Phishing Protection
How to Spot a Fake Data Breach Notification Email
Fake breach emails use fear and urgency to make you click, pay, or disclose credentials. Check the sender and links, verify the incident through the organization's official site, and take account action independently.
Why do fake breach emails work?
A real breach is an effective theme because people fear losing accounts or personal information. Scammers may copy a company's name, logo, and language or mention a real incident without being connected to it.
- Fear-based wording
- Urgent deadline
- Imitation branding
What warning signs should I look for?
Be cautious with mismatched domains, shortened links, unexpected attachments, payment demands, threats of account closure, and requests for passwords or one-time codes.
- Mismatched sender
- Unexpected attachment
- Request for credentials
- Payment demand
What should I do before clicking?
Do not click. Open the organization's official site manually and look for a security notice or contact method. Do not reply to the sender to verify it.
Verify the incident independently
Use a trusted bookmark or type the organization address yourself. Compare the email with official announcements and contact support through a published channel.
- Open the official site.
- Check security notices.
- Use verified support.
Secure the account safely
If the official site confirms a problem, change the password there, replace reused credentials, and enable multifactor authentication. Do not use the email's reset link.
- Change passwords directly.
- Replace reused credentials.
- Enable MFA.
Report the fake email
Use your email provider's phishing-report option and delete the message after preserving evidence if needed. If you entered credentials, change them immediately through the legitimate site.
- Report phishing.
- Preserve evidence privately.
- Contact the institution if money is involved.
Use exposure information carefully
An email exposure match may explain targeting but cannot authenticate a notice. A negative result does not guarantee that a message is safe.
Frequently asked questions
Can a real breach notice contain a link?
It can, but verify the notice independently and open the organization's official site directly when possible.
Should I reply to the sender?
No. Use an independently verified support channel.
What if I clicked but entered nothing?
Close the page, update software, monitor the account, and change credentials if you entered them.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
