Scams and phishing
How to Spot a Fake Data Breach Email
Fake breach emails copy fear and add a link. Real recovery starts on websites you type yourself. Here is how to tell the difference and what to do next.
What a real notice usually looks like
A legitimate company or agency notice tends to:
Even a real letter can be poorly written. Grammar is not a verdict. The request inside the message is. The FTC’s after-breach advice is to visit IdentityTheft.gov/databreach and follow steps that match the data type — not to wire money to the person who emailed you.
- Name the organization in language that matches the real brand
- Describe categories of information, such as email or password, without asking you to reply with those secrets
- Point you to a support page on the company’s own domain
- Avoid a demand for cryptocurrency, gift cards, or a same-day “restoration fee”
- Arrive around the same time as a notice posted on the company’s official site or a page at IdentityTheft.gov for certain incidents
Classic marks of a fake breach email
Treat the message as hostile if it does any of the following:
The FTC’s impersonation guidance is blunt. Government impersonators want money or information. The real FTC will not call to demand your Social Security number, threaten arrest, or ask you to move funds for safekeeping. Caller ID can be faked. CISA’s family guidance adds the habit that stops most of these: think before you click, and verify the sender before you surrender a secret.
- Asks for your password, one-time code, full Social Security number, or a photo of your ID
- Says you must pay to “delete the listing today”
- Uses a shortened or misspelled link
- Threatens arrest, a lawsuit by “the FTC,” or immediate account closure unless you click
- Comes from a public webmail address while claiming to be a bank or a federal agency
- Tells you to install remote-access software so a “specialist” can clean the leak
- Includes a caller ID story: “Do not hang up, stay on the line”
How to verify without using the email’s buttons
This is how to spot a fake data breach email in practice: the fake message cannot survive contact with a URL you already trust. If the official site is silent and the email is frantic, wait. Panic is cheaper for criminals than it is for you.
- Open a new browser tab.
- Type the company’s real domain or a known government address such as identitytheft.gov or consumer.ftc.gov.
- Look for a security or “notice of incident” page.
- If you have an account, sign in through that typed address and read official messages in the inbox on the site.
- If money might be involved, call the number on the back of the card or on a paper statement.
If you already clicked
Slow down. You may still be fine.
IdentityTheft.gov remains the path if the click led to new accounts or other misuse, not only a scare.
- Do not enter a password on the page that opened from the email.
- If you typed a password, change it on the real site from a different tab, then change any reused copies.
- Turn on multifactor authentication or a passkey.
- Review sessions and sign out unknown devices.
- If you typed a card number, call the bank using a known number.
- If you gave a one-time code to a chat agent, assume the account is at risk and use official recovery.
- Run the device’s official update and security tools. You do not need a paid “breach cleaner.”
- Report the scam at ReportFraud.ftc.gov.
What to do with a notice that does check out
When the official site confirms an incident:
A confirmed notice is still not a reason to reply to the original email. Support tickets belong on the site you typed.
- Read the data types.
- Change involved and reused passwords.
- Enable MFA.
- Freeze credit if a Social Security number or similar identifier was involved.
- Take free monitoring only from the company named on the official page.
Reduce the number of future fakes that look convincing
Knowing how to spot a fake data breach email is a security skill. It is also a consumer skill. The people sending the fakes are not trying to help you clean a database. They are trying to become the next copy of your password.
- Unique passwords so one click cannot open five sites
- MFA on email
- A habit of typing URLs
- Mail filters for obvious impersonation phrases, without relying on filters alone
- A household rule: no codes read aloud, ever
Practical checklist
- Do not click the notice. Type the official site.
- Look for password, payment, or ID requests — those are disqualifying.
- Compare the story with the company’s own security page.
- Change passwords only after you are on a typed URL.
- Enable MFA on email.
- Report impersonation at ReportFraud.ftc.gov.
- Use IdentityTheft.gov/databreach for a confirmed incident.
- Keep the original email for your records if you report it, but do not open attachments.
Frequently asked questions
Can a fake email use a real company logo?
Yes. Logos are easy to copy. The domain you type is the check that matters.
What if the email has my old password in the subject line?
That can happen after a real leak or after a phishing kit. Do not reply. Change that password on the official site and retire every reused copy. Do not send the password to anyone who “needs it to delete the file.”
Should I forward the email to the company?
Only through a support form on the official site, and only if that site asks for phishing samples. Do not use a Reply-All chain that still includes the attacker.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
