
You open a few browser tabs, get distracted, and come back later to one that now shows a familiar login page asking you to sign in again. Nothing seems wrong — except that tab quietly transformed itself while you were away. That is tabnabbing, a patient little phishing trick that uses your own inattention. Our GetMyPassword team explains what tabnabbing is and how to avoid it.

What tabnabbing is
Tabnabbing is a phishing technique where a background browser tab silently changes itself into a fake login page while you are not looking. You visit an ordinary-seeming page and leave its tab open. After a while, that tab — now ignored — rewrites itself to mimic the sign-in screen of a service you use, like your email or bank. When you glance back, you assume you got logged out and simply type your password again, handing it to the fake page.
Why it is so sneaky
Most phishing tries to lure you somewhere new. Tabnabbing waits for you to come back to a tab you already trusted. Because you opened it yourself and left it alone, you do not suspect it, and a convincing copy of a login screen plus a familiar logo is enough to lower your guard. The trick leans entirely on a normal habit — leaving tabs open and re-entering a password when one looks logged out — rather than on tricking you into clicking a dodgy link.
How to protect yourself
- Check the address bar before typing a password — confirm the real domain and HTTPS, every time.
- Be suspicious of a tab asking you to re-login that you did not actively navigate to.
- Open sensitive sites in a fresh tab by typing the address yourself, rather than reusing an old one.
- Close tabs you are done with, and keep your browser updated.
- Let a password manager autofill — it will not fill your login on a look-alike domain.
Tabnabbing bets you will trust a tab just because you opened it. The cure is a one-second habit: before any password, read the address bar — a fake page cannot fake the real domain.
Why a password manager helps most
The strongest everyday defense is to stop typing passwords by hand. A password manager autofills your login only on the exact site it belongs to, so a tab pretending to be your bank on a slightly different address simply will not trigger it — an instant red flag. Pair that with a unique password from our password generator for every account and two-factor authentication, and even a password slipped to a fake tab cannot fully open the real account.
Frequently asked questions
What is tabnabbing?
It is a phishing technique where a background browser tab silently changes into a fake login page while you are not looking. When you return, you assume you were logged out and re-enter your password, giving it to the fake page.
How do I avoid tabnabbing?
Always check the address bar for the real domain and HTTPS before typing a password, be suspicious of a tab asking you to re-login that you did not navigate to, open sensitive sites by typing the address yourself, and close tabs you are done with.
Does a password manager stop tabnabbing?
It helps a lot. A password manager autofills only on the exact legitimate site, so it will not fill your login on a look-alike fake tab — and that refusal is a clear warning sign. Combine it with unique passwords and two-factor authentication.



