What the attacker wants
The phisher wants the victim to reveal something that authorizes the attacker elsewhere: a password, OTP, bearer, recovery code, or ceremony fragment that converts into a second session. The conversion is harvest-to-caller — trick the human, then reuse the string as ambient authority on a different device or route. Phishing remains a human problem; this page only denies the ambient conversion that makes the lure cash out as lasting login.
