a second step, if you hand it over quickly
Your fund passwordTries a withdrawal in the same session

Red flags on a fake gambling site

A fake gambling site has to look finished, so it spends effort on logos and badges and none on the things only the real lobby has. Work down this list before you type anything.

  1. The address is not one you reached yourself. You arrived from a message, an advert or a chat, not from an address you typed or a bookmark you made.
  2. The page checks fail. The real lobby shows the JILILUCK wordmark top left, an Abiso notice with a Tanggapin button on a first visit, and the Mag-login and Magrehistro pair.
  3. The form asks for more than a login does. The real login form holds Username, Password, a Tandaan tick box and Mag-login. A page that also wants your fund password, a bank card number or a code at login is collecting what it can use to withdraw.
  4. A PAGCOR logo is the proof. A logo is an image anyone can copy, and the next section explains why PAGCOR itself says so.
  5. Someone is rushing you. A deadline, a “frozen account” or a “verification fee” is the oldest pressure line there is.
  6. The “support” contact is outside the menu. Customer Services in the lobby menu is the only support channel the Terms of Service recognise, and any other channel claiming to be support is fake.

What PAGCOR itself has warned about

PAGCOR publishes its warnings on its own site, and two of them match the copies described above. On 29 June 2026 it warned the public against illegal offshore gaming websites that claim to be licensed or accredited by the agency, use the PAGCOR logo and show fabricated licence certificates. On 25 February 2025 it warned that fraudsters were sending Viber messages that falsely claimed to come from its chairman and its president, using mobile numbers registered in their names.

The lesson from both is the same: a badge or a famous name inside the page or the message proves nothing. Look the brand and its domain up on PAGCOR’s own lists, which the PAGCOR online reference explains how to read, and treat anything that reaches you unasked as unproven.

WarningDateWhat the scammers used
Illegal offshore gaming sites29 June 2026PAGCOR logo, fabricated licence certificates
Impersonated executives25 February 2025Viber messages from numbers registered in the executives’ names

Check the lobby address yourself in under a minute

You do not need a tool for this, only the habit of reading the page before the form. On 2 October 2026 the lobby opened at jililuck.com, and the same page was also served at jililuck1.com, jililuck.app, jililuck22.com and jililuck88.com. An address with a word in front of the lobby’s own address, such as jililuck22.jililuck.com, opens the same lobby and carries that word as an agent’s referral code.

  1. Type the address yourself or open your bookmark, never the link in a message.
  2. Read the whole address: the part just before the final ending is the part that counts.
  3. Confirm the wordmark, the Abiso notice and the Mag-login and Magrehistro pair.
  4. Open Customer Services from the menu, not from a chat that found you.
  5. Log in only when all four match, and use the JILILUCK casino overview to see what the real lobby lanes look like.

Addresses can change, so the page itself, not the list above, is what you trust.

If you already typed your details into a copy

Speed matters more than certainty. Open the real lobby from an address you typed and use the steps below, then read the first-hour account hacked steps for the full order.

Problem

You entered a username and password on a page you now doubt

Fix

Log in to the real lobby and change the login password at once, then change the fund password, because the Terms tell members to change both regularly.

Problem

You also gave away a code

Fix

Treat the session as taken: change both passwords, then ask Customer Services in the menu to review the account.

FAQ

What is a phishing scam on a casino login page?

It is a copy of a real login screen on an address the thief controls. You enter your username and password, the copy passes them on, and the thief logs in as you.

Does a PAGCOR logo on a site prove it is genuine?

No. PAGCOR warned on 29 June 2026 that fake offshore gaming sites use its logo and display fabricated licence certificates. Check the brand and address against PAGCOR's own published lists instead.

Can I trust a Facebook chat that says it is JILILUCK support?

No. The lobby's Terms of Service say Customer Services in the menu is the only way to contact support and that any other channel claiming to be support is fake.

Anong gagawin ko kung nailagay ko na ang password ko sa fake site?

Change the password on the real lobby right away, change the fund password too, and follow the first-hour steps on the account hacked page.

Heading over to JILILUCK?

Your account, your balance and every promotion are held by JILILUCK itself; this guide holds none of them.