How to spot fake emails like "Care For The Poor And Less Privileged" scam email

Phishing/Scam

Also Known As: Care For The Poor And Less Privileged scam

(updated)

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of scam is "Care For The Poor And Less Privileged"?

We have examined this email and found that it is a scam email promising a large sum of money. Typically, scammers behind such emails claim that the recipient has been identified as the beneficiary of a large sum of money from an inheritance, lottery, or some other source. These scams should be ignored.

Care For The Poor And Less Privileged email scam

More about the "Care For The Poor And Less Privileged" scam email

This scam email is supposedly written by Mrs. Mary Michael, a 70-year-old widow who claims to be in poor health and may not survive an upcoming surgery. In the email, Mrs. Michael states that she does not want the bank or corrupt government to have her money if she does not survive the surgery.

She claims to have selected the recipient after visiting some website and is willing to donate the sum of £1.8 million to help the less privileged in the recipient's country.

Mrs. Michael further claims that the funds have been deposited in one of the security companies in London. She assures the recipient that she will provide all necessary information to release the funds from the security company and have it delivered to the recipient's address.

This email is a classic example of advance fee fraud. The scammer behind this email is attempting to convince the recipient to provide personal information and (or) pay an upfront fee to cover various expenses under the guise of receiving a large sum of money.

Once the victim has provided the requested information or made the payment, the scammer will disappear, and the victim will never receive the promised funds. Thus, it is strongly recommended to ignore this scam email and remember not to trust similar scams in the future.

Threat Summary:
Name Care For The Poor And Less Privileged Email Scam
Threat Type Phishing, Scam, Social Engineering, Fraud
Fake Claim The recipient can receive a large sum of money
Disguise Letter from a widow
Symptoms Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer.
Distribution methods Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains.
Damage Loss of sensitive private information, monetary loss, identity theft.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Similar scam emails in general

As a rule, advance fee scams involve promising victims a large sum of money in exchange for upfront fees or personal information. Other common types of scams include lottery scams, phishing scams, and romance scams.

If you receive an email promising a large sum of money, especially if it is unsolicited and asks for personal information or payment, it is likely a scam and should be ignored or reported to the appropriate authorities.

Examples of other scam emails are "Retirement Funds Email Scam", "Mailbox Quota Exceeded Email Scam", and "Payment For Apple Gift Card Email Scam". It is important to note that emails can also be used to send malware.

How do spam campaigns infect computers?

Emails that contain malware are designed to trick recipients into downloading and running malicious software by clicking on malicious links or attachments. The types of files commonly used to deliver malware include Microsoft Office or PDF documents, archive files like ZIP and RAR, executable files, and JavaScript files.

Recipients infect computers when they download and execute malware by themselves. It is important to understand that not all files are able to infect a computer immediately. For instance, harmful Microsoft Office documents rely on macros to be enabled before they can infect a computer.

How to avoid installation of malware?

Exercise caution when receiving unsolicited or irrelevant emails from unknown or suspicious addresses, as they may contain infected files or links to malware-hosting pages. Also, download applications and files only from official sources and avoid third-party downloaders, P2P networks, or other unreliable sources.

Avoid clicking ads on dubious websites. Keep the operating system and installed programs up to date and use reputable antivirus software. If you've already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Text presented in the "Care For The Poor And Less Privileged" email letter:

Subject: Greetings


My Dearest one

I am Mrs. Mary Micheal, 70 years old widow. I was married to the late Engr.Jacobson Micheal, my late husband was from California, USA, He worked with Shell Development Company here in London for Twenty-Six years before he died in the year 2017 after a brief illness that lasted only five days.

Am not in good health but God is alive despite the fact that my doctor has confirmed that I may not survive the surgery that will be performed on me soon. I do not want the bank/corrupt government to have my money if I don't succeed in the operation, My health is in the hand of God.

I selected you after visiting the website and I prayed over it. I am willing to donate the sum of £1.8, Million GBP, to help the less privileged. Please know that the fund was deposited in one of the security companies here in London. Once I hear from you, I will forward to you all the information you will use to get this fund released from the security company and to be delivered to your address in your country.

If you can faithfully help and use the fund to care for the poor and less privileged in your country, I am waiting to read from you for more details on my intention to help the poor and the needy in your country.

Your sister in God,
Mrs. Mary Micheal.

Other examples of emails from "Care For The Poor And Less Privileged" spam campaign:

Sample 1:

Care For The Poor And Less Privileged scam email (2023-03-20)

Text presented within:

Subject: My Dearest in the Lord,

 

My Dearest in the Lord,

Greetings in the name of our Lord Jesus Christ. I’m Mrs. Janalle Potman, the widow of the late Mr. Alexa Potman , I’m 69 years old. I am a Christian convert, suffering from prolonged breast cancer of the breast,My husband died six years ago, and our long years of marriage were not blessed with children. My husband was very wealthy. After his death I inherited all his business and funds. My doctor has diagnosed and told me privately what I should expect, building my spirit for the inevitable . He says i may not last for more than four months, based on this i have taken the decision to share part of my funds and wealth in contribution to the development of the Church and society with major focus on the poor, needy and victims of Coronavirus,  

 

I selected you after visiting the website having prayed over it, I am willing to donate the sum of $12.5 Million USD for your work in developing the Church and to help the poor, needy,and less privileged among your congregations/society. Please note that this fund is deposited in a bank in the country in the Benin Republic where my husband worked, My lawyer will file the application for the transfer of this money in your designated name and information, after my applications and instructions. I now realize that wealth without life in Christ is vanity and non-sense. Always remember that. May the grace and blessings of God be and remain with you. I shall be awaiting for your response.through my private email:   janalle.potman@aol.com

Best Regards,  
Mrs. Janalle Potman

Sample 2:

Care For The Poor And Less Privileged scam email (2023-04-04)

Text presented within:

Subject: HELLO ,

 

--
Hello,

I believe you will do better than I think,

It is understandable that you may be a bit apprehensive because you do not know me, I am writing this mail to you with serious tears in my eyes and great sorrow in my heart, I decided to contact you due to the urgency of my situation. My Name is Mrs.Nadya SALIM, Am contacting you from my country France. I want to tell you this because I don't have any other option than to tell you as I was touched to open up to you, I am married to Late Dr.Nathan SALIM who worked with France Embassy in Ouagadougou the capital city of Burkina Faso for nine years before he died in the year 2011. We were married for eleven years without a child. He died after a brief illness that lasted for only five days. Since his death I decided not to remarry again, when my late husband was alive he deposited the sum of US$10,900,000.00(Ten Million Nine Hundred thousand United States Dollars) with a bank in Ouagadougou,

Presently this money is still in the bank there. He made this money available for exportation of Gold from Burkina mining. Recently, My Doctor told me that I would not last for the period of seven months due to cancer problem. The one that disturbs me most is my stroke sickness. Having known my condition I decided to hand you over this mission to take care of the less-privileged, you will utilize this money the way I am going to instruct herein. I want you to take 30 Percent of the total money for your personal use While 70% of the money will go to charity work" helping people in the street.

Because I grew up as an Orphan and I don't have anybody as my family member, just to Endeavor that the house of God is maintained. Am doing this so that God will forgive my sins and accept my soul because this sickness has suffered me so much. As soon as I receive your reply I shall give you the contact of the bank in Burkina Faso and I will also instruct my lawyer to issue you an authority letter that will prove you the present beneficiary of the money in the bank that's if you assure me that you will act accordingly as I Stated herein. Please kindly reply me back through my private email address for more explanation.( misnadyasal@gmail.com ).

Remain blessed
Yours Sister
Mrs.Nadya Salim .

Sample 3:

Care For The Poor And Less Privileged Email Scam (2023-07-04)

Text presented within:

Subject: My Name Is Mrs Alisha Stoffle


Greetings

Please forgive me for approaching you through this media. I am Mrs.
Alisha Stoffle, 63 years, from the USA, I am childless and I am suffering
from a pro-long critical cancer, my doctors confirmed I may not live a few
months from now as my ill health has defiled all forms of medical treatment.

Since my days are numbered, I have decided willingly to fulfill my
long-time promise to donate you the sum ($8.000.000.00) million dollars I
inherited from my late husband Mr.Herbart Stoffle  foreign bank account for
charities work of God and there is no risk involved; it is 100% hitch free
& safe because it is my inheritance from late husband

If you will be interesting to assist in getting this deposit fund transfer
into your account for charity for the mutual benefit of orphans and the
less privileged project to fulfill my promise before I die, please let me
Know immediately and you will take 50% percent of the total money for your
effort and assistance while 50% of the money will go to charity projects. I
I will appreciate your utmost confidentiality as I wait for your reply.

God Bless you,
Mrs. Alisha Stoffle

Sample 4:

Care For The Poor And Less Privileged email scam (2023-07-10)

Text presented within:

Subject: From Mrs Lynn,

 

I hope this letter finds you in good health and high spirits. My name is Mrs. Lynn Berrycloth, and I write to you with the utmost respect and sincerity. Please allow me to apologize for any inconvenience caused by reaching out to you through this electronic medium. However, I find myself compelled to seek your assistance in fulfilling a charitable project, which holds great importance to me in light of my circumstances. I want to donate my inheritance ($20Million US Dollars) that my late husband left for me and recently, the doctors told me that I might not survive the latest surgery which I have been booked for.
 
It is with a heavy heart that I reveal my ongoing battle with cancer, a diagnosis I received six years ago. Despite the challenges and uncertainty that this illness has brought into my life, I have chosen to remain optimistic and resilient. As I face the inevitable, I am determined to make a positive impact and leave a lasting legacy of kindness and compassion.

In light of this, I have embarked upon a mission to establish a charity project that will cater to the needs of the less privileged. This endeavor is of utmost importance to me, as I strongly believe in the power of generosity and collective effort to uplift the lives of those in need. However, given the limitations of my health and circumstances, I find myself in need of a trustworthy and educated individual who can serve as a confidant and aid me in realizing this noble cause.

I understand that my request may appear unconventional and even risky, as we are not acquainted in person. Nonetheless, my current situation has left me with no other option but to seek assistance through this medium. I implore you to consider this proposition with an open mind and a compassionate heart. Your participation would mean more to me than words can express, and your selfless act towards the less privileged would bring immense joy and fulfillment to my final days.

If you choose to accept this responsibility, I assure you that every effort will be made to ensure your safety and security. Our collaboration would be conducted with the utmost transparency and adherence to ethical principles. I am more than willing to provide you with any necessary documentation or information that will help solidify your trust in this endeavor.
 
I want you to use 30% of the fund to build orphanage homes in your country while 20% goes to cancer research programs and then donate 25% to institutions housing elderly couples who cannot give birth and homeless children in their lifetime just like my late husband and I could not bear children. The remaining 25% goes to you as the person who agrees to carry out my last wish and I will give you more details only if you are willing and ready to handle this project. I humbly request your prompt response, expressing your willingness to assist me in fulfilling my last wish.

Thank you for your attention, and I eagerly await your favorable reply.

With profound gratitude and warm regards,

Mrs. Lynn Berrycloth

Sample 5:

Funds to any good Charity Organization and Motherless Babies Homes

Text presented within:

Subject: Re: LUCKY YOU..CONTACT ME IMMEDIATELY.

 

Reply-To Email: E-mail: billiondollarman8888@hotmail.com

Dear Sir/Madam,

My name is Roman Abramovich and I was the former owner of Chelsea Football Club which has been sold out and all funds have been given to charity since I seriously condemed the Russian invasion in Ukraine which i am against the president's decision Mr. Vladmir Putin as we have since both parted ways for good..  I found your email address and profile on Google search and saw a distinguished person about you.. In this regard i am offering that you contact my account officer which i will send to you his contact email address and that would be after i have received your personal details in your next reply to me. He will help you secure the the sum amount of $100,000,000 (ONE HUNDRED MILLION US DOLLARS ONLY). After receiving this funds i want you to donate 60% of the funds to any good Charity Organization and Motherless Babies Homes of your choice and you can thereafter have the rest for yourself. You will co-operate with the account officer to secure the funds. Please take note that during the course of this transaction there will be no phone call or communication, this is for security reasons.

You should send the following information back to me so i can forward it to my account officer as i have briefed him already about this matter.

1. Full Name:
2. Nationality/Country of Origin:
3. Country Currently Staying:
4. Age:
5. Male/Female:

I expect to hear from you immediately.

Best Regards,

Roman Abramovich
Former Owner; Chelsea FC
E-mail: billiondollarman8888@hotmail.com

Sample 6:

Care For The Poor And Less Privileged email scam (2023-09-05)

Text presented within:

Subject: Dear Beloved Please Read And Get Back To Me

 

Dear -,


I hope this message finds you well. My name is Valentina Sakun, and I am from Ukraine. I was married to Mr. Yevhenii Sakun, the camera operator of Kyiv TV Tower, who tragically lost his life due to the ongoing crisis and a Russian missile strike on Kyiv's Babyn Yar on March 1st, 2022. You can find more information about this incident here: link.

Before my husband's untimely passing, we jointly owned assets valued at approximately $6.5 million (USD), securely stored in a vault located in Dublin, Ireland.


Currently, I am seeking refuge in a Polish hospital due to my deteriorating health. I am 48 years old, and my doctor has informed me that I am unable to travel due to kidney and liver failure. I have only a few more months left, but I am not afraid of death because I know where I am headed.


Before my husband's passing, we made a heartfelt decision to donate these funds to a person of strong faith, someone who would pledge to use the money to support motherless baby homes, orphanages, charitable organizations, assist the less privileged, spread the word of God, and contribute to the fight against Russian rebels in Ukraine.


We made this decision because we do not have any children to inherit this money, and I am determined to honor the promise we made together to donate the funds to someone guided by divine direction. Upon receiving your response, I will promptly proceed with the immediate release of the funds to you through my lawyer.

I kindly request your prayers for me during this challenging time, as my days are numbered.

Please respond privately to me at this email address: valentinasakun@ncapitalloan.com

Please stay safe and may the Lord be with you.

Yours in the Lord,
Valentina Sakun

Sample 7:

Care For The Poor And Less Privileged email scam (2023-10-13)

Text presented within:

Subject: Dear Beloved


Dear -,

Greetings My Beloved One.

It is true that this letter may come to you as a surprise. Nevertheless, I humbly ask you to give me your attention and hear me well. My name is Mrs. Debry Goita from United States of America. I am married to Mr. Williams Goita who once worked with our Embassy in Hungary in the year 2002 and he also worked in an embassy in London for a period of 16 years before he died.

We were married for 25 years without a child before he died after a brief illness. Since his death I decided not to remarry due to my religious belief. When my late husband was alive he deposited the sum of USD$15.000.000.00 (Fifteen million United State American dollars) with a Bank here in America. Presently this money is still in the custody of the Bank. Recently, my Doctor told me that I would not last for the next Four months due to my cancer illness.

Having known my condition, I decided to donate this money to good person that will utilise this money the way I am going to instruct herein.

I want you to use this money for Charity organisation, orphanages, elderly people, widows, to build animal care clinics, free hospital and school for poor people that are in need. l took this decision because I don't have any child that will inherit this money. Moreover, my husband's relatives are not close to me since I develop a Cancer problem and it had been their wish to see me dead in order to inherit his wealth since we have no Child. These people are not worthy of this inheritance. This is why I am taking this decision to contact you and donate this fund to you in order for you to use it for the charity works.

As soon as I receive your reply, I will also issue a letter of authorisation to the bank to transfer the funds to your account. I also want you to reply this message with your full names, address and telephone number where I can reach you.

Any delay in your reply may give me room to look for another good person for this same purpose. Please assure me that you will act accordingly as I stated above.

Thanks and Remain blessed.

Yours faithfully,
Mrs Debry Goita
goita.debry@gmail.com

Sample 8:

Care For The Poor And Less Privileged email scam (2023-10-24)

Text presented within:

Hello I'm Lee Shau-kee, a Hong Kong business magnate, investor, and philanthropist. I'm the chairman and majority owner of Henderson Land Development, a property conglomerate with interests in property, hotels, restaurants and internet services. I gave away 25 percent of my personal wealth to charity and I also pledged to give away the rest of 25% this year. I have decided to donate €2,000,000.00 Euros to you. If you are interested in my donation, do contact me for more info. I will also want you to be part of my Charity Foundation once you receive this money so we can join hands together to help the needy. Warm Regard Mr. Lee Shau Kee

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Types of malicious emails:

If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.

Credential theft Phishing emails

Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.

Common subject lines

  • "Action required: confirm your account"
  • "Your password expires today"
  • "Unusual sign-in attempt detected"
  • "Verify your billing information"
Example phishing email impersonating a major brand
Malware delivery Emails with malicious attachments

Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.

Common subject lines

  • "Invoice INV-2026-XXXX attached"
  • "Fax received - 3 pages"
  • "Your shipping document is ready"
  • "Voicemail from +1-XXX-XXX-XXXX"
Example email with a fake invoice attachment
Extortion Sextortion emails

Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.

Common subject lines

  • "I know your password is XXXX"
  • "Your account has been hacked"
  • "I have recorded you - 48 hours to pay"
  • "You have been compromised"
Example sextortion email demanding bitcoin payment
Callback fraud Refund & callback scams

"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.

Common subject lines

  • "Norton subscription auto-renewed - $499.99"
  • "McAfee Total Protection invoice"
  • "Geek Squad order confirmation"
  • "Your PayPal payment is being processed"
Example fake Norton or McAfee subscription renewal email
Credential theft Account suspension & verification scams

"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.

Common subject lines

  • "Your account will be deleted in 24 hours"
  • "Suspicious activity detected - verify now"
  • "Final warning: account closure"
  • "Action required to keep your account active"
Example fake account suspension email
Mixed payload Delivery & package scams

Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.

Common subject lines

  • "Your DHL package is held at customs"
  • "USPS - delivery attempt failed"
  • "FedEx tracking update - action required"
  • "Pay $2.99 redelivery fee to release your parcel"
Example fake DHL/USPS/FedEx delivery notification
Remote access Tech support scams

Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.

Common subject lines

  • "Microsoft Defender expired - renew now"
  • "Apple ID security alert"
  • "Critical: virus detected on your PC"
  • "Windows license expired - call now"
Example fake Microsoft or Apple tech support alert email
Wire fraud Advance-fee scams

Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.

Common subject lines

  • "Inheritance from a relative you didn't know about"
  • "You won the international lottery"
  • "URGENT - business proposal worth $XX million"
  • "Compensation fund release for fraud victims"
Example advance-fee or 419 scam email
Wire fraud Business email compromise (BEC)

CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.

Common subject lines

  • "Quick task - need you to buy gift cards"
  • "Updated banking details for invoice payment"
  • "Wire transfer request - urgent"
  • "Are you available?" (CEO impersonation opener)
Example business email compromise wire-transfer request

How to spot a malicious email?

Phase 1~ 2 min
Spot - identify the red flags

1

Check the sender's actual address, not the display name

30 sec

The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:

  • Domain mismatch - service@paypa1.com, support@micros0ft-help.com, look-alike domains using digits or extra hyphens
  • Free-email impersonation - any "official" message from a bank, courier, or platform sent from a @gmail.com, @outlook.com, or @yahoo.com address
  • Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Why this matters

Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.

2

Watch for urgency, threats, and generic greetings

30 sec

Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:

  • "Your account will be deleted in 24 hours"
  • "Final notice" / "Immediate action required"
  • "Dear Customer" or "Dear User" instead of your real name
  • Threats of fines, account closure, legal action, or arrest
  • Promises of refunds, prizes, or money you didn't earn
  • Spelling and grammar mistakes in messages claiming to come from a major brand
3

Hover over every link before clicking

30 sec

On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.

  • Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
  • Shortened URLs (bit.ly, tinyurl, t.co) hide the real destination - never click them in unsolicited mail
  • The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
Pro tip

When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.

4

Treat unexpected attachments as hostile

30 sec

If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:

  • .exe, .scr, .iso, .img, .vbs, .bat - executables, never legitimate attachments
  • .docx, .xlsx, .pptx with "Enable macros" prompts - the macros run the malware
  • .pdf with "Click here to view" buttons - usually a phishing redirect, not a real document
  • .zip, .rar, .7z archives, especially password-protected ones - the password defeats the email scanner
Phase 2~ 2 min
Report and delete - if you haven't engaged

If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.

5

Don't reply, don't click "unsubscribe"

30 sec

Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.

Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.

6

Report the scam to your email provider and authorities

1 min

Inside your email client:

  • Gmail: open the message → ⋮ menu → Report phishing
  • Outlook / Outlook.com: ⋯ menu → ReportReport phishing
  • Apple Mail / iCloud: Move to Junk, then forward to reportphishing@apple.com

Forward or report to authorities:

  • International: forward to reportphishing@apwg.org
  • United States: ic3.gov (FBI)
  • United Kingdom: forward phishing emails to report@phishing.gov.uk (NCSC SERS); for financial loss report at reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
  • Canada: antifraudcentre.ca
  • Australia: scamwatch.gov.au
  • EU: your national CERT - find yours via the ENISA CSIRT map

After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.

Phase 3~ 10–60 min
Recover - if you already engaged with the scam

Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.

7

You only clicked a link (didn't enter anything or download anything)

Scenario: clicked link only10 min

Close the page right away. Don't enter any information, even if the page looks legitimate.

  • Clear your browser cache and cookies for the last hour - Chrome/Edge: Ctrl+Shift+DelLast hour → check Cookies and Cached files
  • Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
  • Update your browser to the latest version - most drive-by exploits target outdated browsers
  • Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Why this matters

Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.

8

You opened an attachment or downloaded a file - run a full malware scan

Scenario: opened attachment⚠ Highest risk60–90 min

Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:

8.1Disconnect from the network

Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.

8.2Boot into Safe Mode with Networking, then download the scanners

Windows 11: Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.

Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.

Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.

8.3Run Microsoft Defender Offline

Reboot to normal Windows. Open Windows Security → Virus & threat protection → Scan options. Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.

Recommended antivirus
Combo Cleaner

VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.

Download Combo Cleaner
8.4Run a full Combo Cleaner scan

Install Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.

8.5Run Microsoft Safety Scanner as a second-opinion scan

Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.

8.6Reset browsers and clear notification permissions

Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:

Chrome: chrome://settings/resetRestore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.

Edge: edge://settings/reset. Then edge://settings/content/notifications.

Firefox: about:supportRefresh Firefox.

8.7Re-enable Defender, Tamper Protection, and update everything

Open Windows Security → Virus & threat protection → Manage settings and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run Settings → Windows Update → Check for updates and update browsers and applications.

Important

If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).

9

You entered credentials on a fake login page

Scenario: shared password⚠ Act fast20 min

Assume the attacker has your password and is using it right now. Speed matters.

  1. Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
  2. Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
  3. Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
  4. Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
  5. Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
  6. Update security questions - the attacker may have seen the answers in your account profile.
Why email comes first

If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.

10

You sent money or shared bank, card, or ID details

Scenario: financial loss⚠ Contact bank now30 min

Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.

  1. Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
  2. If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
  3. If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
  4. File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
  5. File with the right authority for your country:
  6. Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
  7. Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Phase 4~ 15 min + 30 days
Verify & monitor

11

Final scan and startup-app check

15 min

Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.

Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.

12

Monitor accounts and credit for 30 days

5 min/day · 30 days

Most fraud follow-ups land in the first month. Until that window closes, keep watching:

  • Bank and card statements - daily for the first week, then weekly
  • Email - watch for password-reset confirmations or login alerts you didn't trigger
  • Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
  • Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks

If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.

Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.

Frequently Asked Questions (FAQ)

Why did I receive this email?

Scammers often send out thousands of these emails to random addresses in the hope of finding a victim who will fall for their scam. These emails are not personal.

I have provided my personal information when tricked by this email, what should I do?

Contact your bank or credit card company immediately to report the incident and freeze your accounts if necessary.

I have downloaded and opened a file attached to this email, is my computer infected?

If you have downloaded and opened a file attached to a suspicious email, there is a possibility that your computer has been infected with malware. It depends on the type of the file.

I have sent cryptocurrency to the address presented in such email, can I get my money back?

These transactions are almost impossible to trace, making it highly unlikely that you will be able to recover the lost funds.

I have read the email but didn't open the attachment, is my computer infected?

If you have received a suspicious email and read the contents but did not download or open any attachments, your computer is unlikely to be infected. Simply opening emails is not harmful.

Will Combo Cleaner remove malware infections that were present in email attachment?

Combo Cleaner has the ability to identify and remove almost all known malware infections. However, it is important to note that sophisticated malware is often concealed deep within the system. As a result, it is crucial to conduct a full system scan to ensure complete detection and removal of any potential threats.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate