What to do if you already replied to a fake email

Replied to a fake recruiter, media invite or review offer? Calm, practical steps, in order, based on what you actually shared.

First, breathe

Replying to one of these emails is not a disaster. Most of the harm in these schemes comes later, from money sent, passwords entered or documents handed over. A reply on its own gives the sender very little. What matters now is what you shared, and what you do next.

Work through the steps below in order. Stop at the ones that apply to you.

Step 1: stop the conversation

Do not reply again, even to tell them you know it is fake. A reply confirms your address is live and read by a person, which makes it more valuable. Do not click anything further in the thread. Do not open attachments.

Move the emails to a folder rather than deleting them. You may need them for a report or to check what you sent.

Step 2: work out what you shared

Read back through your own replies and list exactly what left your inbox. Be precise. The steps that follow depend on it.

Typical items, from least to most serious:

Match your list to the sections below.

If you only replied, or sent a bio and photo

You are fine. Your name, photo and biography are already public if you are an author, consultant or anyone with a website. The sender has gained nothing they could not have found.

Expect more emails from the same source, and possibly from others, because a replying address gets passed around. Mark them as junk and move on.

If you shared a phone number

Expect calls and messages. Do not answer numbers you do not recognise, and do not engage with texts about the "opportunity". If it becomes a nuisance, most phones let you block and report. Changing your number is rarely necessary.

If you shared your address or date of birth

On their own these are not enough to open accounts, but they are pieces of a puzzle. Keep an eye on your post for letters about accounts or credit you did not apply for. In the UK you can register with Cifas for protective registration, which asks lenders to make extra checks before opening anything in your name. There is a fee, and it is worth paying if you also sent ID.

If you sent a scan of your passport, driving licence or other ID

This is the point where it becomes worth acting rather than watching.

  1. Register for protective registration with Cifas (UK) or the equivalent fraud-alert service where you live.
  2. Check your credit file with the main credit reference agencies. Look for searches or accounts you do not recognise.
  3. Read the issuing body's guidance. For a UK passport, HM Passport Office publishes advice on lost or stolen documents; a leaked scan is not the same as a lost passport, but their advice will tell you whether replacement is sensible.
  4. Keep the emails as evidence.

Identity fraud from a leaked scan can happen months later. The checks above are not a one-off.

If you shared bank details

An account number and sort code on their own allow someone to pay you, and in some cases to set up a direct debit. Contact your bank, tell them what happened, and ask them to note the account and watch for unexpected direct debits. Check your statements for a few months. If you shared card details, cancel the card and get a new one issued.

If you entered a password on a page they linked to

Treat that password as public.

  1. Change it now on the account it belonged to.
  2. Change it anywhere else you used the same password. This is the step people skip and the one that matters most.
  3. Turn on two-factor authentication on your email account and anything financial.
  4. Check your email account for forwarding rules or filters you did not create. Fraudsters set these up to keep reading your mail after you change the password.
  5. Check the account's "recent activity" or "signed-in devices" page and sign out anything unfamiliar.

Your email account is the master key to everything else, so start there.

If you sent money

  1. Contact your bank or card provider immediately. Say clearly that you have been the victim of fraud. Banks can sometimes recall a transfer if told quickly, and card payments have a dispute process.
  2. Do not send more money to "release" the first payment. That is the next stage of the same scheme.
  3. Report it. In the UK, to Action Fraud. In the US, to the FTC at reportfraud.ftc.gov. Elsewhere, to your national fraud reporting service. These reports rarely recover money on their own, but they feed the systems that shut these operations down.
  4. Keep everything: emails, payment references, screenshots.

Report the email itself

Wherever you are, forward the original email to the organisation being impersonated. Large companies and broadcasters have fraud or security teams and want to know. Find the reporting address on their real website, not in the email.

In the UK, you can also forward phishing emails to report@phishing.gov.uk, which is run by the National Cyber Security Centre. It takes seconds and helps get the sending domains taken down.

Do not blame yourself

These emails are built by people who do this for a living and refine what works. The fake BBC invitation I received used the right presenter's name and the right programme. The fake recruiter email used a real company. They are designed to pass a quick read. Replying is not stupidity; it is what the email was engineered to produce.

What matters is that you now know the tell. It is almost always the domain.

Next time, in one line

Before you reply to anything that asks for money, documents or a login: read the sender's domain, read the reply-to domain, and ask whether either belongs to the organisation named in the email. If not, it is not from them.

A tool, if you want one

I am building Proof of Sender to make that check quick. Paste the sender address and the organisation it claims to be, and it tells you whether they match. It is early and free. Try it at proofofsender.com/demo.

Not sure about an email in front of you right now? Check the sender free. It runs in your browser and nothing is stored.