A cPanel warning says your mailbox will soon stop working unless you confirm or update your password. The deadline is fake, and the login page is controlled by scammers.
This is a confirmed phishing email. Do not use its update link. Check your mailbox through the webmail address or hosting dashboard you normally use.

Overview
The cPanel Email/Password Update scam targets people who manage email through a website hosting account. It pretends to be an automated notice from cPanel Webmail support and claims the recipient must confirm an update to keep using the mailbox.
One version warns that the email account will become inaccessible after July 31, 2026 and may face permanent restrictions. Its subject line reads “[********]: Please Confirm To Continue.” The hidden or masked account reference helps the same template work against many recipients.
The “CLICK HERE TO UPDATE” link does not perform a legitimate cPanel change. It opens a phishing page designed to resemble a webmail or hosting login. When the victim submits an address and password, the credentials go to the scammers rather than the hosting provider.
This is not a cPanel software problem and it does not mean the real cPanel platform was breached. Criminals are abusing a familiar administration brand because website owners expect occasional storage, password and server notices.
A stolen domain mailbox can cause more damage than an ordinary personal-email compromise. Attackers may read invoices, reset WordPress or hosting passwords, impersonate the business, redirect customer payments and use the trusted domain to send convincing phishing messages.
Reading the email alone is safe. Opening the phishing page does not automatically compromise the mailbox either. The critical moment is entering credentials, approving a sign-in prompt, revealing a one-time code or downloading and running a file offered by the page.
How the cPanel Password Update Scam Works
Step 1: The email invents a service deadline
The message claims the mailbox will stop receiving or sending mail after a specific date. Threats of permanent restriction are meant to replace careful checking with a quick reaction.
Step 2: Familiar hosting language creates credibility
The scam uses terms such as cPanel, Webmail, password update and automated support. It may include your email domain or a generic account placeholder gathered from public website information or bulk address lists.
Step 3: The update button opens a counterfeit portal
The link leads away from the hosting provider to a page that copies the appearance of cPanel, Roundcube or another webmail service. Logos and login boxes can be duplicated in minutes; the domain in the address bar is the important detail.
Step 4: The form captures the mailbox credentials
The victim is asked to enter an email address and current password. Some pages request the password twice, display a fake error or ask for a one-time code to make the process feel like a real account update.
Step 5: Attackers establish access and persistence
After signing in, criminals may create forwarding rules, add recovery methods, generate app passwords or keep an active session. These changes can let them monitor the mailbox even after the owner changes the visible password.
Step 6: The trusted domain is used for further fraud
The compromised address can be used for invoice redirection, password-reset attacks and messages to customers or coworkers. If the same password protects hosting, WordPress or the domain registrar, the website itself may also be at risk.
Red Flags in the Fake cPanel Email
- A sudden cutoff date. The message threatens loss of email access unless you act immediately.
- Vague account details. A masked placeholder or generic mailbox reference replaces a clear service notice.
- An unexpected password-update link. Reputable providers rarely ask customers to transmit an existing password through an email button.
- A sender unrelated to your host. The display name may say cPanel while the real address uses a free or unfamiliar domain.
- A destination that does not match your normal webmail URL. Look at the full address before entering anything.
- Requests for codes or repeated passwords. These can be attempts to defeat multi-factor authentication or confirm that stolen credentials work.
How to Check the Warning Without Using the Email
Open the webmail bookmark or hosting dashboard you already use. If there is a real security or service issue, it should appear there. You can also contact the hosting company using the support page on its official website.
- Do not trust the sender’s display name by itself.
- Compare the link with your normal cPanel or webmail domain.
- Check the hosting dashboard for alerts or required actions.
- Ask the hosting provider whether it sent the notice.
- Use a password manager; it will normally refuse to autofill on an unrelated phishing domain.
What to Do If You Received the cPanel Scam Email
Delete or report the message if you did not interact with it. Do not reply, call numbers inside it or click again to investigate. Forward it to your hosting provider’s abuse or security team if they request samples.
If you opened the page but entered nothing, close it and check the browser’s download list. Remove any unexpected file. Your mailbox password usually does not need changing solely because the page was displayed.
If you entered your webmail password
Assume the credentials were captured. Perform these steps from a clean device and start with the real hosting or webmail portal.
- Change the mailbox password. Make it unique and do not reuse the old password anywhere.
- Terminate active sessions. Revoke unfamiliar devices, IMAP clients, app passwords and connected applications.
- Enable multi-factor authentication. Secure both webmail and the hosting account when the provider supports it.
- Inspect forwarding, filters and delegates. Remove rules that copy mail, hide security notices or redirect replies.
- Review recovery information. Delete unknown phone numbers, secondary addresses and security questions.
- Check sent and deleted folders. Warn customers or coworkers if messages were sent in your name.
- Reset every reused password. Prioritize hosting, WordPress, domain registrar, billing and cloud-storage accounts.
If the mailbox belongs to a business or website
Contact the hosting provider and ask it to review login history and restore secure account access. Then inspect the hosting dashboard, FTP/SFTP users, database users, WordPress administrators and recent file changes.
- Confirm that the domain’s nameservers and DNS records have not changed.
- Check payment details and recent support tickets for unauthorized edits.
- Review website administrator accounts and remove unknown users.
- Notify staff about possible messages sent from the compromised address.
- Monitor invoices and payment requests for changes in bank details.
- Contact the domain registrar immediately if the same credentials were reused there.
If you approved a sign-in request or shared a code
Revoke the session immediately, change the password and reset multi-factor authentication. A one-time code can be enough to authorize a new device even when the criminal never learns the permanent second factor.
If you downloaded or ran a file
Disconnect the device from sensitive accounts and run a full security scan. Do not use that device to change business or banking passwords until it has been checked, because malware can capture the replacement credentials.
Frequently Asked Questions
Does cPanel require password updates by email?
Your hosting provider may require a security change, but an unexpected email link should not be trusted. Open the provider’s dashboard independently and confirm the notice there.
Is cPanel itself compromised?
No evidence in this campaign shows that cPanel was breached. The criminals are impersonating the brand and hosting a separate fake login page.
Can scammers take over my website with an email password?
They may be able to reset connected accounts through the mailbox. The risk is higher if the same password was reused for hosting, WordPress, FTP or the domain registrar.
What if the password no longer works?
Contact the hosting provider through its official support channel immediately. Ask it to lock unauthorized sessions, restore recovery details and review account changes.
The Bottom Line
The cPanel password-update email is a phishing trap, not a real mailbox deadline. Ignore the email button and use your normal hosting dashboard. If you entered credentials, secure the mailbox, hosting account, website and domain before attackers can turn one stolen login into a wider business compromise.