How to spot scams like Beneficiary/Inheritance phishing email
Phishing/ScamAlso Known As: Beneficiary/Inheritance spam
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What is Beneficiary/Inheritance email scam?
Generally, scammers behind email scams such as this one attempt to trick recipients into believing that they are beneficiaries of a will, life insurance policy, etc. Scammers ask recipients to contact them and provide various information. At some point, recipients are asked to pay a processing fee or transfer charge.
Note that scammers exploit the names of existing, often well-known organizations and companies to make their emails seem legitimate.

More about the Beneficiary/Inheritance email scam
There are at least two variants of this email scam. One is disguised as a release of funds message claiming that the recipient is a beneficiary of 3,800,000.000 dollars.
Another one is disguised as a message regarding a will (testament) of a person who has died of COVID-19 and claiming that the recipient, who supposedly has an identical surname, is named as the beneficiary of 21,300,000.000 dollars.
In most cases, when recipients contact or reply to scammers behind these emails they are asked to provide personal, sensitive information such as credit card details or to transfer funds (as a processing fee, transfer charge, etc.).
I.e., scammers attempt to extort money or sensitive information, which can be used for malicious purposes (e.g., to make fraudulent purchases and transactions, and steal identities).
| Name | Beneficiary/Inheritance Email Scam |
| Threat Type | Phishing, Scam, Social Engineering, Fraud. |
| Fake Claim | Recipient is a eligible to receive distributions from a will or life insurance policy. |
| Disguise | A message from the Dubai Islamic bank. |
| Symptoms | Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer. |
| Distribution methods | Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains. |
| Damage | Loss of sensitive private information, monetary loss, identity theft. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Examples of similar scams
"United Nations Online Lotto Email Scam", "USAA Email Scam", and "You Received A Transfer In The Amount Email Scam" are examples of other email scams. Note that cyber criminals can use emails to extort money and sensitive information, and distribute malware (such as Agent Tesla, Urnsif, TrickBot, Adwind, etc.).
How do spam campaigns infect computers?
Ransomware and other malware infections are commonly spread through malspam campaigns, untrusted file/software download sources, fake (third party) software updating tools, Trojans and unofficial software activation tools. Using malspam, criminals send emails that have a malicious file attached, or include a website link designed to download a malicious file.
Their main goal is to trick recipients into executing the file, which then infects the computer with malware. Cyber criminals usually attach a Microsoft Office document, archive file (ZIP, RAR), PDF document, executable file (.exe) or JavaScript file, and wait until recipients open it.
Note that malicious MS Office documents can install malware only when users enable editing/content (macros commands). If the documents are opened with MS Office versions prior to 2010, however, the documents install malicious software automatically, since these older versions do not include "Protected View" mode.
Examples of untrusted file and software download sources are Peer-to-Peer networks (torrent clients), free file hosting websites, freeware download sites, and unofficial web pages. These are used to distribute malicious files by disguising them as legitimate and regular.
When users download and open (execute) the files, however, they inadvertently install malware. Fake software updating tools cause damage by installing malware rather than updates/fixes for installed software, or by exploiting bugs/flaws of outdated software.
Trojans are malicious programs that can cause chain infections by installing other software of this kind. Note that malware can only be distributed in this way if Trojans are already installed on computers.
Unofficial activation ('cracking') tools are illegal programs that supposedly activate licensed software free of charge and bypass activation, however, they often install other malicious programs instead.
How to avoid installation of malware
You are advised to research all software before download/installation. Use only official and verified download channels. Unofficial and free file-hosting websites, Peer-to-Peer sharing networks (BitTorrent, Gnutella, eMule), and other third party downloaders commonly offer harmful and bundled content, and are therefore untrusted and should be avoided.
When downloading/installing, read the terms, study all possible options, use the "Custom/Advanced" settings and opt-out of additional apps, tools, features, and so on. Intrusive advertisements typically seem legitimate, however, they can redirect to dubious and malicious sites (e.g. gambling, pornography, adult-dating, and many others).
If you encounter ads or redirects of this kind, inspect the system and remove all dubious applications and browser extensions/plug-ins immediately. If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Text presented in the Beneficiary/Inheritance email scam:
Subject: DEAR BENEFICIARY
Dubai Islamic Bank
P.O.Box 1080, Dubai
United Arab EmiratesDear Beneficiary
We wish to congratulate and inform you that after thorough review of your Inheritance/Contract funds transfer release documents in conjunction with the World Bank and the International Monetary Fund assessment report, your payment file was forwarded to us for immediate transfer of a part-payment of US$3,800,000.00(Three Million Eight Hundred Thousand United States Dollars) to your designated bank account from their offshore account with us.
The audit reports given to us, shows that you have been going through hard times to see to the release of your funds, which has been delayed by some dubious officials.
We therefore advice that you stop further communication with any correspondence outside this office.
Kindly reconfirm your details to enable us credit your account through online or by telegraphic transfer and send copies of the funds transfer release documents to you and your bankers for confirmation.
Should you follow our directives, your funds will be credited and reflect in your bank account within five (5) bank working days.
For further details and assistance on this Remittance Notification, kindly provide us with the below details:
FULL NAME AND AGE:
TELEPHONE AND MOBILE NUMBERS:
FULL CONTACT ADDRESSNagaraj Ramakrishnan
Chief Credit Officer,
Dubai Islamic Bank/EIB
Dubai, United Arab Emirates.
Screenshot of the Coronavirus-themed variant:

Text in this variant:
Subject: Dear beneficiary
Dear Friend,
I am pleased to write you this letter for the following reasons:- One
of my clients who died as a result of COVID-19 VIRUS in January, in His Will, left
for someone who bears your surname his entire Cash deposit valued Twenty
One Million Three Hundred Thousand Dollars (US$21,300,000.00). The
truth is that, l do not know if you are the beneficiary or not. l have
tried severally to locate the name on the will without success since l
have contacted you,
Can you please get back to me urgently if you are capable of investing
this fund for any profitable business in your Country, get back to me
for further explanation if you are interested. Please reply to the email below.
Regards
Barr. Tyrone Reid
Private Email: tyronereid@protonmail.com
Another variant of "Beneficiary/Inheritance" scam email:

Text presented within:
Subject: URGENT REPLY IS NEEDED FROM YOU
Attn: Beneficiary:
Congratulations!! Your payment has been approved and endorsed, with the instruction and approvals are given from the Authorities Due to the incessant scam activities going around the globe, the Authorities has instructed our Financial Institution to use high Performance in Banking System to set up a Personal Online Banking Account.
The sum of US$15,500,000.00 was deposited in our bank, The Management has resolved to open Personal On-line Banking Account for you with our bank and then give you the on-line access which will enable you to check and make electronics wire transfer out to any part of the world of your choice.
Kindly send the below information to enable us to set the account open for you.
Full Name:..................
Full Address:.........................
Direct Cellphone Number:..........
PASSPORT AND ID CARDS:.................
YOUR OCCUPATION.........
POSITION.........
DATE OF BIRTH..............Looking forward to your next letter
Regards
Thanks for banking with us,
Mr.Charles Goodman.
A/C Online Payment Officer,
US Capital Bank Branch North Carolina,
United States of America
Yet another variant of Beneficiary/Inheritance-themed spam email:

Text presented within:
Subject: Memo !
Attn: Beneficiary,
With due regards to your overdue contract/inheritance funds as
recovered and under the custody of the United Nations fund recovery
committee, thus, considering the overdue duration of your inability
to receive the funds.we write to you in respect of the amount which we have successfully
passed a payment mandate to the paying bank and they are ready to wire
Your payment of (Ten Million Five Hundred Thousand United States
Dollars) USD$10.5M into your receiving bank account.However, we advise you to forward your full names, Cell phone
number/WhatsApp number,Company name, position and address, banking
information and Copy of your int’l passport OR DRIVERS LICENSE to us.As soon as we receive all the requested information from you, we will
proceed with the transfer into your account.Yours faithfully,
Mr Edward Guckin
UN Debt Reconciliation.
Email:m.guckin@aol.com
Email:guckinedward62@gmail.com
Tel:+1 5137177979
Yet another example of Beneficiary/Inheritance-themed spam email:

Text presented within:
Subject: PAYMENT RELEASE INSTRUCTION FROM CITIBANK OF NEW YORK
CITIBANK INTERNATIONAL NEW YORK
DIRECTOR, FOREIGN OPERATIONS DEPARTMENT
ADDRESS: 87-11 Queens Boulevard, Elmhurst, NY 11373
From Desktop of Mrs. Charlotte Ferguson
Attention BeneficiaryI want to inform you that your outstanding payment of $14.5 Million US Dollars, which has been with our Central paying office from United Nations has been sign out for payment after series of meeting with our board of directors, We have already sent you two various notification mails as regarding to this New Development and it's surprising we haven't received any acknowledgement mail from you up till this time, I am sending you this mail again as a REMINDER and to have your consent as regarding to the Authorization Letter we received from United Nations, Also this payment will come to you via Bank Transfer, We want to conclude all payment as soon as possible. Below is the information required?
1) Full Name:
2) Full Address:
3) Your contact telephone and fax number:
4) Your Age and Profession:
5) Copy of any valid form of your Identification:
6) Your Bank name:
7) Your Bank Address:
8) Account name:
9) Account Number:
10) ABA/Routing Number:
11) Swift or Sort Code:Thanks and Congratulations I wait your urgent response.
Thanks and remain bless
DIRECTOR OF FUNDS CLEARANCE UNIT.
E-mail:msangelbenjamin@gmail.com
Yet another example of beneficiary-themed spam email:

Text presented within:
Subject: ATTENTION: Beneficiary
--
ATTENTION: Beneficiary.
I am writing to inform you that your compensation/winning payment via
ATM inter switch card was approved today by the Board and Directors of
the United Nation Committee on Rewards and Compensation.You are therefore advised to reconfirm your details to enable the
financial department to release your payment to you without any delay.Thus, reconfirm the following:
1. Your full name:
2. Your residential address:
3. Your direct phone number:We look forward to your prompt response.
Thank you.
Mr. Williams Brain
Director of Payment,
UN Foreign Office.
Yet another example of an email from "Beneficiary/Inheritance" spam campaign:

Text presented within:
Subject: Dear Sir,
From the Desk of:
Patrick Gill
Chief Remittance Officer,
Barclays Bank London
51 Berkeley St, London W1J 8NL, United Kingdom
Reference #: barc1//BKMD/TT/2023
Ref: LBA / ASSO / P01 / 5836/12/15 Tu Ref: MC / IFP / P02 / 2023
Dear Sir,My name is Herr Matt Hammerstein -.
A list of unclaimed estates held by the Treasury Solicitor. -Last updated 4th January 2023 .
I am the CEO, Barclays Bank London, UK. We would like to inform you that you have some inheritance funds discovered in our bank. This is the total sum of £ 16.5 million (sixteen million five hundred thousand British Pounds Sterling) in our bank.
We seek your immediate response as the beneficiary and present owner of this money so that the total sum £ 16.5 million british pounds will be paid to you.
All we need now is your cooperation, confidentiality in this transaction
and we guarantee that this transfer must be made in accordance with the provisions of the Banking Law of England.Send the below details to us .
1. Full Name:
2. Your direct mobile number:
3. Your contact address:
Herr Matt Hammerstein
From the Desk of:
Patrick Gill
Chief Remittance Officer,
Barclays Bank London
51 Berkeley St, London W1J 8NL, United Kingdom
Reference #: barc1//BKMD/TT/2023
Another example of beneficiary/inheritance-themed spam email:

Text presented within:
Subject: LETTER OF INTENT ACT FAST
International Monetary Fund/United Nations
Foreign Debt Settlement/Reconciliation
World Bank Headquarters
Our Ref: WB/IMF/UN/XX2023Dear Sir/Madam,
THE SUM OF $980,000.00 COMPENSATION APPROVED
This is to inform you that your delayed Inheritance/Contract Fund compensation sum of USD $980,000 Thousand US Dollars from the world Bank has been approved today for immediate payment into your nominated bank account unconditionally. The financial institute known as World Bank Group has been Mandated to effect immediate release of your payment through their remittance department after verification exercise. The World Bank and the (I.M.F) With other monetary agencies resolved this issue in our last meeting in Geneva and decided to pay off all pending debts without any delays. It's very urgent that you send us
your complete details requested below for immediate payment.The needed information's are:
(A) Your full Names
(B) Residential address:
(C) Telephone(Mobile):
(D) Nationality/Country:
(E) Your Email:
(F) Age/Sex:
(G) Occupation/Position:
(H) A scan of your International Passport or Driving License for proof of beneficiary.Kindly send us your details To Mrs.Rahayu Eka ( ekamrsrahayu@gmail.com ) Finally keep us posted once the above funds is received in your bank account.
Awaiting your prompt response.
Yours Sincerely,
Andrew Brown
Managing Director
International Monetary Fund
Another example of an email from "Beneficiary/Inheritance" spam campaign:

Text presented within:
Subject: Re: BUSINESS OPPORTUNITY..CONTACT ME NOW.
Reply to...gloconsult800@outlook.com
Dear Sir/Friend
My name is Kelvin Liu and I work as as Senior Auditor with Global Consult Investment Ltd here in Hong Kong and China Mainland. The late Mr. James Hansen, a successful business man who died with his children in their private plane crash on 30 November 2019, was my client. He left behind the sum of $60,000,000 (Sixty Million US D0llars) in an undisclosed bank and I am the only one authorized to produce a beneficiary to these funds since the late Mr. James Hansen did not state any next of kin to the funds during the time of deposit. I want you to partner with me so you can send your personal details to me and I will present you to the bank as the beneficiary to the funds as I will change the name in the documents to your name and the funds will now be transferred to you in your country where I will travel to meet with you so we can both invest there together in your choice of industry or specialization.
Kindly send the following details.
(A) Your Name in full....
(B) Your Age....
(C) Country....
(D) Male/Female....
(E) Mobile No....I await your urgent reply to this great opportunity.
Yours Faithfully,
Mr. Kelvin Liu
Senior Auditor
Global Consult Investment Ltd.
Hong Kong & China Mainland
Email: gloconsult800@outlook.com
Another example of inheritance-themed scam email:

Text presented within:
Subject: Re: THE 1NHER1TANCE..MUST READ MA1L 1NSIDE..
Reply-To: Ms. Joan R. Gates
Email: joangates66752@hotmail.com
Greetings to you.
I am Ms. Joan Robert Gates, Contact me for Y0UR INHER1TANCE of 16.5 Million USD. Now 1 am dying anytime soon. I have cancer of the lungs and I wish to give all my wealth to charity through you as the doctor says I have no chances of survival.Once again the following details is needed.
Your Full Name:
Your City & Country:
Your M0bile N0:
Your Age:
Waiting For Your Reply...
With Regards,
Ms. Joan R. Gates
Email: joangates66752@hotmail.com
Yet another example of an email from "Beneficiary/Inheritance" spam campaign:

Text presented within:
Subject: COMPLIMENTS!!!
ComplimentsI hope this letter finds you in good health. I am writing to you as an attorney representing the estate of my client, Late Adams, who passed away. My client left behind an estate, including various assets and investments, for which we are currently in the process of identifying the rightful heirs or beneficiaries.
During the initial stages of our investigation, it has come to our attention that there may be potential heirs or individuals who share the same surname as my client and may be entitled to claim the inheritance. Our diligent research has led us to discover your name and its possible connection to the inheritance in question due to the shared surname.
We understand that this may come as a surprise to you, and you may have questions or concerns regarding the inheritance. Please be assured that we are committed to handling this matter with the utmost discretion and professionalism. We seek to ensure that the inheritance is distributed in accordance with the law and my client's wishes, which is why we are reaching out to potential beneficiaries.
If you are indeed a relative or heir of Late Adams, we kindly request that you contact our law office as soon as possible to discuss this matter further. It is crucial that we verify your connection to the deceased and facilitate the necessary legal steps to ensure your rightful share of the inheritance.
Please note that we have taken all precautions to verify the legitimacy of potential heirs. We will require some documentation and information from you to establish your claim, such as identification documents, or other relevant evidence of your relationship to my client.
To discuss this matter in more detail, please contact our office via email at gordon.cole@gordoncole.co.uk and gcukesqoj@gmail.com
. Our team is available to address your inquiries and assist you throughout the process.To facilitate the process of this transaction, urgently forward to me
Your full names,
Telephone and fax numbers,
Address,
Age,
Marital status,
OccupationI will be expecting to hear from you.
Regards
Gordon Cole KC
Thank you for your cooperation, and we look forward to hearing from you soon.
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Types of malicious emails:
If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.
Credential theft Phishing emails
Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.
Common subject lines
- "Action required: confirm your account"
- "Your password expires today"
- "Unusual sign-in attempt detected"
- "Verify your billing information"
Malware delivery Emails with malicious attachments
Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.
Common subject lines
- "Invoice INV-2026-XXXX attached"
- "Fax received - 3 pages"
- "Your shipping document is ready"
- "Voicemail from +1-XXX-XXX-XXXX"
Extortion Sextortion emails
Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.
Common subject lines
- "I know your password is XXXX"
- "Your account has been hacked"
- "I have recorded you - 48 hours to pay"
- "You have been compromised"
Callback fraud Refund & callback scams
"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.
Common subject lines
- "Norton subscription auto-renewed - $499.99"
- "McAfee Total Protection invoice"
- "Geek Squad order confirmation"
- "Your PayPal payment is being processed"
Credential theft Account suspension & verification scams
"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.
Common subject lines
- "Your account will be deleted in 24 hours"
- "Suspicious activity detected - verify now"
- "Final warning: account closure"
- "Action required to keep your account active"
Mixed payload Delivery & package scams
Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.
Common subject lines
- "Your DHL package is held at customs"
- "USPS - delivery attempt failed"
- "FedEx tracking update - action required"
- "Pay $2.99 redelivery fee to release your parcel"
Remote access Tech support scams
Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.
Common subject lines
- "Microsoft Defender expired - renew now"
- "Apple ID security alert"
- "Critical: virus detected on your PC"
- "Windows license expired - call now"
Wire fraud Advance-fee scams
Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.
Common subject lines
- "Inheritance from a relative you didn't know about"
- "You won the international lottery"
- "URGENT - business proposal worth $XX million"
- "Compensation fund release for fraud victims"
Wire fraud Business email compromise (BEC)
CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.
Common subject lines
- "Quick task - need you to buy gift cards"
- "Updated banking details for invoice payment"
- "Wire transfer request - urgent"
- "Are you available?" (CEO impersonation opener)
How to spot a malicious email?
Check the sender's actual address, not the display name
The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:
- Domain mismatch -
service@paypa1.com,support@micros0ft-help.com, look-alike domains using digits or extra hyphens - Free-email impersonation - any "official" message from a bank, courier, or platform sent from a
@gmail.com,@outlook.com, or@yahoo.comaddress - Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.
Watch for urgency, threats, and generic greetings
Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:
- "Your account will be deleted in 24 hours"
- "Final notice" / "Immediate action required"
- "Dear Customer" or "Dear User" instead of your real name
- Threats of fines, account closure, legal action, or arrest
- Promises of refunds, prizes, or money you didn't earn
- Spelling and grammar mistakes in messages claiming to come from a major brand
Hover over every link before clicking
On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.
- Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
- Shortened URLs (
bit.ly,tinyurl,t.co) hide the real destination - never click them in unsolicited mail - The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.
Treat unexpected attachments as hostile
If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:
.exe,.scr,.iso,.img,.vbs,.bat- executables, never legitimate attachments.docx,.xlsx,.pptxwith "Enable macros" prompts - the macros run the malware.pdfwith "Click here to view" buttons - usually a phishing redirect, not a real document.zip,.rar,.7zarchives, especially password-protected ones - the password defeats the email scanner
If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.
Don't reply, don't click "unsubscribe"
Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.
Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.
Report the scam to your email provider and authorities
Inside your email client:
- Gmail: open the message → ⋮ menu → Report phishing
- Outlook / Outlook.com: ⋯ menu → Report → Report phishing
- Apple Mail / iCloud: Move to Junk, then forward to
reportphishing@apple.com
Forward or report to authorities:
After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.
Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.
You only clicked a link (didn't enter anything or download anything)
Close the page right away. Don't enter any information, even if the page looks legitimate.
- Clear your browser cache and cookies for the last hour - → Last hour → check Cookies and Cached files
- Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
- Update your browser to the latest version - most drive-by exploits target outdated browsers
- Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.
You opened an attachment or downloaded a file - run a full malware scan
Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:
Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.
Windows 11: → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.
Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.
Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.
Reboot to normal Windows. Open . Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.
VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.
Download Combo CleanerInstall Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.
Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.
Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:
Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.
Edge: edge://settings/reset. Then edge://settings/content/notifications.
Firefox: about:support → Refresh Firefox.
Open and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run and update browsers and applications.
If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).
You entered credentials on a fake login page
Assume the attacker has your password and is using it right now. Speed matters.
- Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
- Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
- Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
- Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
- Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
- Update security questions - the attacker may have seen the answers in your account profile.
If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.
You sent money or shared bank, card, or ID details
Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.
- Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
- If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
- If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
- File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
- File with the right authority for your country:
- US: ic3.gov + reportfraud.ftc.gov
- UK: reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
- Canada: antifraudcentre.ca
- Australia: scamwatch.gov.au
- EU: your national CERT or police cybercrime unit
- Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
- Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Final scan and startup-app check
Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.
Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.
Monitor accounts and credit for 30 days
Most fraud follow-ups land in the first month. Until that window closes, keep watching:
- Bank and card statements - daily for the first week, then weekly
- Email - watch for password-reset confirmations or login alerts you didn't trigger
- Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
- Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks
If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.
Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Most likely, scammers have sent this email to many addresses (all recipients have received the same letter). Most scammers use email addresses leaked after data breaches.
I have provided my personal information when tricked by this email, what should I do?
If you have provided sensitive information such as login credentials (usernames, IDs, passwords, etc.), change your passwords as soon as possible. In case you have provided your credit car details, ID card information, or other details, contact the corresponding authorities.
I have downloaded and opened a malicious file attached to an email, is my computer infected?
It depends on the file type. For example, executable files infect computers right after opening them. PDF, and MS Office documents do not inject malware unless additional steps are performed.
I have sent cryptocurrency to scammers, can I get my money back?
Crypto transactions are virtually untraceable. Therefore, it is very unlikely that you will be able to retrieve your funds.
I have read the email but didn't open the attachment, is my computer infected?
If you only read the email, then your computer is safe.
Will Combo Cleaner remove malware infections that were present in email attachment?
Yes, Combo Cleaner will remove malware from the operating system. It is capable of detecting almost all known malware. Note that high-end malware usually hides deep in the system. In such cases, running a full system scan is required to eliminate malware.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion