How to recognize phshing scams like INTERNATIONAL MONETARY FUND (IMF)?

Phishing/Scam

Also Known As: INTERNATIONAL MONETARY FUND (IMF) spam

(updated)

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What is INTERNATIONAL MONETARY FUND (IMF) email scam?

The International Monetary Fund (IMF) is a legitimate financial institution, an international organization that promotes global economic growth, reduces poverty, encourages international trade. There is more than one email scam variant claiming to be authored by IMF officials.

Typically, scammers behind these bogus emails attempt to trick recipients into contacting the IMF for issuance of some form of approval, to receive a donation, or for other matters. In any case, the purpose of these emails is to deceive recipients into providing personal information or transferring money.

INTERNATIONAL MONETARY FUND (IMF) email scam

INTERNATIONAL MONETARY FUND (IMF) scam in detail

Scammers often use the names of real people, use actual company logos, addresses, etc., to make their hoaxes seem real. This is an email scam claiming to be a message from Kristalina Georgieva, the managing director of the International Monetary Fund.

Scammers behind it attempt to trick recipients into believing that they were selected to receive a donation from the IMF and into contacting them for more information. It is likely that after contacting the scammers, recipients will be asked to send personal banking details (such as credit card details), or make a small payment like a "transaction fee".

Typically, when scammers successfully obtain credit card details and other personal information, they use it to make fraudulent purchases and transactions, steal identities, hijack personal accounts, etc., or sell it to third parties (other cyber criminals).

Therefore, recipients who fall for these scams suffer monetary loss, cannot access their personal accounts, become victims of identity theft, and encounter other serious problems. This and other similar emails are simply scams - they should be ignored and reported.

Threat Summary:
Name INTERNATIONAL MONETARY FUND (IMF) Email Scam
Threat Type Phishing, Scam, Social Engineering, Fraud
Fake Claim Recipient has been selected to receive a donation
Disguise A letter from the managing director of the International Monetary Fund (IMF)
Symptoms Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer.
Distribution methods Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains.
Damage Loss of sensitive private information, monetary loss, identity theft.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Phishing scams in general

Plentu of email scams are circulating the internet. Some examples are "U.S Army Special Operations Command Consignment Email Scam", "EMPLOYEE BENEFITS Email Scam", and "Synchronize Mail Error Email Scam". They are often disguised as official messages from existing, legitimate companies or other entities, and ask for personal information, payments.

In fact, the emails can be used to deliver malware. In such cases, emails contain malicious links or attachments. Their main purpose is to deceive recipients into opening malicious files.

How do spam campaigns infect computers?

Malware (including ransomware) is usually distributed via malspam campaigns, unofficial software activation ('cracking') tools, Trojans, dubious file/software download sources, and fake software updating tools.

When cyber criminals attempt to distribute malware via malspam campaigns, they send emails that contain malicious attachments or download links for malicious files. Typically, they disguise their emails as official and important. If recipients open the attached file (or a file downloaded via a website link), they cause installation of malicious software.

Cyber criminals commonly attach executable files (.exe), archive files such as RAR, ZIP, PDF documents, JavaScript files and Microsoft Office documents to their emails. Software 'cracking' tools supposedly activate licensed software illegally (bypass activation), however, they often install malicious programs and do not activate any legitimate installed software.

Trojans are other rogue programs that can cause chain infections. I.e., when a Trojan is installed on the operating system, it can install additional malware.

Free file hosting websites, freeware download websites, Peer-to-Peer networks (e.g., torrent clients, eMule), unofficial websites, and third party downloaders are examples of other sources that are used to distribute malware. Cyber criminals disguise malicious files as legitimate and regular. When users download and open them, they inadvertently infect their computers with malware.

Fake software updating tools install malicious software rather than updates/fixes for installed programs, or they exploit bugs/flaws of outdated software that is installed on the operating system.

How to avoid installation of malware

Download software and files from official websites and via direct links. It is not safe to use torrent clients, eMule (or other Peer-to-Peer networks), third party downloaders, unofficial websites or other sources of this kind.

Avoid third party installers. Check "Advanced", "Custom" and other settings, and decline offers to download or install unwanted software. Do not click ads that are displayed on dubious websites, since they can open other untrusted websites or even cause unwanted downloads and installations.

Remove any unwanted, suspicious applications (extensions, add-ons, and plug-ins) that are installed on the browser. The same should be applied to programs of this kind that are installed on the operating system.

Regularly scan your computer with reputable antivirus or anti-spyware software and keep this software up to date.

If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Text presented in the email:

Subject: I.M.F Grant Recipient


INTERNATIONAL MONETARY FUND (IMF)
700 19th Street, N.W.
Washington, D.C. 20431,
U.S.A
 
Date: 19/02/2021
 
IMF OFFICIAL EMPOWERMENT GRANT AND DONATION PROGRAMME 2021
 
Dear Selected International Recipient,
 
REFERENCE NUMBER: IMF/WDC/1109/0320
 
We have selected you to receive a Donation from Us (I.M.F), email back for More Information.
 
FOR MORE INFORMATION:hxxps://www.imf.org/external/np/cpac/gandd.htm
 
Kindly confirm the receipt of this E-mail.
 
Yours in Service,
KRISTALINA GEORGIEVA
(MANAGING DIRECTOR)
INTERNATIONAL MONETARY FUND (I.M.F)

Other examples of INTERNATIONAL MONETARY FUND-themed spam emails:

Sample 1:

INTERNATIONAL MONETARY FUND email scam (2021-05-06)

Text presented within:

Subject: Directive from Dr Kristalina Georgieva the M D IMF, Please Contact Mr. Wilbur Autry for further Directives on your fund payment.

 

INTERNATIONAL MONETARY FUND (HQ1)
700 19th Street, N.W., Washington, D.C.
20431.
Email: wilburautry.imf@aol.com
Date: 4/5/2021

To the knowledge of the Beneficiary.

Re Payment of $5.2m
2021 UNPAID FUND RECOVERED LETTER
In our efforts to foster global monetary cooperation secures financial
stability and facilitates individual company economic growth.

The IMF through our international monitoring network has recovered
your UNPAID FUND $5.2m that has been on hold.

We hereby advise you to reconfirm to this office officially if you are
the person that instructed Mr. RAVIS RAY LUNN of America to claim and
receive the payment on your behalf before we send your fund transfer
instruction to one of our approved paying banks to contact you for the
release of your fund.

For your information we have the following banks as our
nominated/approved payment banks, Lloyd’s Bank London, Citibank New
York and CMB WING LUNG Bank Hong Kong.

Please, Re-confirm as follows
(1) Your Full Name........?
(2) Full Residential Address: (P.O.BOX NOT ALLOWED)?
(3) Country/State..........?
(4) Beneficiary Amount?
(5) Direct and Current Phone?
(6) Passport identification?

Please you are also required to clarify the following immediately:
1. IS Williams Rogers your local representative?
2. Did you broker your fund to one Mr. TRAVIS RAY LUNN of America to claim?
  And receive the payment on your behalf?

3. Did you sign any “Deed of Assignment” in his favor, thereby making
him the current beneficiary with the following account details to
receive your fund?

Mr. TRAVIS RAY LUNN
Address 55601 SWAN RD.SUNRIVER BEND, OREGON 97707
 USA
Account Name: TRAVIS RAY LUNN
Bank Name:  WELLS FARGO
Bank Address: 450 NE WINDY KNOLLS DR BEND,OR,97701
Beneficiary Account Number: 8210526748
Swift Code:WFBIUS6S
Routing Number for wire Transfer: 12100024

Please confirm so that we can proceed with your fund payment as we
don’t anticipate any further delay.

Contact Mr. Wilbur Autry.
Operation department for further Directive.
Email: wilburautry.imf@aol.com

Thank you and have a nice day.

Regards
Dr Ms. Kristalina Georgieva
Managing Director
IMF

Sample 2:

INTERNATIONAL MONETARY FUND (IMF) Email Scam (2022-02-02)

Text presented within:

Attention: Beneficiary

This is to officially notify you that International Monetary Fund
(IMF)/World Bank together with Coris Bank International is
compensating all the scam victims with the sum of US$500,000.00(Five
Hundred thousand United States Dollars) each and your email address
was found among the scam victims list that's why we are contacting
you. We have deposited your fund at the payment director/agent
location where the investigation started.

Contact Mr. Donald Mito payment Director with our office email:
(**********) Reconfirm the below information to him to
be sure of the person we are paying and to update your files, you can
as well reach him on mobile phone +228 70469666

1) Your Full Name:
2) Address, City, State and Country:
3) Personal Cell Phone, Fax and Mobile:
4) Company Name (If Any) Position And Address:
5) Occupation, Age and Marital Status:
6) Copy of Your Int'l Passport/Drivers License:

Upon the receipt of the above information more details will be given to you.

Yours Sincerely.

International Monetary Fund
Kristalina Georgieva
Current Managing Director
...............................................................

Attenzione: Beneficiario

Questo per informarti ufficialmente che il Fondo Monetario
Internazionale (FMI)/Banca Mondiale insieme a Coris Bank International
sta risarcindo tutte le vittime della truffa con la somma di US $
500.000,00 (cinquecentomila dollari statunitensi) ciascuna e il tuo
indirizzo email è stato trovato tra i elenco delle vittime della
truffa ecco perché ti stiamo contattando. Abbiamo depositato il tuo
fondo presso il direttore dei pagamenti/la sede dell'agente in cui è
iniziata l'indagine.

Contatta il Direttore dei pagamenti Mr. Donald Mito con la nostra
email di ufficio: (**********) Riconfermagli le
informazioni di seguito per essere sicuro della persona che stiamo
pagando e per aggiornare i tuoi file, puoi anche raggiungerlo sul
cellulare + 228 70469666

1) Il tuo nome completo:
2) Indirizzo, Città, Stato e Paese:
3) Cellulare personale, Fax e Mobile:
4) Nome dell'azienda (se presente) Posizione e indirizzo:
5) Professione, età e stato civile:
6) Copia del tuo passaporto internazionale/patente di guida:

Al ricevimento delle informazioni di cui sopra ti verranno forniti
maggiori dettagli.

Cordiali saluti.

Fondo monetario internazionale
Kristalina Georgieva
Attuale amministratore delegato

Sample 3:

INTERNATIONAL MONETARY FUND-themed spam email (2022-05-14)

Text presented within:

Subject: INTERNATIONAL GRANT (IMF) FOR -
                                                   
INTERNATIONAL MONETARY FUND (IMF)
700 1 Westfield Avenue, Stratford,
London. E20 1HZ
UK
 
IMF OFFICIAL EMPOWERMENT GRANT AND DONATION PROGRAMME 2022
Hello Grant Recipient -,
 
REFERENCE NUMBER: IMF/WDC/1109/0320
 
We have selected you to receive a Grant Cash Donation of $1,550,000.00 USD.
FOR MORE INFORMATION: Kindly Reply via email: imfintmonetaryfund@icloud.com and Send your Reference Number
(IMF/WDC/1109/0320) for Confirmation via Whats-App Message to I.M.F Public Relations Center:+44 7377 170359.

 
Thanks for your Understanding.
Yours in Service,
KARINA OKAJIMA
(MANAGING DIRECTOR)
INTERNATIONAL MONETARY FUND

© 2022 INTERNATIONAL MONETARY FUND. ALL RIGHTS RESERVED.

Sample 4:

INTERNATIONAL MONETARY FUND (IMF) email scam (2022-06-13)

Text presented within:

Subject: I.M.F GRANT REFERENCE

 
--

INTERNATIONAL MONETARY FUND (IMF)
700 19th Street, N.W.
Washington, D.C. 20431, U.S.A
Date: 09/06/2022

Dear Lithuanian Grant Recipient,
We have selected you to receive a Grant Cash Donation of $1,550,000.00 USD.

FOR MORE INFORMATION: Kindly Reply via email and Send your Grant Reference Number :(IMF/WDC/334/0288/2022) for Confirmation via Whats App Message to I.M.F Public Relations Center: +1 619 485 6806.

Thanks for your Understanding.

Yours in Service,
KRISTALINA GEORGIEVA
(MANAGING DIRECTOR)

Sample 5:

INTERNATIONAL MONETARY FUND (IMF) email scam (2022-09-13)

Text presented within:

Subject: [Spam]Free - IMF Empowerment Grant

 

INTERNATIONAL MONETARY FUND (IMF)
700 19th Street, N.W.
Washington, D.C. 20431, U.S.A

Date: 9/10/2022

IMF EMPOWERMENT GRANT AND DONATION

Dear -,

REFERENCE: IMF/WDC/0288/1022

You have been selected to receive our individual empowerment grant.

For more information, kindly reply via email and send your reference (IMF/WDC/0288/1022) for confirmation via WhatsApp message to the IMF Public Relations Center +1 (808) 213-7133.

Yours in service,
Kristalina I. Georgieva-Kinova
Managing Director, International Monetary Fund (IMF)

Sample 6:

INTERNATIONAL MONETARY FUND (IMF) spam email (2022-10-12)

Text presented within:

INTERNATIONAL MONETARY FUND (IMF)
700 19th Street, N.W.
Washington, D.C. 20431,
U.S.A.

The IMF and COVID-19 Financial Grant October 2022

REFERENCE: IMF/CVD19/1089/2072

The IMF has responded to the COVID-19 crisis by quickly deploying financial assistance, developing policy advice and creating special tools to assist individuals in it's member countries. The IMF is providing financial assistance and debt service relief to individuals in it's member countries facing the economic impact of the COVID-19 pandemic.

You have been selected to receive The IMF and COVID-19 Financial Grant for the month of October 2022. Email back for more information.

Email: scott@imfempowerfun.com  and send your reference for confirmation via whatsapp message (+1 213-566-9047)

Kindly confirm the receipt of this e-mail.

Yours in service,
Ceda Ogada
Secretary of the Fund
Secretary’s Department Director
INTERNATIONAL MONETARY FUND (I.M.F).

© 2022 INTERNATIONAL MONETARY FUND. ALL RIGHTS RESERVED.

Sample 7:

International Monetary Fund (IMF)-themed scam email (2022-10-31 - sample 1)

Text presented within:

Subject: Fund+

 

OFFICE OF THE DIRECTOR GENERAL, INTERNATIONAL MONETARY FUND.
IMF Headquarters: 7001 19th Street, 20219-001
N.W, Washington D. C. 20413,
United States of America.


Our Ref: IMF/FGN/RMB/088/2022
Internal Memo Urgent!

Attn: Beneficiary,

SUB-FUND TRANSFER NOTIFICATION: INTERNATIONAL MONETARY FUND (IMF) DEBT SERVICING
EXERCISE.

Sequel to the meeting we had with the African and European country leaders in
the recent Mexico world G20B summit in regards to the payments been owed by the
Africa,America,Asia and Europe continents, the Chairman of African Union(AU) and
that of the European Union (EU) have made it known to all the beneficiaries been
owed via Contracts, Inheritance, Lottery, during their recent interview with
United Nation overdue contract payment commission that all the debts been owed
by the Africans and Europeans should be paid to them via AU and EU accounts
with the supervision of the bank of International settlement (BIS) here in the
United States which you happened to be one of the beneficiary confirmed for this
payment settlement.

Also In accordance with the payment verification and auditing exercise carried
out by the UK Debt Servicing Unit of the World Bank, (W.B) and the International
Monetary Fund (IMF) in conjunction with the European Union(EU), It has been
brought to the knowledge of the Controller General, International Monetary Fund
that your outstanding valued at US$4,500.000.00(Four Million Five Hundred
Thousand United States Dollars) only has been deposited for immediate transfer
with the SOUTH AFRICAN RESERVE BANK and has been approved for urgent payment to
your receiving bank account through their International remittance unit.

We issue this last notification to you on this development since we were unable
to reach you with the payment Details, as you are advised to contact the SOUTH
AFRICAN RESERVE BANK, International Remittance Unit.

Attn: Mr. Fred Malusi on Direct Tel: +27 748476701 Email:
fredmalusi@executivemail.co.za, with this payment Ref N0:BBYUK/REG1958755 for
the transfer conclusion.

This avenue has been created by the United Nations (EU) & (AU) on
Foreign debt Reconciliation Commission to offset all the outstanding foreign
payments on-hold in order to rehabilitate the lost dignity of the EU, AU &
Others.

The international Monetary Fund (IMF) remains communicated to our
financial principles through the above contact details. We hope you will benefit
from our team of experts. We assure you the best of our services at all times
assuring you of this payment transfer legitimacy.

Congratulation,

Yours Faithfully,
Kristalina Georgieva(Managing Director (IMF).

Sample 8:

International Monetary Fund (IMF)-themed scam email (2022-10-31 - sample 2)

Text presented within:

Subject: Do not take this message as a junk message.


OFFICE OF THE DIRECTOR GENERAL, INTERNATIONAL MONETARY FUND.
IMF Headquarters: 7001 19th Street, 20219-0001 USA*FRBK*WDC*010/22
N.W., Washington D. C. 20413, United States of  America.
Our Ref: IMF/FGN/RMB/088/2022  

Internal Memo Urgent.

ATTN: Beneficiary Contractor/Next of Kin “

With African/ European/Asian/ Country         

SUB-US$1,227,000.00 PAYMENT NOTIFICATION: INTERNATIONAL MONETARY FUND (IMF) DEBT SERVICING EXERCISE

EFT APPROVAL :   VERIFY DEAL MY2KXXX4665433821/1000043550000077
ELECTRONIC FUNDS TRANSFER: 4083 0521 0038 4356        OPERATOR N0: 037899
DEAL RECEIPT – FOREIGN CURRENCY TRF BROUGHT  - CALL   EFT  ACCOUNT
Deal Date : 2/8/2022  1ш 2шш       Value Date:7/8/2022        
TRO5244075994Q09  Total Amount For Transfer   : US$1,227,000.00

Sequel to the recent Corona-Virus Pandemic and the meeting we had with the African & European country leaders in the recent G20 Summit in regards to the payments been owed by the African and Europe continents, the Chairman of African Union (AU) and the European Union (EU) have made it known to all the beneficiaries been owed via Contracts/Inheritance Payments, During their recent interview with United Nations Overdue Payment Commission that all the debts been owed by the Africans/Europeans Union should be paid to them via IMF/OCC accounts  with  the  supervision of  the  IMF  and  The bank of International settlement (BIS) which you happened to be one of the Beneficiary confirmed for this Urgent payment settlement.

Also In accordance with the payment verifications and auditing exercise carried out by the African Debt Servicing Unit and the International Monetary Fund (IMF) in conjunction with the African and European Union (EU), it has been brought to the knowledge of the Comptroller General,  International  Monetary  Fund  that  your  outstanding  payment Compensation valid US$1,227,000.00 (One Million, Two Hundred & Twenty Seven Thousand United States Dollars) only has been deposited for immediate Payment with the South African Rand Merchant Bank and has been approved for urgent Online payment transfer in your name immediately.

We issue this last notification to you on this development Since We Were Unable To Reach You With The Payment Details,  you  are  advised  to  contact  the  Rand  Merchant  Bank  south Africa, International Remittance Unit, 'Attn: Mr. James Formby on Direct Tel:+27-710927585 email: ( rmbdannybates@citromail.hu ) with payment Ref: MY2KXX4665433821/1000043550000077 for the Payment conclusion.

This  avenue  has  been  created  by  the  United  Nations  (EU)  &  (AU)  on  Foreign  debt Reconciliation Commission to offset all the outstanding foreign payments on-hold in order to rehabilitate the lost dignity of the EU & AU African states.

The international Monetary Funds (IMF) remains communicated to our  financial principles through the above contact details.  We hope you will benefit from our team of experts.  We assure you the best of our services at all times assuring you of this payment transfer conclusion.

PAYMENT REFN0 : YUK/REG1958755

Yours Faithfully,

Mrs. Kristalina Georgieva
Managing Director
International Monetary Fund
Washington, D.C. 20431, U.S.A

Sample 9:

INTERNATIONAL MONETARY FUND (IMF)-themed spam email (2022-11-22)

Text presented within:

Subject: Scam Victims!

 

Dear email owner,


The International Monetary Fund (IMF) compensates all victims of fraud
and your email address was found on the list of victims of fraud.

This Western Union office has been hired by the IMF to transfer your
compensation to you via Western Union Money Transfer.

However, we have decided to make your own payment through Western
Union Money Transfer, $5,000 per day until the total of $5,000.000,00,
has been transferred to you in full.

We may not be able to send the payment with your email address alone,
so we need your information's on where we will send the money to you,
Such as:

Name of the addressee________________

Address________________

Country__________________

Telephone number________________

Attached copy of your ID_____________

Age ________________________


We will start the transfer once we have received your Information:
Contact E-mail: (wsternunion844@gmail.com)

Faithfully,
Mr. Anthony Duru

1 (605) 453-2941

Director of Western Union Money Transfer

Sample 10:

INTERNATIONAL MONETARY FUND (IMF)-themed spam email (2022-12-06)

Text presented within:

Subject: APPROVAL NOTICE


ATTENTION

You are among those whose pending payment has been approved by the INTERNATIONAL MONETARY FUND (IMF) in conjunction with the WORLD BANK. The release of your fund has been delayed either as a result of your dealing with unauthorized individuals or unawareness of your current fund and its value. You are advised to stop further communication with anybody or institution regarding the payment.

Note that these funds constitute unpaid Insurance, Pension, Contract sums, Inheritance/next of kin and Lottery beneficiaries that originated from Europe, Asia Plus Middle East, America and Africa. Be notified then You are among the list of individuals and companies whose unpaid funds have been approved for payment under the supervision of the International Monetary Fund Headquarters here in Washington, DC USA.

We request that you contact this office within 48 hours of receiving this notification.

On contacting us, please confirm your full name and contact telephone number to enable us to normalize the documents in your name and advise you on how to make your claim.

Yours faithfully,
Dr. Robert Carter
Coordinator, International Settlement Unit
Tel: +1 202 7737588

Sample 11:

INTERNATIONAL MONETARY FUND (IMF) email scam (2023-03-08)

Text presented within:

Subject: Call/text +1(862)227-1973

INTERNATIONAL MONETARY FUND {IMF} OFFICE
IMF Headquarters. 700 19th Street, N.W
Phone:+1(862)227-1973
Website:www.imf.org.
C/O Kristalina Georgieva
E-mail:kristalina.georgieva@outlook.com.
In Affiliation with West African Economic
and Monetary Union (WAEMU).

Attention Beneficiary;
Your Long overdue Payment Is Ready:

It came to our notice today that your long overdue unpaid contracts inheritance fund, next of kin and lotto benefits that was originated from Africa, Europe, Asia Plus Middle east and American is among the list of individuals and companies that your unpaid fund has been located to the CITY BANK LONDON, UNITED KINGDOM. Your email appeared among the beneficiaries, who will receive a part-payment of your contractual sum and has been approved already for months now. You are requested to get back to us for more direction and instruction on how to receive your fund. However, we received an email from one Mr.Robert Dean Randolph who told us that he is your next of kin and that you died in a car accident last week.He has also submitted his account for us to transfer the fund to him including his International passport. we want to hear from you before we can make the transfer to confirm if you are dead or not. Please in
confirmation that you are still alive, you are advised to reconfirm the below listed information to enable us facilitate an immediate payment for you.

1 Your full names
2 Your present contact address.
3 Your telephone & Fax numbers.
4 Your Occupations/age/sex.
5 Your Private Email Address.
6 Home Equity (Yes or No)


Once again, We apologize to you on behalf Of IMF (International Monetary Fund) for the delays on paying your funds, which according to records in the system had been long overdue. You can contact the IMF director/chairperson Ms. Kristalina Georgieva on her E-mail:(kristalina.georgieva@outlook.com).

Yours Sincerely,
Kristalina Georgieva
Chairperson/Director IMF,
IMF Headquarters.700 19th Street, N.W
+1(862)227-1973
www.imf.org.

Sample 12:

INTERNATIONAL MONETARY FUND (IMF) scam email (2023-03-14)

Text presented within:

Subject: CONGRATULATION

 

INTERNATIONAL MONETARY FUND (IMF)
700 19th Street, N.W.
Washington, D.C. 20431,
U.S.A.

The IMF Financial Grant 2023
REFERENCE: IMF/REL23/1069/2092

The IMF has responded to the world financial crisis by quickly deploying financial assistance, developing policy advice and creating special tools to assist individuals in its member countries. The IMF is providing financial assistance, a Business relief fund,grant and debt service relief to individuals in its member countries facing the economic impact,financial recession and debt worldwide.

You have been selected to receive The IMF Financial Grant for the year 2023.Payment amount is determined by each beneficiary's credit score and you are advised to choose between the listed amount ;

1,$10.000-$50.0000
2,$50.000-$100.000
3,$100.000- $500.000
4,$500.000-$1 000.000
5.Above $1m

Your approval reference number is (IMF/REL23/1069/2092)

Message the Payment Manager,Mr John Bretton on 209-779-0764 ( 1 209-779-0764) and via whatsapp message , *Drop* your approval reference number *your account* *number and contact information .

Send your reference for confirmation via whatsapp message 209-779-0764 ( 1 209-779-0764)  with chosen amount and follow winning instructions to receive your fund.

Congratulations.

Yours in service,

Ceda Ogada
Secretary of the Fund
Secretary’s Department Director
INTERNATIONAL MONETARY FUND (I.M.F).

© 2023 INTERNATIONAL MONETARY FUND. ALL RIGHTS RESERVED.

Sample 13:

INTERNATIONAL MONETARY FUND (IMF) email scam (2023-08-22)

Text presented within:

Subject: Overdue Payment

 

--
INTERNATIONAL MONETARY FUND (IMF)
International Settlement Unit,
1900 Pennsylvania Avenue NW, Washington, DC 20431, United States
Tel: +1 202 7737588

Attn: Beneficiary

This is to inform you that you are among those whose pending payment
has been approved by the International Monetary Fund (IMF) in
conjunction with the World Bank Group (WBG), this decision was taken
at the 2023 Spring Meetings of the World Bank Group (WBG) and the
International Monetary Fund (IMF) which was held from Monday, April 10
to Sunday, April 16 in the WBG and IMF headquarters, in Washington DC.

The fund release has been delayed as a result of your dealings with
unauthorized individuals, so you are advised to stop every
communication with anybody/institution regarding the payment. These
funds originated from unpaid contract sums, inheritance/next of kin
and lottery beneficiaries that originated from Europe, Asia Plus
Middle East, America and Africa. You are among the list of individuals
and companies whose unpaid funds have been approved for payment under
the supervision of the International Monetary Fund Headquarters here
in Washington, DC USA.

We do hereby ask you to contact this office within 48 hours of
receiving this notification. Please reconfirm your full name and
contact telephone number to enable us to normalize the documents in
your name and to advise you on how to make your claim.

Yours faithfully,
Dr. Robert Carter
Coordinator, International Settlement Unit

Sample 14:

INTERNATIONAL MONETARY FUND (IMF) email scam (2023-09-05)

Text presented within:

Subject: IMF/WBG Grant - ******** has be selected Congrats

Dear Grant Recipient ********,
 
REFERENCE NUMBER: IMFWB0WM738Q

We would like to extend our congratulations to you on being selected as the recipient of the IMF/WBG Grant Donation of $2,550,000.00 USD.
This program aims to enhance public health interventions and help the private sector continue to function and maintain jobs.
The World Bank Group and the International Monetary Fund are providing up to $160 billion in financing tailored to the health,
economic, and social shocks countries are facing. This includes $50 billion of IDA resources on grant and highly concessional terms.
This fund is intended to help you support your family, including your business.

1. Your Full Name

2. Home Address

3. Office Address

4. Country of Origin
5. Age

6. Occupation.

Please if you have received any WORLD BANK GROUP AND INTERNATIONAL MONETARY FUND Intervention fund previously kindly indicate and state the amount.

FOR MORE INFORMATION:
Kindly Reply with Your above Ref No. via email imfandwbprogramscheme@gmail.com.

Regards

Yours in Service,
JOSE VELILLA
(GRANT OFFICER)
WORLD BANK GROUP AND INTERNATIONAL MONETARY FUND

Sample 15:

INTERNATIONAL MONETARY FUND (IMF) email scam (2023-09-19)

Text presented within:

Subject: COMPENSATION SETTLEMENT OF ESCROW ACCOUNTS US$6,000,000.00


INTERNATIONAL MONETARY FUND (IMF)
Address: 700 19th Street, N.W.
Washington, D.C. 20431, USA
 
COMPENSATION SETTLEMENT OF ESCROW ACCOUNTS US$6,000,000.00
 
It is a pleasure to write you that we have reconciled with our logistic department on the reimbursement of some fund spent by you during the cause of your inadequate dealings with some imposters who claim to be staff in banks and other regional payment centers.
 
Our reconciliation teams with the prospectus instrument of the United Nations after freezing suspected imposters account. This support was fully effective with the help of World Bank after a summit meeting in United States, ?the financial analysis on financial stability issues fluctuating their economy with the international global standard.
 
After gathering of this sum, our logistic department gave us a list of customers to be paid who fall victims to this imposters due to unawareness. And mode of payment was as well specified for proper conducts and financial regulations to kick against criminality during process of payment.
 
We have arranged your payment through our swift card centers, which is the latest instruction from International Monetary Fund Reconciliation Office. The card center will send you an ATM Debit card which you will use to withdraw your money in any ATM Center, Banks and Union Pay Credit outlets in the world, You are hereby selected as an honor for this payment approval, which you are to acknowledge the receipt of this mail in returning the required below to the Logistic Department by email listed below.
 
Office of Reconciliation and Logistics Vaults, International Monetary Fund (IMF),
 
Contact Manager: Rowland Garett
Email: rowlandgarett4life@gmail.com
 
1. Full Name:
2. Phone and Fax Number:
3. Your age and Current Occupation:
4. Contact Address where you want your ATM Card to be delivered to (P.O Box Not Acceptable):
 
For your information, you have to stop any further communication with any other person (s) or office (s) to avoid any hitches in receiving your payment.
 
Because of Impostors, we hereby issued you our code of conduct, which is (ATM-745) so you have to indicate this code when contacting the Card Center by using it as your subject.
 
Yours in Service,
Kristalina Georgieva,
Director of the Finance Department
International Monetary Fund

Sample 16:

INTERNATIONAL MONETARY FUND (IMF) email scam (2024-03-01)

Text presented within:

Subject: ACKNOWLEDGEMENT

 

Attn: Fund recipient,

We have been authorized by the European investment bank London and the IMF to investigate the reason for unnecessary deferral funds that have been approved by law. During Our investigation, we found out that your payment was Delayed by corrupt officials of some banks who tried to redirect your funds to their personal Accounts.

In order to stop this dubious act, we have agreed with the European investment bank of London and  the International Monetary Fund(IMF), we are able to handle this payment and monitor it. Avoid hopeless situations with banks and other organs of the authorities In criminal proceedings.

We have received an irrevocable payment guarantee for your payment from the Imf. We would like to inform you that the European investment bank has decided to compensate you with the sum of $1,000,000,00 and transfer it to your bank account via Wire Transfer.

contact our correspondent bank secretary Mrs.Rose James with the email address below.officialrosejames3@gmail.com

Be sure to contact the above bank without any delay for the final release and transfer of your fund. The European Investment Bank must be sure to transfer your funds to your bank account without delay.

We assume your urgent cooperation.

Thank you.

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Types of malicious emails:

If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.

Credential theft Phishing emails

Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.

Common subject lines

  • "Action required: confirm your account"
  • "Your password expires today"
  • "Unusual sign-in attempt detected"
  • "Verify your billing information"
Example phishing email impersonating a major brand
Malware delivery Emails with malicious attachments

Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.

Common subject lines

  • "Invoice INV-2026-XXXX attached"
  • "Fax received - 3 pages"
  • "Your shipping document is ready"
  • "Voicemail from +1-XXX-XXX-XXXX"
Example email with a fake invoice attachment
Extortion Sextortion emails

Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.

Common subject lines

  • "I know your password is XXXX"
  • "Your account has been hacked"
  • "I have recorded you - 48 hours to pay"
  • "You have been compromised"
Example sextortion email demanding bitcoin payment
Callback fraud Refund & callback scams

"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.

Common subject lines

  • "Norton subscription auto-renewed - $499.99"
  • "McAfee Total Protection invoice"
  • "Geek Squad order confirmation"
  • "Your PayPal payment is being processed"
Example fake Norton or McAfee subscription renewal email
Credential theft Account suspension & verification scams

"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.

Common subject lines

  • "Your account will be deleted in 24 hours"
  • "Suspicious activity detected - verify now"
  • "Final warning: account closure"
  • "Action required to keep your account active"
Example fake account suspension email
Mixed payload Delivery & package scams

Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.

Common subject lines

  • "Your DHL package is held at customs"
  • "USPS - delivery attempt failed"
  • "FedEx tracking update - action required"
  • "Pay $2.99 redelivery fee to release your parcel"
Example fake DHL/USPS/FedEx delivery notification
Remote access Tech support scams

Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.

Common subject lines

  • "Microsoft Defender expired - renew now"
  • "Apple ID security alert"
  • "Critical: virus detected on your PC"
  • "Windows license expired - call now"
Example fake Microsoft or Apple tech support alert email
Wire fraud Advance-fee scams

Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.

Common subject lines

  • "Inheritance from a relative you didn't know about"
  • "You won the international lottery"
  • "URGENT - business proposal worth $XX million"
  • "Compensation fund release for fraud victims"
Example advance-fee or 419 scam email
Wire fraud Business email compromise (BEC)

CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.

Common subject lines

  • "Quick task - need you to buy gift cards"
  • "Updated banking details for invoice payment"
  • "Wire transfer request - urgent"
  • "Are you available?" (CEO impersonation opener)
Example business email compromise wire-transfer request

How to spot a malicious email?

Phase 1~ 2 min
Spot - identify the red flags

1

Check the sender's actual address, not the display name

30 sec

The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:

  • Domain mismatch - service@paypa1.com, support@micros0ft-help.com, look-alike domains using digits or extra hyphens
  • Free-email impersonation - any "official" message from a bank, courier, or platform sent from a @gmail.com, @outlook.com, or @yahoo.com address
  • Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Why this matters

Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.

2

Watch for urgency, threats, and generic greetings

30 sec

Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:

  • "Your account will be deleted in 24 hours"
  • "Final notice" / "Immediate action required"
  • "Dear Customer" or "Dear User" instead of your real name
  • Threats of fines, account closure, legal action, or arrest
  • Promises of refunds, prizes, or money you didn't earn
  • Spelling and grammar mistakes in messages claiming to come from a major brand
3

Hover over every link before clicking

30 sec

On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.

  • Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
  • Shortened URLs (bit.ly, tinyurl, t.co) hide the real destination - never click them in unsolicited mail
  • The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
Pro tip

When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.

4

Treat unexpected attachments as hostile

30 sec

If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:

  • .exe, .scr, .iso, .img, .vbs, .bat - executables, never legitimate attachments
  • .docx, .xlsx, .pptx with "Enable macros" prompts - the macros run the malware
  • .pdf with "Click here to view" buttons - usually a phishing redirect, not a real document
  • .zip, .rar, .7z archives, especially password-protected ones - the password defeats the email scanner
Phase 2~ 2 min
Report and delete - if you haven't engaged

If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.

5

Don't reply, don't click "unsubscribe"

30 sec

Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.

Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.

6

Report the scam to your email provider and authorities

1 min

Inside your email client:

  • Gmail: open the message → ⋮ menu → Report phishing
  • Outlook / Outlook.com: ⋯ menu → Report → Report phishing
  • Apple Mail / iCloud: Move to Junk, then forward to reportphishing@apple.com

Forward or report to authorities:

  • International: forward to reportphishing@apwg.org
  • United States: ic3.gov (FBI)
  • United Kingdom: forward phishing emails to report@phishing.gov.uk (NCSC SERS); for financial loss report at reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
  • Canada: antifraudcentre.ca
  • Australia: scamwatch.gov.au
  • EU: your national CERT - find yours via the ENISA CSIRT map

After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.

Phase 3~ 10–60 min
Recover - if you already engaged with the scam

Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.

7

You only clicked a link (didn't enter anything or download anything)

Scenario: clicked link only10 min

Close the page right away. Don't enter any information, even if the page looks legitimate.

  • Clear your browser cache and cookies for the last hour - Chrome/Edge: Ctrl+Shift+Del → Last hour → check Cookies and Cached files
  • Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
  • Update your browser to the latest version - most drive-by exploits target outdated browsers
  • Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Why this matters

Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.

8

You opened an attachment or downloaded a file - run a full malware scan

Scenario: opened attachment⚠ Highest risk60–90 min

Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:

8.1Disconnect from the network

Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.

8.2Boot into Safe Mode with Networking, then download the scanners

Windows 11: Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.

Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.

Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.

8.3Run Microsoft Defender Offline

Reboot to normal Windows. Open Windows Security → Virus & threat protection → Scan options. Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.

Recommended antivirus
Combo Cleaner

VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.

Download Combo Cleaner
8.4Run a full Combo Cleaner scan

Install Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.

8.5Run Microsoft Safety Scanner as a second-opinion scan

Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.

8.6Reset browsers and clear notification permissions

Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:

Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.

Edge: edge://settings/reset. Then edge://settings/content/notifications.

Firefox: about:support → Refresh Firefox.

8.7Re-enable Defender, Tamper Protection, and update everything

Open Windows Security → Virus & threat protection → Manage settings and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run Settings → Windows Update → Check for updates and update browsers and applications.

Important

If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).

9

You entered credentials on a fake login page

Scenario: shared password⚠ Act fast20 min

Assume the attacker has your password and is using it right now. Speed matters.

  1. Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
  2. Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
  3. Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
  4. Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
  5. Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
  6. Update security questions - the attacker may have seen the answers in your account profile.
Why email comes first

If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.

10

You sent money or shared bank, card, or ID details

Scenario: financial loss⚠ Contact bank now30 min

Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.

  1. Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
  2. If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
  3. If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
  4. File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
  5. File with the right authority for your country:
  6. Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
  7. Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Phase 4~ 15 min + 30 days
Verify & monitor

11

Final scan and startup-app check

15 min

Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.

Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.

12

Monitor accounts and credit for 30 days

5 min/day · 30 days

Most fraud follow-ups land in the first month. Until that window closes, keep watching:

  • Bank and card statements - daily for the first week, then weekly
  • Email - watch for password-reset confirmations or login alerts you didn't trigger
  • Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
  • Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks

If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.

Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.

Frequently Asked Questions (FAQ)

Why did I receive this email?

Usually, cybercriminals use obtained email databases to spread their scams. They send the same email (or emails) to many people - these emails are never personal.

I have provided my personal information when tricked by this email, what should I do?

Victims who have fallen for such scams (have provided account credentials) should change all passwords immediately. In other cases (for example, when the provided information is credit card details, ID card information etc.), users should contact corresponding authorities.

Can emails be used to distribute malware?

Emails can be used as tools to trick recipients into infecting their computers. Such emails contain malicious attachments or links. Recipients infect computers by opening/executing malicious files.

Will Combo Cleaner remove malware infections that were present in email attachment?

Yes, Combo Cleaner will detect and eliminate almost all known malware infections. It is recommended to scan the operating system using the full scan feature. Certain types of malware are capable of hiding deep in the system.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate