How to recognize scams like "Moving Funds To Your Account" email scam

Phishing/Scam

Also Known As: Moving Funds To Your Account advance-fee scam

(updated)

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of scam is "Moving Funds To Your Account"?

Our research has shown that it is a scam email offering recipients a large sum of money in return for cooperation. Typically, scammers behind scams like this (known as advance-fee scams) seek to trick recipients into sending them money and (or) personal information. It is advisable not to respond to such emails to avoid potential issues.

Moving Funds To Your Account email spam campaign

More about the "Moving Funds To Your Account" scam email

The scam email, supposedly from Ms. Zaynab Hassan, a regional audit manager at United Bank for Africa in Burkina Faso, contains a fraudulent proposal. The sender states that she discovered an unclaimed $5 million during an audit and needs assistance transferring the funds.

The recipient is offered a 40% share of the money if they agree to act as the beneficiary. The email mentions that the transfer can be safely completed through a bank-to-bank transaction or ATM card. However, this is a classic advance-fee scam designed to deceive recipients into sharing personal information or paying fees for a nonexistent payout.

Usually, when scammers behind such scams aim to extract personal information from recipients, they request credit card details, ID card information, or other details that can be misused to steal identities or for other malicious purposes. Either way, individuals should recognize such emails to avoid monetary loss, identity theft, and other negative consequences.

Threat Summary:
Name Moving Funds To Your Account Email Scam
Threat Type Phishing, Scam, Social Engineering, Fraud
Fake Claim The recipient can claim a large sum of money
Disguise Letter from a regional audit manager at United Bank for Africa in Burkina Faso
Symptoms Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer.
Distribution methods Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains.
Damage Loss of sensitive private information, monetary loss, identity theft.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Similar scam emails in general

Advance-fee scams are fraudulent schemes utilized to lure potential victims with promises of large financial rewards in exchange for personal information or upfront payments. It is important to recognize such fraudulent tactics and avoid responding to unsolicited offers that seem too good to be true, as they often lead to identity theft or financial loss.

Examples of similar emails are "Invest In Your Company Email Scam", "You Share The Same Name Email Scam", and "A Businessman Made A Fixed Deposit Of Huge Fund Email Scam". In addition to stealing money or personal information, emails of this kind can be used to deliver malware.

How do spam campaigns infect computers?

Threat actors behind emails designed to deceive users into infecting computers often contain malicious attachments. These attachments can be executables, archives, MS Office documents, PDFs, script files, or others. Users activate malware when interacting with these files (e.g., enabling macros commands in infected documents or opening malicious executables).

Additionally, emails can contain links that distribute malware. By clicking these links, users can be redirected to fraudulent websites that trick them into downloading malware or initiate automatic downloads of malicious software.

How to avoid installation of malware?

Be cautious when dealing with emails that contain links or attachments. If an email seems unexpected, irrelevant, and (or) from an unknown sender—avoid interacting with its contents. Always download files and software from official websites or trusted app stores. Do not click ads, pop-ups, or links on dubious sites.

Ensure your operating system and software are regularly updated, and use a reliable security program. If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Text presented in the "Moving Funds To Your Account" email letter:

Subject: Hello


Greeting,

My name is Ms. Zaynab, Hassan I am  currently Regional Audit Manager of United Bank for Africa Burkina Faso. I understand that this message must seem quite strange but I assure you, if my sources are correct, together we will be able to ensure the success of my proposal.

I got your email address contact details from your country,s guest book which i got from my late friend archive as a good match for future business that will make both of us very happy!

Although i am not comfortable to send this proposal to you because of increase in SCAM and FRAUD especially in Africa, but i am too sure that this is not Scam because you have access to confirm, and provided you all the necessary information you need to know, do not let my Bank know the source of your information. I have pack agenda financial transaction that will benefit both of us. As the currently Regional Audit Manager  of this bank United Bank for Africa Burkina Faso (UBA), it is my duty to send financial reports to my head office in the capital city of Ouagadougou, Burkina Faso. On the course of year 2022/2023 end of the year's report, i discovered that at my branch in which I am the Audit Manager, discovered the sum of US$5,000,000,00 (Fve Million United State Dollars. )  without beneficial and since then had PLACED this fund in an ESCROW CALL ACCOUNT without a beneficiary. As the regional manager of the bank, I cannot be directly connected to this money thus, i am impelled to request for your assistance to receive this money into your bank account.

I intend to part 40% of this fund to you while 60% shall be for me and two officers who will assist us to move the fund to your account. I do need to assure you that there is no risk involved in this Business. It’s going to be BANK TO BANK TRANSFER Or THROUGH ATM VISA CARD. All I need from you is to stand as the original depositor of this fund. If you accept this offer, i will appreciate your timely response and then we shall discuss on how we move on…

NB: Your early reply is highly welcomed and attaches your profiles, such as your name and address, and also your contact telephone number for easy means of communication.

Best Regards,Ms. Zaynab, Hassan

Other examples of emails from "Moving Funds To Your Account" spam campaign:

Sample 1:

Moving Funds To Your Account email scam (2024-10-03)

Text presented within:

Subject: RE,,,,

 

Hello Dearest,

Allow me to inform you of my desire to enter into a business relationship with you. I have your contact from the directory of the international site. I prayed for this and chose your name among other names because of what my spirit told me that you are a reputable and reliable person to whom I can expose my proof and do business with. Therefore, you should not hesitate to trust this simple and honest matter.

I am Raphaël Kamara, the only son of the late Mr. and Mrs. VINCENT KAMARA. My father was a very wealthy cocoa merchant in Abidjan, the economic capital of Ivory Coast, before he was poisoned to death by his business partners during one of his trips to discuss a business deal.

When my mother died on August 6, 2019, my father accepted me especially because I am an only child and without a mother. Before my father died on March 30, 2024 in a private hospital here in Abidjan, he secretly called me to his bedside and told me that he had the sum of $7,500,000 (Seven Million Five Hundred Thousand Dollars) in a pending account in a bar. bank here in Abidjan, that he used my name as his only child for relatives in deposit the fund. He explained to me that it was because of this wealth and the large amount of money that his business partners had to balance with him because of the business they did, that he was poisoned by his associates of l business, that would seek a God. -The fear of the foreign partner in a country of my choice where I transferred that money and use it for investment purposes (such as property management).

Please, I respectfully request your assistance in the following ways.
1) To get the money for me in your account provide a bank account where the money will be transferred.
2) To serve as a guardian of this since I am an 18 year old kid with no business experience.
3) To help me come to your country once the money is transferred to your account so I can continue my studies and a new life.

I am ready to give 15% of the amount as compensation for the efforts made after the successful transfer of these funds to your designated overseas account. I look forward to hearing from you soon, please. Thank you and God bless you.


Best regards...

Sample 2:

Moving Funds To Your Account email scam (2025-02-05)

Text presented within:

Subject: FAVOURED- next of kin


Attn: Dear Friend,

I am Barrister Diego Carlos a solicitor at law. I am the personal attorney to late Mr.LEO a national of your country, who was an official contractor (category D) with Tullow Oil Plc. London, an oil firm in United Kingdom. Here in after shall be referred to as my client. On the 6th of July 2023, my client, his wife and their only daughter were involved in a car accident on holiday trip along Wimbledon, south-west London, England. All occupants of the vehicle unfortunately lost their lives. Since then I have made several enquiries and presentations to locate any of my client's extended relatives, this has also proved abortive. It is after these several unsuccessful attempts to locate any member of his family failed that I decided to contact you since coincidentally you have your last name believing that you can invariably be of help in this situation to stands as the next of kin to this my client. I am contacting you to assist in repatriating the money and property left behind by my client before they get
confiscated or declared.

Already, the bank where the deceased had an account valued at about 920,0000 Euros has issued me a notice/ultimatum to provide the next of kin or have the account confiscated within the next one month. Since It has been unsuccessful in locating the relatives for over 2 years now, I seek your consent to present you as the next of kin of the deceased, so that the proceeds of this account valued at  920,0000 Euros can be paid to your account and there after we can share the fund (money) in the ratio of 7:3. Meanwhile, I will have 70% of the proceed while you have 30% for your assistance. I have all necessary legal documents that can be used to back up any claim we may make. All I require is your honest co-operation to enable us see this transaction through .I guarantee that this will be executed under a legitimate arrangement that will protect you from any breach of the law.

Please get in touch with me by my email and send to me your telephone and fax numbers to enable us discuss further about this transaction.

Best regards,
Barrister  Diego Carlos

Good morning Sky 04-2-2025

Sample 3:

Moving Funds To Your Account email scam (2025-02-11)

Text presented within:

Subject: MY INVESTMENT PROPOSAL LETTER TO YOU.

 

FROM: MRS ANITA ALEKSANDER.

THIS IS MY INVESTMENT PROPOSAL LETTER TO YOU.

I am Mrs Anita Aleksander  the wife of Mr. Seme Aleksander (Ukraine sunflower oil & wheat, maize farmer ) my husband was murdered by the Russian Army troop because of the war between Russian& Ukraine it was so very terrible. .    

He was a sunflower oil & wheat and maize farmer who have invested much in agriculture political opponents.

I acknowledge very well that my Husband deposited the sum of US$10.7M (TEN MILLION SEVEN HUNDRED THOUSAND UNITED STATES DOLLARS) with a security and financial company here in Johannesburg South -Africa with the intention of using it for the purchase of new farm machinaries and chemical for Agricultural purpose as well as purchasing hectares of land in South Africa for his investment. I got your contact through online chamber of commerce .With the high risk of staying in my country we are now on political asylum. (Refugee) me and my daughter we are here in South Africa, my position does not allow me to open an account or to normalize this funds to any meaningful business transaction, I want you to understand that this is purely family fund not money laundering affair.

I solicit for your honest assistance as I want this fund to be transferred to your account in oversea with your partnership, I will want to invest this fund in your country.

We can invest the fund as a family investment together with you in your country be assured that all the necessary document backing this fund will been arranged with one of the Attorney I meet here in Johannesburg South Africa, feel free to ask any question regarding this transaction.

Hoping to hear from you soonest, kindly contact me through this my private email For Confidential:  anetaaleksander56@gmail.com

I will be waiting to hear from you.

Thanks you and regards

MRS ANITA  ALEKSANDER

Sample 4:

Moving Funds To Your Account Email Scam (2025-04-08)

Text presented within:

Subject: Hello reply asap

My name is Clara Frederik,
I am an accountant working with a BANK here in London. My office monitors and controls the bank's affairs concerned with foreign payments. I am aware of all transfers or remittances of huge funds moving out of the bank both on the local and international levels. I have before me, a list of funds that could not be transferred to some nominated accounts as these accounts have been identified either as ghost accounts, unclaimed deposits, or over-invoiced sums, etc,
hence I am soliciting your concern to have the sum of US$25,800,000.00 transferred into your account for the benefit of you and me. The transaction would be done legally to avoid problems now and in the future. 'My conditions' 1. This deal must be kept secret forever, and all correspondence must be strictly done by email or WhatsApp for security reasons. 2. There should be no third parties as most problems associated with funds business are caused by agents or representatives. 3. The funds would be shared in the ratio i.e. 75% for i and my colleague and 25% for you. If you agree with my conditions, l will advise you on what to do immediately and the transfer will commence as I will fix your name on the PAYMENT SCHEDULE to speed up the process. WhatsApp number or cell phone number for further details.
Regards
Clara Frederik

Sample 5:

Moving Funds To Your Account email scam (2025-06-18)

Text presented within:

Subject: TOP SECRET 6/16/2025 6:42:09 p.m.

I am Mr. Marwan Hadi, Head of Retail Banking and Wealth Management, at HSBC Bank Dubai, UAE. I have been in search of someone with the name so i came online to search then i saw you here, i think it is by the will of God to come across you now, i am having some important business discussion i wish to share with you, it is in connection with your last name and you are going to benefit from it.

One Late Peter, a citizen of your country and a crude Oil dealer made a fixed deposit with my bank valued at US$70,000,000.00 (Seventy Million United State Dollars) the due date for the deposit contract was last 22nd of January 2025,sadly peter was among the death victims a magnitude 7.5 earthquake on september 28,2018, a magnitude 7.5 earthquake struck Indonesia's Central Sulawesi province on Sept. 28, 2018, triggering a tsunami and landslides that caused widespread destruction and loss of life. More than 2,000 people are known to have died and 4,400 are seriously injured he was in Indonesia on a Gold business trip which he introduced to me, sadly that was how he met his end. My bank management is yet to know about his death, i knew about it because he was my friend and i am his account officer.

Peter did not mention any Next of Kin/ Heir when the account was opened, so few months ago i was going through his account details and noticed that his account needs to be renew or to terminate the contract, so i thought of it again and again and i decided to get a next of Kin so that the fund can be out of HSBC Bank, now i am seeking for your co-operation so we can get the fund to our self instead of allowing it to remain in the bank and if the bank do not hear from Late Peter they will use the fund for their personal use, i have prayed and made a very good home grand work concerning this transaction before contacting you, since you have same last name with late Peter my bank head quarters will release the fund to you as the rightful next of Kin to the fund, there is no risk involved in this transaction all i want is for you to keep this transaction secret between the both of us, do not discuss with anybody about this transaction i am here to guide you all through this transaction, the fund will be transferred to your account.

I am not a greedy person, so I am suggesting we share the funds equal, 50/50% to both parties, my share will assist me to start my own company which has been my dream. Let me know your mind on this and please do treat this information as TOP SECRET. We shall go over the details once I receive your urgent response reply.

Sample 6:

Moving Funds To Your Account email scam (2025-07-10)

Text presented within:

Subject: from Ms Nancy Santor?

Hello My Dear Friend ,

I am Ms. Nancy Santos a Clerk under the office of the Director on Foreign Payments World Bank in America . I have worked as the Assistant to the Director and was demoted when they found out that I have never been in support of their shady deals, they wrote a petition against me and I was moved to the Finance Ministry but now I am back to continue my good work which I believe in transparency to humanity.

Though I am now in a lower department and position, I still have access to all transfer files .I have gone through your own payment file and have found that you have completed all that is required of you to have your fund released into your account but the greed which exist in the lives of the Directors of the Foreign Payment, World Bank, Federal Reserve Bank, and other approved paying Banks here will not let them do what they are supposed to do.

I am happy for the good President we have in America today who is not like the former presidents who did nothing about corruption/corrupt practices in the payment system. Because of their greed and amount involved, they would not let you know what to do to get your funds transferred to you. The money you have spent in the past is nothing compared to what they make from your funds through what we call International Trade on Stock and Exchange.

This was what Mr. Michael D. White and Janet Yellen OF U.S. Department of the Treasury, introduced to all of them, telling them never to release your already approved payment so that they can use it to trade on the

International Market on 60 days intervals and make 10% of the amount. Check out how much they must have made with your payment since it was first approved for transfer to your account. This is one secret most of our foreign beneficiaries are not aware of and they need someone to stand for them to clear this and make them get their payments within 48hours. To be frank with you, if I had contacted you earlier, you would have received this money in your account directly today through KTT wire transfer because I know their secret which they believe no one else is aware of or will be intimidated to speak up, all you need is to get an Irrevocable Presidential Permit, from the Kirkland & Ellis law Firm US, Barrister Anthony H. Speier.

I will tell you what you have to do as soon as I get your response to have your funds transferred within 48 hours to your account. This is what I was doing for some beneficiaries and the Directors suspected and kicked against me. I have no interest in your money, I have no interest in what they do too but my anger is that they use and dump us not because we want to share money with them but because they think we know nothing about their deals.

Please assure me that no one will know about this and it will be secret until you have received the document and take them by surprise. I am so sorry for all you have gone through. Once I receive your response, I shall give you the contact details of the best lawyer in Kirkland & Ellis Law Firm so you can contact him and request for the Irrevocable Presidential Permit with the help of the lawyer,

once you have this document on your name you must receive your overdue payment without paying any charges to the bank, the lawyer must stand by you till you receive your payment, the only required fee will be for securing of the Irrevocable Presidential Permit PLEASE REPLY TO MY: Personal EMAIL: msn624750@tutamail.com
I am waiting for your response.
Regards,
Ms. Nancy Santos
NB you have to stop any further communication with any other person or office to avoid any hitches in receiving your payment because of Impostors;

Sample 7:

Moving Funds To Your Account email scam (2025-09-16)

Text presented within:

Subject: From The Desk Of Sir. Hugo Albert

FROM THE DESK OF
SIR. HUGO ALBERT
146 HAGLEY ROAD BIRMINGHAM
BIRMINGHAM CITY B3 3PJ U.K

I seize this opportunity to extend my greetings to you and your family hoping that this third quarter of the year will bring more joy, happiness and prosperity into your household. My name is Sir. Hugo Albert, I am the auditor and head of the computing department of a bank here in the United Kingdom. I wish to inform you of a bank account that was opened in our bank since my inception into office in 2003, and according to our record, it was evident that nobody has ever operated on this account since then. I therefore took the courage to look for a reliable and honest person who will be capable of this important transaction.

The owner of this money is LATE MR. MUTASSIM BILLAH GADDAFI, the son of LATE MUAMMAR GADDAFI OF LIBYA. He was captured by anti-Gaddafi forces and later killed alongside his father. no other person knows about this money or anything concerning his account and the account has no next of kin and my investigation further proved to me that his family and his country does not know anything about this account.

I am therefore seeking for a reliable person that will play the human role as the next of kin to this fund which is in the amount of £41,000,000.00(FOURTY ONE MILLION POUNDS STERLING). I have also discovered that if I do not remit this money out urgently, it will be forfeited to the government treasury account as an unclaimed fund.

I will use my position and influence to affect the legal approval and onward transfer of this fund into any nominated bank account of your choice with appropriate clearance from foreign payment department.

You will henceforth stand to get 40% while 5% shall be set aside for repayment of any expense that will be incurred during the process of this transaction from both parties, and 55% will be for me.
I will fill you in with further details upon your swift reply on this email herein hugoalbert77@aol.com Please be informed that confidentiality of this transaction is of utmost importance.

Yours Truly
Sir. Hugo Albert

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Types of malicious emails:

If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.

Credential theft Phishing emails

Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.

Common subject lines

  • "Action required: confirm your account"
  • "Your password expires today"
  • "Unusual sign-in attempt detected"
  • "Verify your billing information"
Example phishing email impersonating a major brand
Malware delivery Emails with malicious attachments

Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.

Common subject lines

  • "Invoice INV-2026-XXXX attached"
  • "Fax received - 3 pages"
  • "Your shipping document is ready"
  • "Voicemail from +1-XXX-XXX-XXXX"
Example email with a fake invoice attachment
Extortion Sextortion emails

Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.

Common subject lines

  • "I know your password is XXXX"
  • "Your account has been hacked"
  • "I have recorded you - 48 hours to pay"
  • "You have been compromised"
Example sextortion email demanding bitcoin payment
Callback fraud Refund & callback scams

"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.

Common subject lines

  • "Norton subscription auto-renewed - $499.99"
  • "McAfee Total Protection invoice"
  • "Geek Squad order confirmation"
  • "Your PayPal payment is being processed"
Example fake Norton or McAfee subscription renewal email
Credential theft Account suspension & verification scams

"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.

Common subject lines

  • "Your account will be deleted in 24 hours"
  • "Suspicious activity detected - verify now"
  • "Final warning: account closure"
  • "Action required to keep your account active"
Example fake account suspension email
Mixed payload Delivery & package scams

Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.

Common subject lines

  • "Your DHL package is held at customs"
  • "USPS - delivery attempt failed"
  • "FedEx tracking update - action required"
  • "Pay $2.99 redelivery fee to release your parcel"
Example fake DHL/USPS/FedEx delivery notification
Remote access Tech support scams

Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.

Common subject lines

  • "Microsoft Defender expired - renew now"
  • "Apple ID security alert"
  • "Critical: virus detected on your PC"
  • "Windows license expired - call now"
Example fake Microsoft or Apple tech support alert email
Wire fraud Advance-fee scams

Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.

Common subject lines

  • "Inheritance from a relative you didn't know about"
  • "You won the international lottery"
  • "URGENT - business proposal worth $XX million"
  • "Compensation fund release for fraud victims"
Example advance-fee or 419 scam email
Wire fraud Business email compromise (BEC)

CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.

Common subject lines

  • "Quick task - need you to buy gift cards"
  • "Updated banking details for invoice payment"
  • "Wire transfer request - urgent"
  • "Are you available?" (CEO impersonation opener)
Example business email compromise wire-transfer request

How to spot a malicious email?

Phase 1~ 2 min
Spot - identify the red flags

1

Check the sender's actual address, not the display name

30 sec

The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:

  • Domain mismatch - service@paypa1.com, support@micros0ft-help.com, look-alike domains using digits or extra hyphens
  • Free-email impersonation - any "official" message from a bank, courier, or platform sent from a @gmail.com, @outlook.com, or @yahoo.com address
  • Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Why this matters

Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.

2

Watch for urgency, threats, and generic greetings

30 sec

Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:

  • "Your account will be deleted in 24 hours"
  • "Final notice" / "Immediate action required"
  • "Dear Customer" or "Dear User" instead of your real name
  • Threats of fines, account closure, legal action, or arrest
  • Promises of refunds, prizes, or money you didn't earn
  • Spelling and grammar mistakes in messages claiming to come from a major brand
3

Hover over every link before clicking

30 sec

On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.

  • Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
  • Shortened URLs (bit.ly, tinyurl, t.co) hide the real destination - never click them in unsolicited mail
  • The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
Pro tip

When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.

4

Treat unexpected attachments as hostile

30 sec

If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:

  • .exe, .scr, .iso, .img, .vbs, .bat - executables, never legitimate attachments
  • .docx, .xlsx, .pptx with "Enable macros" prompts - the macros run the malware
  • .pdf with "Click here to view" buttons - usually a phishing redirect, not a real document
  • .zip, .rar, .7z archives, especially password-protected ones - the password defeats the email scanner
Phase 2~ 2 min
Report and delete - if you haven't engaged

If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.

5

Don't reply, don't click "unsubscribe"

30 sec

Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.

Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.

6

Report the scam to your email provider and authorities

1 min

Inside your email client:

  • Gmail: open the message → ⋮ menu → Report phishing
  • Outlook / Outlook.com: ⋯ menu → ReportReport phishing
  • Apple Mail / iCloud: Move to Junk, then forward to reportphishing@apple.com

Forward or report to authorities:

  • International: forward to reportphishing@apwg.org
  • United States: ic3.gov (FBI)
  • United Kingdom: forward phishing emails to report@phishing.gov.uk (NCSC SERS); for financial loss report at reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
  • Canada: antifraudcentre.ca
  • Australia: scamwatch.gov.au
  • EU: your national CERT - find yours via the ENISA CSIRT map

After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.

Phase 3~ 10–60 min
Recover - if you already engaged with the scam

Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.

7

You only clicked a link (didn't enter anything or download anything)

Scenario: clicked link only10 min

Close the page right away. Don't enter any information, even if the page looks legitimate.

  • Clear your browser cache and cookies for the last hour - Chrome/Edge: Ctrl+Shift+DelLast hour → check Cookies and Cached files
  • Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
  • Update your browser to the latest version - most drive-by exploits target outdated browsers
  • Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Why this matters

Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.

8

You opened an attachment or downloaded a file - run a full malware scan

Scenario: opened attachment⚠ Highest risk60–90 min

Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:

8.1Disconnect from the network

Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.

8.2Boot into Safe Mode with Networking, then download the scanners

Windows 11: Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.

Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.

Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.

8.3Run Microsoft Defender Offline

Reboot to normal Windows. Open Windows Security → Virus & threat protection → Scan options. Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.

Recommended antivirus
Combo Cleaner

VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.

Download Combo Cleaner
8.4Run a full Combo Cleaner scan

Install Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.

8.5Run Microsoft Safety Scanner as a second-opinion scan

Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.

8.6Reset browsers and clear notification permissions

Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:

Chrome: chrome://settings/resetRestore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.

Edge: edge://settings/reset. Then edge://settings/content/notifications.

Firefox: about:supportRefresh Firefox.

8.7Re-enable Defender, Tamper Protection, and update everything

Open Windows Security → Virus & threat protection → Manage settings and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run Settings → Windows Update → Check for updates and update browsers and applications.

Important

If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).

9

You entered credentials on a fake login page

Scenario: shared password⚠ Act fast20 min

Assume the attacker has your password and is using it right now. Speed matters.

  1. Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
  2. Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
  3. Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
  4. Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
  5. Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
  6. Update security questions - the attacker may have seen the answers in your account profile.
Why email comes first

If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.

10

You sent money or shared bank, card, or ID details

Scenario: financial loss⚠ Contact bank now30 min

Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.

  1. Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
  2. If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
  3. If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
  4. File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
  5. File with the right authority for your country:
  6. Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
  7. Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Phase 4~ 15 min + 30 days
Verify & monitor

11

Final scan and startup-app check

15 min

Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.

Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.

12

Monitor accounts and credit for 30 days

5 min/day · 30 days

Most fraud follow-ups land in the first month. Until that window closes, keep watching:

  • Bank and card statements - daily for the first week, then weekly
  • Email - watch for password-reset confirmations or login alerts you didn't trigger
  • Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
  • Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks

If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.

Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.

Frequently Asked Questions (FAQ)

Why did I receive this email?

Scammers often send out the same phishing email to a large number of recipients. They use email addresses obtained through data breaches or other means. These emails are typically generic, lacking any form of personalization (e.g., names)

I have provided my personal information when tricked by this email, what should I do?

If you have shared any account credentials, update all your passwords immediately. If scammers obtained your ID card information, credit card details, or other information, contact local authorities, your bank, or other relevant entities.

I have downloaded and opened a malicious file attached to an email, is my computer infected?

The risk of infection depends on the type of file you open. For instance, if you open a compromised Word document without enabling macros, you may avoid activating any malware. However, opening an infected executable file increases the chances of compromising your system.

I have read the email but did not open the attachment, is my computer infected?

Merely reading or opening emails is safe. Infections can happen when users open malicious attachments or click on fraudulent links within those emails.

Will Combo Cleaner remove malware infections that were present in email attachment?

Yes, Combo Cleaner is capable of detecting and removing malware. However, advanced malware can often embed itself deep within the system, making it essential to conduct a full system scan to eliminate any hidden malware.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate