What is the "Business Owner Compensation" email scam

Phishing/Scam

Also Known As: Business Owner Compensation phishing scam

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of email is "Business Owner Compensation Email Scam"?

We have examined this email and determined it is a scam. It falsely presents itself as an official government notice informing recipients that business owners worldwide are eligible for a $2.7 million compensation payout. There is no such program - this is an advance-fee fraud designed to harvest personal information and, eventually, money from anyone who responds. The email should be deleted without reply.

Business Owner Compensation Email Scam email spam campaign

"Business Owner Compensation Email Scam" email scam in detail

The email claims that the Federal Government of the United States has decided to compensate business owners, small business founders, CEOs, school owners, and people injured during an ongoing war. Each recipient, it says, qualifies for $2.7 million under so-called "FELA Claims," with the payout allegedly approved by the Trump administration.

To receive the funds, recipients are asked to reply with their full name, business name, business address, phone number, and gender. Collecting this kind of personal data is a classic first step in advance-fee fraud. Once the scammers have it, they use it to build a false sense of legitimacy before introducing demands for money.

After a victim replies, follow-up messages typically introduce obstacles: processing fees, legal charges, transfer taxes, or government levies that must be paid before the funds can be released. None of these payments produce any result. Each one is followed by another demand, and the cycle continues until the victim stops responding or runs out of money.

The email borrows the name and contact details of Tycko & Zavareei LLP, a real U.S. law firm, to make the scheme appear credible. That firm has no connection to this email and plays no role in any such compensation program. Its name appears here without the firm's knowledge or consent.

Sharing personal information with these scammers puts recipients at risk of identity theft. If banking or payment details are later requested and provided, direct financial losses can follow. There is no government compensation program of this kind, and no legitimate authority solicits personal details through a generic email reply.

Threat Summary:
Name Business Owner Compensation phishing scam
Threat Type Phishing, Scam, Social Engineering, Fraud
Fake Claim Business owners, founders, and war injury victims worldwide are eligible to receive $2.7 million in U.S. federal government compensation
Disguise Official U.S. federal government compensation notice endorsed by Tycko & Zavareei LLP
Symptoms Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer.
Distribution methods Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains.
Damage Loss of sensitive private information, monetary loss, identity theft.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Email scams in general

In conclusion, this email is a classic advance-fee fraud disguised as a government compensation notice. There is no fund, no payout, and no program. Responding to it hands personal data to criminals who will use it to extract money through invented fees. Campaigns like this may also serve as a delivery vector for malware in follow-up messages.

More examples of similar scam emails are Policy Violation Detected, Truist Security Alert, and Purchase Order Shared With You Via Dropbox.

How do spam campaigns infect computers?

Spam emails are one of the most common ways malware reaches users' devices. Threat actors attach malicious files directly to messages - these can be executables, compressed archives, PDFs, Microsoft Office documents, or script files. Opening such an attachment, or enabling malicious macro commands inside a document, can trigger a malware infection.

Emails may also contain links to malicious websites. Visiting such a page can trigger an automatic file download or lead the user to a site that asks them to manually run a harmful program. In most cases, malware needs the user to take some action before it can compromise the system.

How to avoid installation of malware?

Treat unexpected emails with caution, especially those making unusual promises or urgent demands. Do not open attachments or follow links in messages from senders you do not recognize. If an email claims to represent a known organization, verify it through that organization's official website or support channels before taking any action.

Only download software from official developer websites or verified app stores. Avoid pirated programs, cracks, and key generators - these are widely used to bundle malware with otherwise legitimate-looking content. Keep your operating system and applications up to date, and run regular scans with a reputable security tool.

If you have already opened a malicious attachment, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate any infiltrated malware.

Text presented in the "Business Owner Compensation Email Scam" email letter:

Subject: Compensate Notification

HELLO

This is to officially bring to your notice that the Federal Government of United State of America have decided to compensate
every Business Owners Worldwide From June 2026
To support and compensate Every small businesses Owners, Founder and CEO & School Owners facing higher expenses during to on going war
(FELA Claims)Also For those who Injuries during to on going war All Types of Injured Victims

Will be compensated With the sum of ($2.7 Million dollars) Two Million Seven Hundred Thousand United State Dollars)
to be scheduled to pay you through Tycko & Zavareei LLP Recovery Company -
Approved by President Trump administration

Each beneficiary would receive a maximum of ($2.7 Million dollars) Two Million Seven Hundred Thousand United State Dollars)
Your funds have been arranged to be paid directly to your Bank account, To receive the above money, you are therefore advised
to reply with the following details

full name====
Business Name==
Business Address==
Phone Number==
Female/male==

Our team is here to guide you in every step until you claimed your Compensation funds successfully

Note: You must only forward the following credentials to the email address below:

Sincerely,
Management Recovery Department
Mr Adrian Marcus(International lawyers Team)
Tycko & Zavareei LLP Recovery Service Company Partner With World Bank
Executive Director Of Funds Recovery Service Company.
+1(800)829-1954

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

Types of malicious emails:

Phishing email icon Phishing Emails

Most commonly, cybercriminals use deceptive emails to trick Internet users into giving away their sensitive private information, for example, login information for various online services, email accounts, or online banking information.

Such attacks are called phishing. In a phishing attack, cybercriminals usually send an email message with some popular service logo (for example, Microsoft, DHL, Amazon, Netflix), create urgency (wrong shipping address, expired password, etc.), and place a link which they hope their potential victims will click on.

After clicking the link presented in such email message, victims are redirected to a fake website that looks identical or extremely similar to the original one. Victims are then asked to enter their password, credit card details, or some other information that gets stolen by cybercriminals.

Email-virus icon Emails with Malicious Attachments

Another popular attack vector is email spam with malicious attachments that infect users' computers with malware. Malicious attachments usually carry trojans that are capable of stealing passwords, banking information, and other sensitive information.

In such attacks, cybercriminals' main goal is to trick their potential victims into opening an infected email attachment. To achieve this goal, email messages usually talk about recently received invoices, faxes, or voice messages.

If a potential victim falls for the lure and opens the attachment, their computers get infected, and cybercriminals can collect a lot of sensitive information.

While it's a more complicated method to steal personal information (spam filters and antivirus programs usually detect such attempts), if successful, cybercriminals can get a much wider array of data and can collect information for a long period of time.

Sextortion email icon Sextortion Emails

This is a type of phishing. In this case, users receive an email claiming that a cybercriminal could access the webcam of the potential victim and has a video recording of one's masturbation.

To get rid of the video, victims are asked to pay a ransom (usually using Bitcoin or another cryptocurrency). Nevertheless, all of these claims are false - users who receive such emails should ignore and delete them.

How to spot a malicious email?

While cyber criminals try to make their lure emails look trustworthy, here are some things that you should look for when trying to spot a phishing email:

  • Check the sender's ("from") email address: Hover your mouse over the "from" address and check if it's legitimate. For example, if you received an email from Microsoft, be sure to check if the email address is @microsoft.com and not something suspicious like @m1crosoft.com, @microsfot.com, @account-security-noreply.com, etc.
  • Check for generic greetings: If the greeting in the email is "Dear user", "Dear @youremail.com", "Dear valued customer", this should raise suspiciousness. Most commonly, companies call you by your name. Lack of this information could signal a phishing attempt.
  • Check the links in the email: Hover your mouse over the link presented in the email, if the link that appears seems suspicious, don't click it. For example, if you received an email from Microsoft and the link in the email shows that it will go to firebasestorage.googleapis.com/v0... you shouldn't trust it. It's best not to click any links in the emails but to visit the company website that sent you the email in the first place.
  • Don't blindly trust email attachments: Most commonly, legitimate companies will ask you to log in to their website and to view any documents there; if you received an email with an attachment, it's a good idea to scan it with an antivirus application. Infected email attachments are a common attack vector used by cybercriminals.

To minimise the risk of opening phishing and malicious emails we recommend using Combo Cleaner Antivirus for Windows

Example of a spam email:

Example of an email spam

What to do if you fell for an email scam?

  • If you clicked on a link in a phishing email and entered your password - be sure to change your password as soon as possible. Usually, cybercriminals collect stolen credentials and then sell them to other groups that use them for malicious purposes. If you change your password in a timely manner, there's a chance that criminals won't have enough time to do any damage.
  • If you entered your credit card information - contact your bank as soon as possible and explain the situation. There's a good chance that you will need to cancel your compromised credit card and get a new one.
  • If you see any signs of identity theft - you should immediately contact the Federal Trade Commission. This institution will collect information about your situation and create a personal recovery plan.
  • If you opened a malicious attachment - your computer is probably infected, you should scan it with a reputable antivirus application. For this purpose, we recommend using  Combo Cleaner Antivirus for Windows.
  • Help other Internet users - report phishing emails to Anti-Phishing Working Group, FBI’s Internet Crime Complaint Center, National Fraud Information Center and U.S. Department of Justice.

Frequently Asked Questions (FAQ)

Why did I receive this email?

These messages are sent in bulk to large numbers of recipients at once. Cybercriminals compile address lists from data breaches, fake websites, and other sources. The emails are not personally targeted.

I have provided my personal information when tricked by this email, what should I do?

Be alert for follow-up emails attempting to continue the scam using the details you submitted. If you shared account credentials, change those passwords immediately across every service where they are used.

If banking details or government identification data were also shared, contact your bank and the relevant authorities without delay to limit the risk of further harm.

I have downloaded and opened a malicious file attached to an email, is my computer infected?

Executable files (.exe and similar formats) tend to activate malware the moment they are opened. Document types such as Word files or PDFs usually require an additional step - like enabling macros - before any malicious code can run. Either way, running a security scan as soon as possible is advisable.

I have read the email but did not open the attachment, is my computer infected?

Reading or viewing an email alone does not put your computer at risk. Infections require some form of interaction with malicious content - opening an attached file or clicking a harmful link. Simply opening the message is safe.

Will Combo Cleaner remove malware infections that were present in email attachment?

Combo Cleaner is capable of detecting and removing most known malware. That said, some sophisticated threats may evade detection. Running a full system scan is the most reliable way to ensure nothing remains on the device.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate