
How to Spot a Fake M2 Login Page
A cloned login page can copy M2’s orange buttons, banners and announcement word for word. What it cannot copy is the domain. These five checks take a few seconds and protect your balance.
Five checks before you type your password
- Read the domain. It must be exactly m2win001.com or m2win002.com. Read it from the end backwards so you are not fooled by a familiar start.
- Look for swapped characters:
0foro,1forl,rnform, extra dashes or words such as-login,-bonusor-my. - Think about how you got there. Did you type it or use your bookmark? Good. Did you tap a link in a group chat, comment or ad? Close it.
- Check what it asks for. M2’s Sign In form asks for your username and password. A page that wants your OTP, IC photo or bank PIN to “verify” is fake.
- Watch for pressure. “Your account will be frozen in 10 minutes” or “claim your RM bonus now” are classic phishing hooks.
Tricks scammers use
- “New official link” broadcasts in Telegram and WhatsApp groups.
- Fake support agents who message you first and ask for your OTP.
- Top-up agents who ask you to transfer money to a personal account.
- Look-alike search ads that sit above the real result.
If you already typed your password
- Open the real site yourself and reset your password with Forgot Username/Password.
- Change the same password anywhere else you used it.
- Tell M2 support through LiveChat on the official site.
The easiest protection
Add the official link to your Home Screen once using the M2 App guide, then always open M2 from that icon. For a side-by-side checklist, see Real vs Fake M2 Links.