How to spot scams like Beneficiary/Inheritance phishing email

Phishing/Scam

Also Known As: Beneficiary/Inheritance spam

(updated)

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What is Beneficiary/Inheritance email scam?

Generally, scammers behind email scams such as this one attempt to trick recipients into believing that they are beneficiaries of a will, life insurance policy, etc. Scammers ask recipients to contact them and provide various information. At some point, recipients are asked to pay a processing fee or transfer charge.

Note that scammers exploit the names of existing, often well-known organizations and companies to make their emails seem legitimate.

Beneficiary/Inheritance email scam email spam campaign

More about the Beneficiary/Inheritance email scam

There are at least two variants of this email scam. One is disguised as a release of funds message claiming that the recipient is a beneficiary of 3,800,000.000 dollars.

Another one is disguised as a message regarding a will (testament) of a person who has died of COVID-19 and claiming that the recipient, who supposedly has an identical surname, is named as the beneficiary of 21,300,000.000 dollars.

In most cases, when recipients contact or reply to scammers behind these emails they are asked to provide personal, sensitive information such as credit card details or to transfer funds (as a processing fee, transfer charge, etc.).

I.e., scammers attempt to extort money or sensitive information, which can be used for malicious purposes (e.g., to make fraudulent purchases and transactions, and steal identities).

Threat Summary:
Name Beneficiary/Inheritance Email Scam
Threat Type Phishing, Scam, Social Engineering, Fraud.
Fake Claim Recipient is a eligible to receive distributions from a will or life insurance policy.
Disguise A message from the Dubai Islamic bank.
Symptoms Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer.
Distribution methods Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains.
Damage Loss of sensitive private information, monetary loss, identity theft.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Examples of similar scams

"United Nations Online Lotto Email Scam", "USAA Email Scam", and "You Received A Transfer In The Amount Email Scam" are examples of other email scams. Note that cyber criminals can use emails to extort money and sensitive information, and distribute malware (such as Agent Tesla, Urnsif, TrickBot, Adwind, etc.).

How do spam campaigns infect computers?

Ransomware and other malware infections are commonly spread through malspam campaigns, untrusted file/software download sources, fake (third party) software updating tools, Trojans and unofficial software activation tools. Using malspam, criminals send emails that have a malicious file attached, or include a website link designed to download a malicious file.

Their main goal is to trick recipients into executing the file, which then infects the computer with malware. Cyber criminals usually attach a Microsoft Office document, archive file (ZIP, RAR), PDF document, executable file (.exe) or JavaScript file, and wait until recipients open it.

Note that malicious MS Office documents can install malware only when users enable editing/content (macros commands). If the documents are opened with MS Office versions prior to 2010, however, the documents install malicious software automatically, since these older versions do not include "Protected View" mode.

Examples of untrusted file and software download sources are Peer-to-Peer networks (torrent clients), free file hosting websites, freeware download sites, and unofficial web pages. These are used to distribute malicious files by disguising them as legitimate and regular.

When users download and open (execute) the files, however, they inadvertently install malware. Fake software updating tools cause damage by installing malware rather than updates/fixes for installed software, or by exploiting bugs/flaws of outdated software.

Trojans are malicious programs that can cause chain infections by installing other software of this kind. Note that malware can only be distributed in this way if Trojans are already installed on computers.

Unofficial activation ('cracking') tools are illegal programs that supposedly activate licensed software free of charge and bypass activation, however, they often install other malicious programs instead.

How to avoid installation of malware

You are advised to research all software before download/installation. Use only official and verified download channels. Unofficial and free file-hosting websites, Peer-to-Peer sharing networks (BitTorrent, Gnutella, eMule), and other third party downloaders commonly offer harmful and bundled content, and are therefore untrusted and should be avoided.

When downloading/installing, read the terms, study all possible options, use the "Custom/Advanced" settings and opt-out of additional apps, tools, features, and so on. Intrusive advertisements typically seem legitimate, however, they can redirect to dubious and malicious sites (e.g. gambling, pornography, adult-dating, and many others).

If you encounter ads or redirects of this kind, inspect the system and remove all dubious applications and browser extensions/plug-ins immediately. If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Text presented in the Beneficiary/Inheritance email scam:

Subject: DEAR BENEFICIARY

Dubai Islamic Bank
P.O.Box 1080, Dubai
United Arab Emirates

Dear Beneficiary

We wish to congratulate and inform you that after thorough review of your Inheritance/Contract funds transfer release documents in conjunction with the World Bank and the International Monetary Fund assessment report, your payment file was forwarded to us for immediate transfer of a part-payment of US$3,800,000.00(Three Million Eight Hundred Thousand United States Dollars) to your designated bank account from their offshore account with us.

The audit reports given to us, shows that you have been going through hard times to see to the release of your funds, which has been delayed by some dubious officials.

We therefore advice that you stop further communication with any correspondence outside this office.

Kindly reconfirm your details to enable us credit your account through online or by telegraphic transfer and send copies of the funds transfer release documents to you and your bankers for confirmation.

Should you follow our directives, your funds will be credited and reflect in your bank account within five (5) bank working days.

For further details and assistance on this Remittance Notification, kindly provide us with the below details:

FULL NAME AND AGE:
TELEPHONE AND MOBILE NUMBERS:
FULL CONTACT ADDRESS

Nagaraj Ramakrishnan
Chief Credit Officer,
Dubai Islamic Bank/EIB
Dubai, United Arab Emirates.

Screenshot of the Coronavirus-themed variant:

beneficiary inheritance email scam covid-themed variant

Text in this variant:

Subject: Dear beneficiary

Dear Friend,
I am pleased to write you this letter for the following reasons:- One
of my clients who died as a result of COVID-19 VIRUS in January, in His Will, left
for someone who bears your surname his entire Cash deposit valued Twenty
One Million Three Hundred Thousand Dollars (US$21,300,000.00). The
truth is that, l do not know if you are the beneficiary or not. l have
tried severally to locate the name on the will without success since l
have contacted you,
Can you please get back to me urgently if you are capable of investing
this fund for any profitable business in your Country, get back to me
for further explanation if you are interested. Please reply to the email below.
Regards
Barr. Tyrone Reid
Private Email: tyronereid@protonmail.com

Another variant of "Beneficiary/Inheritance" scam email:

Beneficiary/Inheritance scam email (2020-12-09)

Text presented within:

Subject: URGENT REPLY IS NEEDED FROM YOU

 

Attn: Beneficiary:

Congratulations!! Your payment has been approved and endorsed, with the instruction and approvals are given from the Authorities Due to the incessant scam activities going around the globe, the Authorities has instructed our Financial Institution to use high Performance in Banking System to set up a Personal Online Banking Account.

The sum of US$15,500,000.00 was deposited in our bank, The Management has resolved to open Personal On-line Banking Account for you with our bank and then give you the on-line access which will enable you to check and make electronics wire transfer out to any part of the world of your choice.

Kindly send the below information to enable us to set the account open for you.

Full Name:..................
Full Address:.........................
Direct Cellphone Number:..........
PASSPORT AND ID CARDS:.................
YOUR OCCUPATION.........
POSITION.........
DATE OF BIRTH..............    

Looking forward to your next letter

Regards

Thanks for banking with us,

Mr.Charles Goodman.
A/C Online Payment Officer,
US Capital Bank Branch North Carolina,
United States of America

Yet another variant of Beneficiary/Inheritance-themed spam email:

Beneficiary/Inheritance-themed spam email (2021-04-12)

Text presented within:

Subject: Memo !

 

Attn: Beneficiary,

With due regards to your overdue contract/inheritance funds as
recovered and under the custody of the United Nations fund recovery
committee, thus, considering  the overdue duration of your inability
to receive the funds.

we write to you in respect of the amount which we have successfully
passed a payment mandate to the paying bank and they are ready to wire
Your payment of (Ten Million Five Hundred Thousand United States
Dollars) USD$10.5M into your receiving bank account.

However, we advise you to forward your full names, Cell phone
number/WhatsApp number,Company name, position and address, banking
information and Copy of your int’l passport OR DRIVERS LICENSE to us.

As soon as we receive all the requested information from you, we will
proceed with the transfer into your account.

Yours faithfully,

Mr Edward Guckin
UN Debt Reconciliation.
Email:m.guckin@aol.com
Email:guckinedward62@gmail.com
Tel:+1 5137177979

Yet another example of Beneficiary/Inheritance-themed spam email:

Beneficiary/Inheritance-themed spam email (2022-09-21)

Text presented within:

Subject: PAYMENT RELEASE INSTRUCTION FROM CITIBANK OF NEW YORK

CITIBANK INTERNATIONAL NEW YORK
DIRECTOR, FOREIGN OPERATIONS DEPARTMENT
ADDRESS: 87-11 Queens Boulevard, Elmhurst, NY 11373
From Desktop of Mrs. Charlotte Ferguson


Attention Beneficiary

I want to inform you that your outstanding payment of $14.5 Million US Dollars, which has been with our Central paying office from United Nations has been sign out for payment after series of meeting with our board of directors, We have already sent you two various notification mails as regarding to this New Development and it's surprising we haven't received any acknowledgement mail from you up till this time, I am sending you this mail again as a REMINDER and to have your consent as regarding to the Authorization Letter we received from United Nations, Also this payment will come to you via Bank Transfer, We want to conclude all payment as soon as possible. Below is the information required?


1) Full Name:
2) Full Address:
3) Your contact telephone and fax number:
4) Your Age and Profession:
5) Copy of any valid form of your Identification:
6) Your Bank name:
7) Your Bank Address:
8) Account name:
9) Account Number:
10) ABA/Routing Number:
11) Swift or Sort Code:

Thanks and Congratulations I wait your urgent response.

Thanks and remain bless


DIRECTOR OF FUNDS CLEARANCE UNIT.
E-mail:msangelbenjamin@gmail.com

Yet another example of beneficiary-themed spam email:

Beneficiary-themed spam email (2023-01-04)

Text presented within:

Subject: ATTENTION: Beneficiary

--
ATTENTION: Beneficiary.


I am writing to inform you that your compensation/winning payment via
ATM inter switch card was approved today by the Board and Directors of
the United Nation Committee on Rewards and Compensation.

You are therefore advised to reconfirm your details to enable the
financial department to release your payment to you without any delay.

Thus, reconfirm the following:

1. Your full name:
2. Your residential address:
3. Your direct phone number:

We look forward to your prompt response.

Thank you.

Mr. Williams Brain
Director of Payment,
UN Foreign Office.

Yet another example of an email from "Beneficiary/Inheritance" spam campaign:

Beneficiary/Inheritance email scam (2023-01-27)

Text presented within:

Subject: Dear Sir,

 

From the Desk of:
Patrick Gill
Chief Remittance Officer,
Barclays Bank London
51 Berkeley St, London W1J 8NL, United Kingdom
Reference #: barc1//BKMD/TT/2023

Ref: LBA / ASSO / P01 / 5836/12/15 Tu Ref: MC / IFP / P02 / 2023

Dear Sir,

My name is Herr Matt Hammerstein  -.
A list of unclaimed estates held by the Treasury Solicitor. -

Last updated 4th January 2023 .

I am the CEO, Barclays Bank   London, UK. We would like to inform you that you have some inheritance funds discovered in our bank. This is the total sum of £ 16.5 million (sixteen million five hundred thousand British Pounds Sterling) in  our  bank.

We seek your immediate response as the beneficiary and present  owner  of this money so that the total sum £ 16.5 million british pounds  will  be paid to you.

All we need now is your cooperation, confidentiality in this transaction
and we guarantee that this transfer must be made in accordance with the provisions of the Banking Law of England.

Send the  below  details  to  us .

1. Full Name:

2. Your direct mobile number:

3. Your contact address:

Herr Matt Hammerstein

From the Desk of:
Patrick Gill
Chief Remittance Officer,
Barclays Bank London
51 Berkeley St, London W1J 8NL, United Kingdom
Reference #: barc1//BKMD/TT/2023

Another example of beneficiary/inheritance-themed spam email:

Beneficiary/Inheritance Email Scam (2023-03-28)

Text presented within:

Subject: LETTER OF INTENT ACT FAST

 

International Monetary Fund/United Nations
Foreign Debt Settlement/Reconciliation
World Bank Headquarters
Our Ref: WB/IMF/UN/XX2023

Dear Sir/Madam,

THE SUM OF $980,000.00 COMPENSATION APPROVED

This is to inform you that your delayed Inheritance/Contract Fund compensation sum of USD $980,000 Thousand US Dollars from the world Bank has been approved today for immediate payment into your nominated bank account unconditionally. The financial institute known as World Bank Group has been Mandated to effect immediate release of your payment through their remittance department after verification exercise. The World Bank and the (I.M.F) With other monetary agencies resolved this issue in our last meeting in Geneva and decided to pay off all pending debts without any delays. It's very urgent that you send us
your complete details requested below for immediate payment.

The needed information's are:

(A) Your full Names
(B) Residential address:
(C) Telephone(Mobile):
(D) Nationality/Country:
(E) Your Email:
(F) Age/Sex:
(G) Occupation/Position:
(H) A scan of your International Passport or Driving License for proof of beneficiary.

Kindly send us your details To Mrs.Rahayu Eka ( ekamrsrahayu@gmail.com ) Finally keep us posted once the above funds is received in your bank account.

Awaiting your prompt response.

Yours Sincerely,
Andrew Brown
Managing Director
International Monetary Fund

Another example of an email from "Beneficiary/Inheritance" spam campaign:

Beneficiary/Inheritance email scam (2023-07-03)

Text presented within:

Subject: Re: BUSINESS OPPORTUNITY..CONTACT ME NOW.

 

Reply to...gloconsult800@outlook.com

Dear Sir/Friend

My name is Kelvin Liu and I work as as Senior Auditor with Global Consult Investment Ltd here in Hong Kong and China Mainland. The late Mr. James Hansen, a successful business man who died with his children in their private plane crash on 30 November 2019, was my client. He left behind the sum of $60,000,000 (Sixty Million US D0llars) in an undisclosed bank and I am the only one authorized to produce a beneficiary to these funds since the late Mr. James Hansen did not state any next of kin to the funds during the time of deposit. I want you to partner with me so you can send your personal details to me and I will present you to the bank as the beneficiary to the funds as I will change the name in the documents to your name and the funds will now be transferred to you in your country where I will travel to meet with you so we can both invest there together in your choice of industry or specialization.

Kindly send the following details.

(A) Your Name in full....
(B) Your Age....
(C) Country....
(D) Male/Female....
(E) Mobile No....

I await your urgent reply to this great opportunity.

Yours Faithfully,

Mr. Kelvin Liu
Senior Auditor
Global Consult Investment Ltd.
Hong Kong & China Mainland
Email: gloconsult800@outlook.com

Another example of inheritance-themed scam email:

Inheritance-themed spam email (2023-07-10)

Text presented within:

Subject: Re: THE 1NHER1TANCE..MUST READ MA1L 1NSIDE..

 

Reply-To: Ms. Joan R. Gates

Email: joangates66752@hotmail.com

Greetings to you.
 
I am Ms. Joan Robert Gates, Contact me for Y0UR INHER1TANCE of 16.5 Million USD. Now 1 am dying anytime soon. I have cancer of the lungs and I wish to give all my wealth to charity through you as the doctor says I have no chances of survival.

Once again the following details is needed.

Your Full Name:
Your City & Country:
Your M0bile N0:
Your Age:
Waiting For Your Reply...
With Regards,
Ms. Joan R. Gates
Email: joangates66752@hotmail.com

Yet another example of an email from "Beneficiary/Inheritance" spam campaign:

Beneficiary/Inheritance email scam (2024-01-11)

Text presented within:

Subject: COMPLIMENTS!!!


Compliments

 I hope this letter finds you in good health. I am writing to you as an attorney representing the estate of my client, Late Adams, who passed away. My client left behind an estate, including various assets and investments, for which we are currently in the process of identifying the rightful heirs or beneficiaries.

During the initial stages of our investigation, it has come to our attention that there may be potential heirs or individuals who share the same surname as my client and may be entitled to claim the inheritance. Our diligent research has led us to discover your name and its possible connection to the inheritance in question due to the shared surname.

We understand that this may come as a surprise to you, and you may have questions or concerns regarding the inheritance. Please be assured that we are committed to handling this matter with the utmost discretion and professionalism. We seek to ensure that the inheritance is distributed in accordance with the law and my client's wishes, which is why we are reaching out to potential beneficiaries.

If you are indeed a relative or heir of Late Adams, we kindly request that you contact our law office as soon as possible to discuss this matter further. It is crucial that we verify your connection to the deceased and facilitate the necessary legal steps to ensure your rightful share of the inheritance.

Please note that we have taken all precautions to verify the legitimacy of potential heirs. We will require some documentation and information from you to establish your claim, such as identification documents, or other relevant evidence of your relationship to my client.

To discuss this matter in more detail, please contact our office via email at gordon.cole@gordoncole.co.uk and  gcukesqoj@gmail.com
. Our team is available to address your inquiries and assist you throughout the process.

To facilitate the process of this transaction, urgently forward to me
Your full names,
Telephone and fax numbers,
Address,
Age,
Marital status,
Occupation

I will be expecting to hear from you.

Regards
Gordon Cole KC
Thank you for your cooperation, and we look forward to hearing from you soon.

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Types of malicious emails:

If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.

Credential theft Phishing emails

Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.

Common subject lines

  • "Action required: confirm your account"
  • "Your password expires today"
  • "Unusual sign-in attempt detected"
  • "Verify your billing information"
Example phishing email impersonating a major brand
Malware delivery Emails with malicious attachments

Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.

Common subject lines

  • "Invoice INV-2026-XXXX attached"
  • "Fax received - 3 pages"
  • "Your shipping document is ready"
  • "Voicemail from +1-XXX-XXX-XXXX"
Example email with a fake invoice attachment
Extortion Sextortion emails

Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.

Common subject lines

  • "I know your password is XXXX"
  • "Your account has been hacked"
  • "I have recorded you - 48 hours to pay"
  • "You have been compromised"
Example sextortion email demanding bitcoin payment
Callback fraud Refund & callback scams

"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.

Common subject lines

  • "Norton subscription auto-renewed - $499.99"
  • "McAfee Total Protection invoice"
  • "Geek Squad order confirmation"
  • "Your PayPal payment is being processed"
Example fake Norton or McAfee subscription renewal email
Credential theft Account suspension & verification scams

"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.

Common subject lines

  • "Your account will be deleted in 24 hours"
  • "Suspicious activity detected - verify now"
  • "Final warning: account closure"
  • "Action required to keep your account active"
Example fake account suspension email
Mixed payload Delivery & package scams

Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.

Common subject lines

  • "Your DHL package is held at customs"
  • "USPS - delivery attempt failed"
  • "FedEx tracking update - action required"
  • "Pay $2.99 redelivery fee to release your parcel"
Example fake DHL/USPS/FedEx delivery notification
Remote access Tech support scams

Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.

Common subject lines

  • "Microsoft Defender expired - renew now"
  • "Apple ID security alert"
  • "Critical: virus detected on your PC"
  • "Windows license expired - call now"
Example fake Microsoft or Apple tech support alert email
Wire fraud Advance-fee scams

Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.

Common subject lines

  • "Inheritance from a relative you didn't know about"
  • "You won the international lottery"
  • "URGENT - business proposal worth $XX million"
  • "Compensation fund release for fraud victims"
Example advance-fee or 419 scam email
Wire fraud Business email compromise (BEC)

CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.

Common subject lines

  • "Quick task - need you to buy gift cards"
  • "Updated banking details for invoice payment"
  • "Wire transfer request - urgent"
  • "Are you available?" (CEO impersonation opener)
Example business email compromise wire-transfer request

How to spot a malicious email?

Phase 1~ 2 min
Spot - identify the red flags

1

Check the sender's actual address, not the display name

30 sec

The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:

  • Domain mismatch - service@paypa1.com, support@micros0ft-help.com, look-alike domains using digits or extra hyphens
  • Free-email impersonation - any "official" message from a bank, courier, or platform sent from a @gmail.com, @outlook.com, or @yahoo.com address
  • Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Why this matters

Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.

2

Watch for urgency, threats, and generic greetings

30 sec

Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:

  • "Your account will be deleted in 24 hours"
  • "Final notice" / "Immediate action required"
  • "Dear Customer" or "Dear User" instead of your real name
  • Threats of fines, account closure, legal action, or arrest
  • Promises of refunds, prizes, or money you didn't earn
  • Spelling and grammar mistakes in messages claiming to come from a major brand
3

Hover over every link before clicking

30 sec

On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.

  • Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
  • Shortened URLs (bit.ly, tinyurl, t.co) hide the real destination - never click them in unsolicited mail
  • The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
Pro tip

When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.

4

Treat unexpected attachments as hostile

30 sec

If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:

  • .exe, .scr, .iso, .img, .vbs, .bat - executables, never legitimate attachments
  • .docx, .xlsx, .pptx with "Enable macros" prompts - the macros run the malware
  • .pdf with "Click here to view" buttons - usually a phishing redirect, not a real document
  • .zip, .rar, .7z archives, especially password-protected ones - the password defeats the email scanner
Phase 2~ 2 min
Report and delete - if you haven't engaged

If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.

5

Don't reply, don't click "unsubscribe"

30 sec

Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.

Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.

6

Report the scam to your email provider and authorities

1 min

Inside your email client:

  • Gmail: open the message → ⋮ menu → Report phishing
  • Outlook / Outlook.com: ⋯ menu → ReportReport phishing
  • Apple Mail / iCloud: Move to Junk, then forward to reportphishing@apple.com

Forward or report to authorities:

  • International: forward to reportphishing@apwg.org
  • United States: ic3.gov (FBI)
  • United Kingdom: forward phishing emails to report@phishing.gov.uk (NCSC SERS); for financial loss report at reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
  • Canada: antifraudcentre.ca
  • Australia: scamwatch.gov.au
  • EU: your national CERT - find yours via the ENISA CSIRT map

After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.

Phase 3~ 10–60 min
Recover - if you already engaged with the scam

Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.

7

You only clicked a link (didn't enter anything or download anything)

Scenario: clicked link only10 min

Close the page right away. Don't enter any information, even if the page looks legitimate.

  • Clear your browser cache and cookies for the last hour - Chrome/Edge: Ctrl+Shift+DelLast hour → check Cookies and Cached files
  • Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
  • Update your browser to the latest version - most drive-by exploits target outdated browsers
  • Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Why this matters

Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.

8

You opened an attachment or downloaded a file - run a full malware scan

Scenario: opened attachment⚠ Highest risk60–90 min

Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:

8.1Disconnect from the network

Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.

8.2Boot into Safe Mode with Networking, then download the scanners

Windows 11: Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.

Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.

Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.

8.3Run Microsoft Defender Offline

Reboot to normal Windows. Open Windows Security → Virus & threat protection → Scan options. Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.

Recommended antivirus
Combo Cleaner

VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.

Download Combo Cleaner
8.4Run a full Combo Cleaner scan

Install Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.

8.5Run Microsoft Safety Scanner as a second-opinion scan

Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.

8.6Reset browsers and clear notification permissions

Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:

Chrome: chrome://settings/resetRestore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.

Edge: edge://settings/reset. Then edge://settings/content/notifications.

Firefox: about:supportRefresh Firefox.

8.7Re-enable Defender, Tamper Protection, and update everything

Open Windows Security → Virus & threat protection → Manage settings and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run Settings → Windows Update → Check for updates and update browsers and applications.

Important

If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).

9

You entered credentials on a fake login page

Scenario: shared password⚠ Act fast20 min

Assume the attacker has your password and is using it right now. Speed matters.

  1. Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
  2. Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
  3. Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
  4. Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
  5. Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
  6. Update security questions - the attacker may have seen the answers in your account profile.
Why email comes first

If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.

10

You sent money or shared bank, card, or ID details

Scenario: financial loss⚠ Contact bank now30 min

Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.

  1. Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
  2. If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
  3. If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
  4. File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
  5. File with the right authority for your country:
  6. Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
  7. Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Phase 4~ 15 min + 30 days
Verify & monitor

11

Final scan and startup-app check

15 min

Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.

Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.

12

Monitor accounts and credit for 30 days

5 min/day · 30 days

Most fraud follow-ups land in the first month. Until that window closes, keep watching:

  • Bank and card statements - daily for the first week, then weekly
  • Email - watch for password-reset confirmations or login alerts you didn't trigger
  • Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
  • Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks

If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.

Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.

Frequently Asked Questions (FAQ)

Why did I receive this email?

Most likely, scammers have sent this email to many addresses (all recipients have received the same letter). Most scammers use email addresses leaked after data breaches.

I have provided my personal information when tricked by this email, what should I do?

If you have provided sensitive information such as login credentials (usernames, IDs, passwords, etc.), change your passwords as soon as possible. In case you have provided your credit car details, ID card information, or other details, contact the corresponding authorities.

I have downloaded and opened a malicious file attached to an email, is my computer infected?

It depends on the file type. For example, executable files infect computers right after opening them. PDF, and MS Office documents do not inject malware unless additional steps are performed.

I have sent cryptocurrency to scammers, can I get my money back?

Crypto transactions are virtually untraceable. Therefore, it is very unlikely that you will be able to retrieve your funds.

I have read the email but didn't open the attachment, is my computer infected?

If you only read the email, then your computer is safe.

Will Combo Cleaner remove malware infections that were present in email attachment?

Yes, Combo Cleaner will remove malware from the operating system. It is capable of detecting almost all known malware. Note that high-end malware usually hides deep in the system. In such cases, running a full system scan is required to eliminate malware.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate