
Fake email deactivation alert wants to trick you into sharing passwords
Scammers are sending fraudulent mail service notifications claiming your account is scheduled for deletion to harvest business credentials.
A high-volume phishing campaign masquerading as a mail service deactivation notification has been detected in circulation. These emails claim that your organisation's mail account is scheduled for deletion, pressuring you to "Cancel De-activation" immediately.
This activity was flagged due to its sophisticated technical setup and its ability to bypass standard filters by leveraging compromised legitimate domains. The coordinated nature of the attack across multiple local organisations indicates a focused attempt to harvest business credentials.
The technical details contain a significant contradiction: while the messages originate from domains with fully verified SPF, DKIM, and DMARC records, the request itself is a direct violation of standard IT protocols. Legitimate mail providers do not send unprompted "deactivation approved" notices to individual users.
The lure is surprisingly realistic, using professional formatting and a clean "Mail Service" template to lower your guard. The fake button leads to a highly detailed login portal designed to capture sensitive access numbers and passwords during a routine workday.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Verify Independence: Always check account status through your official organisation admin portal or contact your IT provider directly.
- Check the Link: Never use buttons in unexpected security emails. Hover over links to see the real destination or type the provider URL manually.
- Enable Hardware MFA: Use FIDO2 hardware keys (like YubiKeys) to provide immunity to the credential harvesting tactics used in this campaign.
- Report Suspicious Mail: Forward any unprompted deactivation notices to your security team or report them as phishing in your mail client.


