How to avoid falling for scams like "Investment In Your Country" email scam
Phishing/ScamAlso Known As: Investment In Your Country phishing campaign
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What is "Investment In Your Country"?
We have examined the email and found that it is a fraudulent attempt designed to deceive recipients into revealing their sensitive information and (or) extorting money from them. The email contains elements of deception, such as false claims or requests, with the ultimate goal of exploiting unsuspecting individuals for financial gain.

More about the "Investment In Your Country" scam email
The email purports to be from someone named Petrova in Ukraine. Petrova (the scammer) claims to be experiencing difficulties in reaching the recipient due to a lack of internet access in their town. The email states that the sender intends to relocate to the recipient's country due to the ongoing conflict in Ukraine and wishes to invest in a new business there.
The letter mentions funds for investment and even a substantial amount of gold to establish a jewelry manufacturing company. The scammer offers monetary rewards in exchange for assistance. The email's urgency is emphasized by the disrupted phone network caused by attacks on network installations due to ongoing warfare.
The scammer provides a WhatsApp contact number for further communication and expresses gratitude for any help the recipient might provide. The email exhibits classic elements of a fraudulent scheme, with promises of large investments and rewards while seeking personal information or financial involvement.
| Name | Investment In Your Country Email Scam |
| Threat Type | Phishing, Scam, Social Engineering, Fraud |
| Fake Claim | Recipients will receive money in exchange for assistance |
| Disguise | Letter from a person named Petrova |
| Symptoms | Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer. |
| Distribution methods | Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains. |
| Damage | Loss of sensitive private information, monetary loss, identity theft. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Similar scam emails in general
Fraudulent emails, like the one described, often share common characteristics that serve as red flags. These include unsolicited and generic content, such as vague introductions or promises of substantial financial gains, an urgent or emotionally manipulative tone, and a request for personal information or financial involvement.
They frequently contain grammatical errors and inconsistencies in language use. Moreover, scammers may claim to be in a difficult or urgent situation, such as being caught in a conflict or disaster, in an attempt to elicit sympathy and quick responses. These deceptive emails typically seek to exploit recipients by extracting money, sensitive information, or both.
More examples of similar emails are "Recovered Stolen Funds And Crypto Currency", "Deceased Relative", and "Central Bank Of Nigeria". It is important to know that such emails can contain files or links used to distribute malicious software.
How do spam campaigns infect computers?
Attackers send deceptive emails that appear legitimate, often mimicking well-known organizations or individuals, and prompt users to open malicious attachments or click on malicious links. These attachments or links may contain malware, such as ransomware or keyloggers, which can compromise the recipient's system.
Cybercriminals use various types of files to trick users into infecting their computers via email, with the most common being attachments like .exe, .doc, .pdf, and .zip files.
How to avoid installation of malware?
Keep your operating system, software, and antivirus programs up to date. Exercise caution when interacting with email attachments and links, especially if they come from unknown or suspicious sources. Avoid downloading software or files from unverified websites and clicking advertisements on pages of this kind.
Do not download pirated software or tools that are supposed to activate paid software illegally. Be vigilant and stay informed about current cybersecurity threats and common tactics used by cybercriminals to better recognize and avoid potential risks.
If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Text presented in the "Investment In Your Country" email letter:
Subject: Re:Greeting from Ukraine,I wait your respnse to my email
My name is Petrova from Ukraine.I have tried to reach you but find it difficult due to internet scarcity here in this town.
I am contacting you because I want to come over to you country,I have some funds I plan to invest in your country because I want to relocate my Late Father business due to ongoing war in my country Ukraine and visit your country to set up new investment business you may advice profitable in your area.
I also have some millions of dollars i want to invest and 995kg of 24carat gold I want to ship to your country and establish gold jewelry manufacturing company.
I will offer you good monetary rewards for your help,due to how russian drone boambards this town frequently,phone network is disrupted because of attacks on network installations,please for fast discussion, you can add me on whats up and let's talk,this is my whatsapp number below +380953074284Thanking you as i wait to hear from you soon so i can tell you
more details.
God bless you for your care.Regards,
P.Ivan.
Tel/whatsapp:+380953074284
Other examples of emails from "Investment In Your Country" spam campaign:
Sample 1:

Text presented within:
Subject: Greetings,
Greetings,
My name is Alice Martin. My parents have died, but I have in a bank here about ($ 10,500,000.00 United States dollars) ten million five hundred thousand US dollars which I inherited from my late father, Joseph Martin.
I want to Invest the fund in your country with your consent, advice and help.
Secondly, on your full acceptance to work with me regarding this purpose, kindly indicate your interest by replying back to me so that I will furnish you with the necessary information and the details on how to proceed further. I am ready to offer 20% of the total amount of the money to you on the final transfer of the money to your bank account.
Waiting for your urgent response.
My best regards to you and your family.
I need your guidance.
Best regards.
Alice Martin.
Sample 2:

Text presented within:
Subject: Pleasant greetings from Madrid
Dear Sir/Madam,Pleasant greetings from Madrid,
This is a private effort to introduce a partnership proposal to you and I believe it is only a day that people meet and become good friends and business partners.
I am Mrs. Roselyn J. Gonzalez, a banker by profession, I have an Investment proposal in your country worth of $9,718,000.00 which I will like to discuss with you privately and due to time difference I advise
that you get back to me via my private email address: roselyngonzalez535@gmail.com with your contact details immediately you acknowledge the receipt of this mail, so that I will be able to respond
to you with more details and also give you a call to let you know how this could be concluded in a couple of days or weeks.Thanks, as I wait for your reply.
Regards,
Mrs. Roselyn J Gonzalez
Sample 3:

Text presented within:
Subject: I shall be waiting to hear from you.
Dear Friend.
How are you today and i hope you are doing very fine? Before I introduce myself, I wish to inform you that this letter is not a hoax mail and I urge you to treat it serious.This letter must come to you as a big surprise, but I believe it is only a day that people meet and become great friends and business partners. Please I want you to read this letter very carefully and I must apologize for barging this message into your mail box without any formal introduction due to the urgency and confidentiality of this business and I know that this message will come to you as a surprise. Please this is not a joke and I will not like you to joke with it OK, with due respect to your person and much sincerity of purpose,
I make this contact with you as I believe that you can be of great assistance to me My name is Mr. Nasir Daku. from South Sudan but currently in the republic of South Africa due to persistent conflict going on in our country.I got your contact from the South Africa Easy Info Directory, and I am contacting you for your kind assistance for investment in your country. I really wish to invest towards real estate properties, Hotel or construction company, as the case may be, but if there is any other investment you think that would be profitable for me, please let me know. I shall be waiting to hear from you through this email address: (worldwideconsultants00101@gmail.com), for more orientation, possibly with your direct telephone number.Your early response will be appreciated.
Kind Regards,
Mr. Nasir Daku
Email: worldwideconsultants00101@gmail.com
Sample 4:

Text presented within:
Subject: Hi.
My name is Amir L., I am a career auditor working with an investment company based in Singapore. I sent you an email last week but I don’t know if you received and ignored my message or it mistakenly fell into your spam folder.
I need your response to discuss my urgent need with regards to a deceased client who invested in our company. We are an investment and asset management company, our late client instructed us to sale his Million EUR property and convert it into a viable investment in the capital Marked via Euro Bond. After the sales of this property and successful conversion of the funds into investment capital, we lost our client who happen to be a politically exposed person in his home country.
Because our late client was in political office and also aninternational business man, he did not disclose his next of kinto inherit his investment in the capital market and at moment, wecan’t disclose this investment to the deceased client countrybecause the information will be used to tarnish his politicalParty’s reputation, thus the funds in the capital market can only be used for investment abroad.
I stand to present you as a trustee to funds and where we can collectively invest the funds in a real estate project in your country, further modalities will be discussed upon your response.
Regards,
Amir L.
Sample 5:

Text presented within:
Subject: Kindly waiting for your response.
Hello dearest,
Permit me to inform you of my desire to go into a business relationship with you. I got your contact from the International web site directory. I prayed over it and selected your name among other names due to what my mind told me to tell me that you are a reputable and trustworthy person I can expose my ordeal to and do business with. So I must not hesitate to confide in you for this simple and sincere business.
I am Raphael Kamara , the only son of the late Mr and Mrs VINCENT KAMARA. My father was a very wealthy cocoa merchant in Abidjan, the economic capital of Ivory Coast, before he was poisoned to death by his business associates on one of their outings to discuss a business deal.
When my mother died on the 6th August 2019, my father took me special because I am the only child and motherless. Before the death of my father on 30th March 2024 in a private hospital here in Abidjan, he secretly called me on his bedside and told me that he has a sum of $7.500.000 (Seven Million, five hundred thousand dollars) left in a suspense account in a local Bank here in Abidjan, that he used my name as his only child for the next of kin in deposit of the fund. He explained to me that it was because of this wealth and some huge amount of money his business associates supposed to balance him from the deal they had, that he was poisoned by his business associates, that I should seek for a God fearing foreign partner in a country of my choice where I will transfer this money and use it for investment purpose, (such as real estate management).
Please, I am honourably seeking your assistance in the following ways.
1) To receive the money for me in your account by providing a Bank account where this money would be transferred to.
2) To serve as the guardian of this since I am a boy of 18 years and I do not have business experience.
3) To help me come over to your country as soon as the money is transferred to your account so that I will continue my education and a new life.I am willing to give you 15% of the sum as compensation for effort input after the successful transfer of this fund to your designated account overseas. Anticipating to hear from you quickly please. Thanks and God Bless.
I await your response through my private email address at (kamararaphael92@gmail.com ) for more details.
Yours faithfully
Sample 6:

Text presented within:
Subject: INVESTMENT FUND
Hello,
Hope you're hale and hearty today?
I have the directive of my Principal (a political network in Gaza,Palestine) to make contact with you, after a successful due diligence on your personal and corporate capacity.
We have huge funds at the moment, up to $20 million USD already moved out of Gaza, and currently handled by a Finance Group in Switzerland. We would like to move this fund to your country for investment and according to the report on our diligence, you're capable of handling the funds.
Let me make it clear, we have already moved the funds out of Gaza and successfully traded the funds into crypto currency (bitcoin), to enhance seamless administration and easy remittance to you without attracting undue attention.
Now we seek, if we have your approval, to move $20 million dollars bitcoin value to you for liquidation into cash funds and for investment in any lucrative/solid venture for the next few years (10 maybe).
We're offering you 30% of the total sum for your assistance and the rest 60% can be invested on our behalf by you, but under our close supervision.
The good part of our deal/offer to you is that all expenses have been paid. We have made all necessary payments, including processing fees/charges to the Swiss finance company handling the bitcoin transfer to you. In this case you have nothing to worry about, you're not paying any upfront fees/charges to anyone. What we need is your consent/approval and a great deal is closed.
Please carefully read and understand my above proposal, while I await your positive response in time.
Best Regards,
John Collins,
Sample 7:

Text presented within:
...CRY FOR HELP
Greetings to you and your family, I pray that this message finds you in good health, My name is Sandrina Omaru the only daughter to the late Mr Williams Omaru. I am contacting you because I need you to stand as my guardian in the management of my inheritance value, the sum of 3.6 million Euro that my late father left for me before he died. It is sad to say that he passed away mysteriously in France during one of his business trips abroad Though his sudden death was linked or rather suspected to have been masterminded by an uncle of mine who travelled with him at that time. But God knows the truth! My mother died when I was just 6yrs old, and since then my father has treated me so special.
The death of my father actually brought sorrow to my life. I also want to invest the fund under your care because I am ignorant of the business world. I am in a sincere desire for your humble assistance in these regards.Your suggestions and ideas will be highly regarded.
I am 21 years old and a university undergraduate and really don't know what to do. Now I want an honest partner overseas who I can transfer this money with his assistance and after the transaction I will come and reside permanently in your country till such a time that it will be convenient for me to return back home if I so desire. This is because I have suffered a lot of setbacks as a result of the incessant political crisis here in Ivory coast.
Please consider this and get back to me as soon as possible. Immediately I confirm your willingness, I will send to you my Picture and also inform you of more details involved in this matter.
Thanks and God bless you.
Kind Regards,
Sandrina Omaru
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Types of malicious emails:
If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.
Credential theft Phishing emails
Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.
Common subject lines
- "Action required: confirm your account"
- "Your password expires today"
- "Unusual sign-in attempt detected"
- "Verify your billing information"
Malware delivery Emails with malicious attachments
Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.
Common subject lines
- "Invoice INV-2026-XXXX attached"
- "Fax received - 3 pages"
- "Your shipping document is ready"
- "Voicemail from +1-XXX-XXX-XXXX"
Extortion Sextortion emails
Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.
Common subject lines
- "I know your password is XXXX"
- "Your account has been hacked"
- "I have recorded you - 48 hours to pay"
- "You have been compromised"
Callback fraud Refund & callback scams
"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.
Common subject lines
- "Norton subscription auto-renewed - $499.99"
- "McAfee Total Protection invoice"
- "Geek Squad order confirmation"
- "Your PayPal payment is being processed"
Credential theft Account suspension & verification scams
"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.
Common subject lines
- "Your account will be deleted in 24 hours"
- "Suspicious activity detected - verify now"
- "Final warning: account closure"
- "Action required to keep your account active"
Mixed payload Delivery & package scams
Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.
Common subject lines
- "Your DHL package is held at customs"
- "USPS - delivery attempt failed"
- "FedEx tracking update - action required"
- "Pay $2.99 redelivery fee to release your parcel"
Remote access Tech support scams
Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.
Common subject lines
- "Microsoft Defender expired - renew now"
- "Apple ID security alert"
- "Critical: virus detected on your PC"
- "Windows license expired - call now"
Wire fraud Advance-fee scams
Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.
Common subject lines
- "Inheritance from a relative you didn't know about"
- "You won the international lottery"
- "URGENT - business proposal worth $XX million"
- "Compensation fund release for fraud victims"
Wire fraud Business email compromise (BEC)
CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.
Common subject lines
- "Quick task - need you to buy gift cards"
- "Updated banking details for invoice payment"
- "Wire transfer request - urgent"
- "Are you available?" (CEO impersonation opener)
How to spot a malicious email?
Check the sender's actual address, not the display name
The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:
- Domain mismatch -
service@paypa1.com,support@micros0ft-help.com, look-alike domains using digits or extra hyphens - Free-email impersonation - any "official" message from a bank, courier, or platform sent from a
@gmail.com,@outlook.com, or@yahoo.comaddress - Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.
Watch for urgency, threats, and generic greetings
Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:
- "Your account will be deleted in 24 hours"
- "Final notice" / "Immediate action required"
- "Dear Customer" or "Dear User" instead of your real name
- Threats of fines, account closure, legal action, or arrest
- Promises of refunds, prizes, or money you didn't earn
- Spelling and grammar mistakes in messages claiming to come from a major brand
Hover over every link before clicking
On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.
- Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
- Shortened URLs (
bit.ly,tinyurl,t.co) hide the real destination - never click them in unsolicited mail - The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.
Treat unexpected attachments as hostile
If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:
.exe,.scr,.iso,.img,.vbs,.bat- executables, never legitimate attachments.docx,.xlsx,.pptxwith "Enable macros" prompts - the macros run the malware.pdfwith "Click here to view" buttons - usually a phishing redirect, not a real document.zip,.rar,.7zarchives, especially password-protected ones - the password defeats the email scanner
If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.
Don't reply, don't click "unsubscribe"
Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.
Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.
Report the scam to your email provider and authorities
Inside your email client:
- Gmail: open the message → ⋮ menu → Report phishing
- Outlook / Outlook.com: ⋯ menu → Report → Report phishing
- Apple Mail / iCloud: Move to Junk, then forward to
reportphishing@apple.com
Forward or report to authorities:
After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.
Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.
You only clicked a link (didn't enter anything or download anything)
Close the page right away. Don't enter any information, even if the page looks legitimate.
- Clear your browser cache and cookies for the last hour - → Last hour → check Cookies and Cached files
- Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
- Update your browser to the latest version - most drive-by exploits target outdated browsers
- Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.
You opened an attachment or downloaded a file - run a full malware scan
Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:
Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.
Windows 11: → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.
Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.
Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.
Reboot to normal Windows. Open . Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.
VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.
Download Combo CleanerInstall Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.
Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.
Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:
Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.
Edge: edge://settings/reset. Then edge://settings/content/notifications.
Firefox: about:support → Refresh Firefox.
Open and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run and update browsers and applications.
If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).
You entered credentials on a fake login page
Assume the attacker has your password and is using it right now. Speed matters.
- Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
- Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
- Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
- Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
- Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
- Update security questions - the attacker may have seen the answers in your account profile.
If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.
You sent money or shared bank, card, or ID details
Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.
- Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
- If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
- If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
- File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
- File with the right authority for your country:
- US: ic3.gov + reportfraud.ftc.gov
- UK: reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
- Canada: antifraudcentre.ca
- Australia: scamwatch.gov.au
- EU: your national CERT or police cybercrime unit
- Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
- Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Final scan and startup-app check
Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.
Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.
Monitor accounts and credit for 30 days
Most fraud follow-ups land in the first month. Until that window closes, keep watching:
- Bank and card statements - daily for the first week, then weekly
- Email - watch for password-reset confirmations or login alerts you didn't trigger
- Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
- Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks
If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.
Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Criminals distribute identical letters to numerous recipients with the expectation that they will deceive at least one individual. These spam emails lack personalization and are mass-sent to reach a wide audience.
I have provided my personal information when tricked by this email, what should I do?
If you have shared personal information due to a deceptive email, act swiftly. Change compromised passwords, monitor accounts for suspicious activity, and report unauthorized transactions. Be cautious of further contact from the sender, and consider alerting law enforcement and running a malware scan on your computer.
I have downloaded and opened a malicious file attached to an email, is my computer infected?
For executable files, the likelihood of infection is high. However, if the file was a document like .pdf or .doc, there is a chance you may have avoided the infection, as merely opening such documents sometimes is not sufficient for malware to infect the system.
I have sent cryptocurrency to the address presented in such email, can I get my money back?
Recovering cryptocurrency sent to a fraudulent address presented in an email can be exceptionally challenging. Cryptocurrency transactions are typically irreversible, and once funds are sent to an address, they cannot be easily retrieved.
I have read the email but did not open the attachment, is my computer infected?
Merely viewing the email or its content (without opening links or attachments) does not lead to an infection.
Will Combo Cleaner remove malware infections that were present in email attachment?
Combo Cleaner possesses the capability to detect and remove the majority of malware infections. It is essential to remember that sophisticated malware often conceals itself deep within the system. Therefore, it is imperative to perform a comprehensive system scan.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion