Two failure modes dominate: credentials entered on a copied page, and credentials reused from somewhere else.
Who issues the login
The operator does. They create the account, set the credentials the client will accept, hold the balance and handle recovery. If you lose access, they are the only party who can restore it.
This is also why account questions get such contradictory answers online: every answer is describing a different operator’s process, and none of them says so.
Copied login pages
A fake login page is cheaper to build than a fake app and works just as well. It ranks for brand-plus-login searches, accepts whatever you type, and either forwards you to the real site or shows an error while the credentials are already gone.
There is no visual tell worth relying on. The only durable defence is never arriving at a login from a search result or a message — open the operator’s site from a bookmark you saved at registration, or open the client itself.
Verification, and doing it early
Licensed operators verify identity. The moment they choose to do it is informative: verification at registration is normal practice, and verification demanded only when you try to withdraw is a well-known way of delaying payouts.
Complete it when you open the account, keep the name on the account identical to the name on the payment method, and expect to be asked again if either changes. More on withdrawals.