Spam Wipe field note
How to Check an Account Security Alert for Scams
An unexpected security alert may describe an unfamiliar sign-in, a password reset or an account about to be locked. Its button offers an immediate fix. A f

An unexpected security alert may describe an unfamiliar sign-in, a password reset or an account about to be locked. Its button offers an immediate fix. A fraudulent version uses that pressure to steal your password, capture a verification code or persuade you to call a fake support number.
Genuine alerts can also concern unfamiliar activity. Appearance alone cannot settle whether a message is authentic. The safest response is to open the account independently and check its security settings, without using the alert’s links, attachments or contact details.
Recognise what the message wants
Look at the requested action before deciding whether the message seems convincing. A counterfeit sign-in page may collect your password, then ask for a one-time code while someone attempts to access the real account. Another version directs you to a caller who requests remote access or payment to resolve a supposed security problem.
Common warning signs include:
- A deadline that pressures you to act before checking the account.
- A request to disclose a password, recovery code or identity document in a reply.
- An unexpected attachment presented as a security report.
- A demand to install software or approve a sign-in you did not initiate.
- A payment request tied to stopping an alleged intrusion.
Good spelling, a familiar logo and your correct name do not establish authenticity. An attacker can copy visual details and use information obtained elsewhere. Equally, an unfamiliar location in an alert is a reason to investigate, rather than proof that somebody has gained access.
Inspect the sender without trusting it
Expand the sender details if your mail application allows it. The display name may say “account security” while the address underneath is unrelated. Lookalike addresses can use extra words or subtle spelling changes to resemble a familiar sender.
An address displayed in a message is not sufficient authentication. Even a specific address such as [email protected] should not become a shortcut for deciding that every message displaying it is safe. Verify the activity through your account instead.
On a computer, hovering over a link may reveal its destination without opening it. On a phone, a link preview may provide similar information. If you cannot inspect it confidently, leave it alone. You do not need to investigate a suspicious link to secure your account.
Read the destination rather than the button label. A familiar word somewhere in an address does not identify who controls the site. Shortened links conceal the destination, and an encrypted connection does not establish that the page belongs to the service you intended to visit.
Do not reply to ask whether the alert is genuine or call its printed number. Both routes may lead directly to the sender. Use contact options reached through the service’s normal website or an application you already trust.
Check the account independently
Close the message. Open your usual application, a trusted bookmark or a website address you already know. Avoid guessing an address from memory if you are uncertain, and do not treat a search advertisement as a verified support route.
Find the account’s security or sign-in history. A Recent activity page is an example of the account record to look for; labels and available details vary between services. Compare any listed events with your own actions.
Check the time, device and outcome together. An unsuccessful password attempt is different from a successful sign-in. Location estimates can be imprecise, so an unfamiliar place alone is less useful than several details that do not match your activity.
- Look for successful sign-ins from devices you do not recognise.
- Check for password changes or resets you did not request.
- Review recovery email addresses, phone numbers and authentication methods.
- Inspect connected applications and unfamiliar permissions.
- Check for changes to trusted devices or other security settings.
If you find an unfamiliar event, use the account’s own reporting and recovery controls. If no matching event appears, continue to avoid the message: an empty activity list does not authenticate an email. For a work account, ask your organisation’s support team through an established channel.
Respond according to what you shared
You opened the page but entered nothing
Close it and decline downloads, notifications, extensions and remote-access requests. Opening a link does not by itself prove that your account was taken over. Check whether anything downloaded or whether you granted a permission, rather than assuming either that everything is safe or that every account is compromised.
You entered a password
Change it promptly through the genuine account settings. Use a device you trust, especially if the suspicious page persuaded you to install software. Replace the password on any other accounts where you reused it, beginning with your main email account and accounts holding sensitive information.
Use the account’s option to end other sessions where available. A password change may not remove every existing session or connected application. Review recovery methods and access permissions too, so an unfamiliar recovery address or authorised application does not remain unnoticed.
You shared a code or approved a prompt
Treat this as possible account access. A code can complete a sign-in that an attacker has already started. Reject further unexpected prompts, change the password, review sessions and check that authentication methods still belong to you. Do not share another code with someone claiming to reverse the first approval.
You installed software or allowed remote access
End the remote session and disconnect the affected device from the network if access may still be active. Use a different trusted device to secure important accounts. Update and run your security software, and seek technical help through a verified channel if you cannot establish what was installed or changed.
You disclosed financial or identity information
Contact the relevant institution through details you already trust and explain what you shared. Keep records of transactions and communications. The Federal Trade Commission’s phishing guidance provides further steps for exposed information and potentially harmful downloads. Use the appropriate identity-fraud reporting process for your country.
Report the message and preserve useful evidence
Use your email service’s phishing-report option when available, then remove the message from your inbox. For a work account, follow your organisation’s reporting procedure before deleting evidence. Describe whether you clicked, entered information, approved a prompt or installed anything; those distinctions help determine the response.
If a verified reporting procedure asks for the original message as an attachment, that can preserve information lost in an ordinary forward. Obtain the destination independently rather than relying on an address printed in the suspicious message. Avoid circulating clickable copies to colleagues or friends.
Record the approximate time, what happened and any transaction references. A screenshot may help, but do not reopen the malicious page merely to collect one. Never include passwords or verification codes in an incident report.
Reduce the chance of a repeat
Give important accounts unique passwords and enable multi-factor authentication where available. Keep recovery information accurate and store recovery codes somewhere secure. Additional authentication helps protect a stolen password, but it cannot make an unexpected approval request trustworthy.
Keep your browser, operating system and security software updated. Save a trusted route to account settings before an incident occurs. When the next alert arrives, use that route to inspect the account and decide what needs changing.
