Body:
I've watched a handful of regulars in SpinRoom get tripped up by this in the last few weeks, so I wanted to write down what actually happens before someone loses more than a session session-budget. The scam is simple: you request a withdrawal, and within an hour you get an email or SMS that looks like it came from the community-hub, asking you to "re-verify" your identity or upload KYC documents through a link. The page behind that link looks exactly like the withdrawal or verification screen you know. Same logo, same layout, same button text. But it is not the community-hub. It is a clone, and its only job is to harvest your documents, your login, or both. Here is what I check, in order, every single time. First, the URL itself. A real community-hub withdrawal screen lives under the main domain you already use. Not a subdomain like verify.community-hub-name.com, not a lookalike with a swapped letter or an extra dash, and definitely not a link shortener. If the address bar does not start with the exact domain you typed when you created the account, stop. Do not enter anything. Close the tab. Second, the padlock. A green lock or "secure" label in the browser means the connection is encrypted. It does not mean the site is legitimate. Phishing kits now include free SSL certificates as standard, so the padlock is close to useless as a trust signal on its own. It only tells you that someone else cannot easily read what you send. It says nothing about who is receiving it. Third, the context. Did the request arrive through a link in an email or SMS? That alone is enough to treat it as hostile. Legitimate operators do not send withdrawal re-verification links through messages. They place a notification inside your logged-in account, under your profile or cashier section. When I get one of these messages, I never click it. I open a new tab, type the community-hub address manually, log in, and look for any pending verification notice there. If there is nothing, the message was fake. If there is something, I handle it through the in-account upload portal, which is where real KYC documents belong anyway. Fourth, the details on the page. Cloned pages often get the small things wrong because they are built from screenshots. The footer links may not work. The language selector may be missing. The support chat widget might be a static image instead of a live button. The copyright year may be outdated. A real withdrawal screen is part of a working application. A clone is a picture of one with input fields bolted on. If anything on the page feels flat or unclickable, that is a warning sign. What I do when something feels off is simple. I take a full screenshot before closing the tab, then I contact support through the official site or app and ask them to confirm whether any verification request was sent to my account. I do not reply to the original email or SMS. I do not forward documents anywhere except the in-account upload area. One more habit that helps: bookmark the real community-hub login page and use that bookmark every time. Never rely on search results or message links to get back to your account. It takes five seconds and removes the most common entry point for these clones. None of this is about paranoia. It is about making the scam unprofitable for the people running it. If you pause at the URL bar and verify the request inside your account, you have already beaten the page. Stay sharp out there.