---
title: "Inception the Movie is Now an Undetectable Phishing Method | Phish Protection"
description: "Inception the Movie is Now an Undetectable Phishing Method: Cyber expert James Fisher discovered a new phishing method he calls the &#34;inception bar.&#34; He named."
image: "https://phishprotection.com/og/blog/inception-the-movie-is-now-an-undetectable-phishing-method.png"
canonical: "https://phishprotection.com/blog/inception-the-movie-is-now-an-undetectable-phishing-method/"
---

Quick Answer

Cyber expert\[ James Fisher\](https://jameshfisher.com/2019/04/27/the-inception-bar-a-new-phishing-method/) discovered a new phishing method he calls the "inception bar." He named it after the movie\[ Inception\](https://www.imdb.com/title/tt1375666/?ref\_=nv\_sr\_1?ref\_=nv\_sr\_1), and just like the movie, the phishing method traps you in a fake reality. You can see an example of how it works on his website.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Finception-the-movie-is-now-an-undetectable-phishing-method%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Inception%20the%20Movie%20is%20Now%20an%20Undetectable%20Phishing%20Method&url=https%3A%2F%2Fphishprotection.com%2Fblog%2Finception-the-movie-is-now-an-undetectable-phishing-method%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fphishprotection.com%2Fblog%2Finception-the-movie-is-now-an-undetectable-phishing-method%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Finception-the-movie-is-now-an-undetectable-phishing-method%2F&title=Inception%20the%20Movie%20is%20Now%20an%20Undetectable%20Phishing%20Method "Share on Reddit") [ ](mailto:?subject=Inception%20the%20Movie%20is%20Now%20an%20Undetectable%20Phishing%20Method&body=Check out this article: https%3A%2F%2Fphishprotection.com%2Fblog%2Finception-the-movie-is-now-an-undetectable-phishing-method%2F "Share via Email") 

![Phish Protection blog post image](https://media.mailhop.org/phishprotection/images/2019/04/anti-phishing-protection-1239-1.jpg) 

Cyber expert[ James Fisher](https://jameshfisher.com/2019/04/27/the-inception-bar-a-new-phishing-method/) discovered a new phishing method he calls the “inception bar.” He named it after the movie[ Inception](https://www.imdb.com/title/tt1375666/?ref%5F=nv%5Fsr%5F1?ref%5F=nv%5Fsr%5F1), and just like the movie, the phishing method traps you in a fake reality. You can see an example of how it works on his website.

He discovered the exploit in Chrome for mobile, confirming what we already know: _mobile is the number one threat target going forward._

According to James, “In Chrome for mobile, when the user scrolls down, the browser hides the URL bar. When the user scrolls up, Chrome will re-display the true URL bar. But we can trick Chrome so that it never re-displays the true URL bar! Once Chrome hides the URL bar, we move the entire page content into a ‘scroll jail.’ Then the user _thinks_ they’re scrolling up in the page, but in fact they’re only scrolling up in the scroll jail! Like a dream in _Inception_, the user believes they’re in their own browser, but they’re actually in a browser within their browser.”

![Anti phishing protection 1239](https://media.mailhop.org/phishprotection/images/2019/04/anti-phishing-protection-1239-1.jpg) 

James elaborates, “The user should be able to scroll to the top of the jail, at which point Chrome will re-display the URL bar. But we can disable this behavior, too! We insert a very tall padding element at the top of the scroll jail. Then, if the user tries to scroll into the padding, we scroll them back down to the start of the content! It looks like a page refresh.”

The real scary part, James admitted, is that even though he created the inception bar, he found himself being tricked by it. When asked how users can protect themselves from such an exploit he said, “I don’t really know. I see it as a security flaw in Chrome. But what’s the fix?”

Okay, so a cyber expert identifies a flaw in Chrome capable of being used to phish users and the exploit is so perfect even he falls for it and he has no idea how to protect users against it. The next time someone tries to convince you the best way to protect yourself against **phishing is awareness training**, have them read this article.

![Anti phishing solutions](https://media.mailhop.org/phishprotection/images/2019/04/anti-phishing-solutions-4367.jpg) 

_The only way to prevent being phishing by an exploit this good is real-time link checking._ Even if someone pulls off the perfect phish and gets you to click on a malicious link, real-time link checking checks the link as you click on it and protects you from being phished. And of course for it to be really useful, the real-time link checking MUST work with mobile devices.

If you really want to frustrate hackers, get[ cloud-based phishing protection](/) that protects all your devices no matter how good their phishing method is. It’s fast, it’s affordable and that’s no fake reality.

## Topics

[ Phishing Awareness ](/tags/phishing-awareness/) 

![Brad Slavin](https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead across DuoCircle's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Protect your inbox from phishing attacks

Real-time email security with 60-day free trial. No credit card required.

[Start Free Trial](https://portal.duocircle.com/cart.php?a=add&pid=101&brand=phishprotection) [View Pricing](/pricing/) 

## Related Articles

[  Foundational 5m  0ktapus, Okta Breach Helps Attackers Launch Sophisticated Supply Chain Attacks  Sep 5, 2022 ](/blog/0ktapus-okta-breach-helps-attackers-launch-sophisticated-supply-chain-attacks/)[  Foundational 14m  12 Real-World Spear Phishing Examples And The Red Flags You Missed  Feb 4, 2026 ](/blog/12-real-world-spear-phishing-examples-and-the-red-flags-you-missed/)[  Foundational 2m  8 million Android users fell prey to SpyLoan malware on Google Play Store  Dec 5, 2024 ](/blog/8-million-android-users-fell-prey-to-spyloan-malware-on-google-play-store/)[  Foundational 1m  A Big Part of the Phishing Problem is You  Sep 17, 2019 ](/blog/a-big-part-of-the-phishing-problem-is-you/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"Phish Protection","url":"https://phishprotection.com","description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Inception the Movie is Now an Undetectable Phishing Method","description":"Inception the Movie is Now an Undetectable Phishing Method: Cyber expert James Fisher discovered a new phishing method he calls the \"inception bar.\" He named.","url":"https://phishprotection.com/blog/inception-the-movie-is-now-an-undetectable-phishing-method/","datePublished":"2019-04-30T10:24:26.000Z","dateModified":"2026-04-17T15:43:10.000Z","dateCreated":"2019-04-30T10:24:26.000Z","author":{"@type":"Person","@id":"https://phishprotection.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://phishprotection.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://phishprotection.com/blog/inception-the-movie-is-now-an-undetectable-phishing-method/"},"articleSection":"foundational","keywords":"Phishing Awareness","wordCount":471,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/phishprotection/images/2019/04/anti-phishing-protection-1239-1.jpg","caption":"Phish Protection blog post image","width":1200,"height":630},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://phishprotection.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://phishprotection.com/blog/"},{"@type":"ListItem","position":3,"name":"Foundational","item":"https://phishprotection.com/foundational/"},{"@type":"ListItem","position":4,"name":"Inception the Movie is Now an Undetectable Phishing Method","item":"https://phishprotection.com/blog/inception-the-movie-is-now-an-undetectable-phishing-method/"}]}
```
