cPanel Failed Incoming Messages Email EXPOSED: Fake Quarantine Alerts Steal Logins

The subject sitting in the inbox is Failed Incoming Messages Report, which is the kind of host ticket people open before they finish coffee. You open it because a blocked purchase order is a Monday that will not wait, and a quarantined file sounds like work a panel actually sends when the mailbox is full.

The body writes in the calm voice of a system that already runs the server, and it regrets to inform you that some incoming messages were placed in quarantine because the attached files exceeded the allowed server quota. A small table sits under that apology, listing three items marked Read, with the subjects Revised PO, PO, and Orders, each stamped 8/17/2026 5:57:25 PM as if a clerk had already tried to file them. One orange control sits under the rows, labeled Review Quarantined Messages, and the footer signs as Roundcube Webmail Support, with a 2004-2026 copyright line and a reminder to keep storage limits maintained so future mail is not disrupted.

If a real purchase order is waiting, you get it from the thread you already have, or from the webmail you already open, rather than from a surprise table that arrived with three identical timestamps. Leave this card where it is while you check the mailbox the way you always check it. A quota report that cannot wait for a page you type is asking you to hurry for a reason that is not on the table.

Outlook view of a Failed Incoming Messages Report email with a Review Quarantined Messages button and a table of quarantined purchase orders

Overview

Review Quarantined Messages is not a folder your host already keeps for oversized attachments, and it does not open a queue you can print, forward, or compare with last week’s mail. The click leads to a page that drops a Re-Authentication Required overlay onto a familiar-looking error screen and asks for the mailbox password so a repair can continue. There is no quarantined Revised PO waiting behind that overlay, and there is no Orders file a clerk already tried to save, because the overlay is collecting the login for the inbox you are already sitting in.

What they take first is the password for that mailbox, and after that they take the mailbox itself. That includes the threads with vendors, the reset codes that land an hour later, and the people who already answer when your name is on the From line. A quota story is useful costume for that harvest, because a blocked incoming file sounds like operations rather than like a stranger asking for a secret. A table of purchase orders makes the errand feel like work you already meant to finish, which is why the three rows are there. Once the overlay has the password, the people who wrote the report can read the real mail, impersonate the address, and reset other logins that all send their recovery mail to the same place.

cPanel, L.L.C. is a real company, and Roundcube is a real webmail project that hosts around the world actually install, which is exactly why those names are useful on a From line. Anyone can type cPanel Webmail Support into a display name, and anyone can paste a 2004-2026 Roundcube copyright onto a footer, which means a tidy heading does not prove that a control panel quarantined three messages for you. Neither product collects a mailbox password through a surprise Review Quarantined Messages button in a cold quota report, and a real vendor does not need you to prove you own a box that just received mail. If you need the real control-panel company, type cpanel.net yourself in a new tab, then look at mail from a page you already trust.

The overlay copies the inbox rather than copying a quota dashboard, which is why Gmail users often see a Google-looking box, while other addresses get the colors and labels that already match their own provider. Your address may already be sitting in the username field, and the overlay will say re-authentication is required to continue a repair, which is a polite way of asking for the same password you used to open Outlook. One copy of that next page has sat on wittenhorst.eu, which is not a host you type for webmail, and which is not a reason to go hunting the address after you close the tab.

The Federal Trade Commission describes this shape in ordinary language in How To Recognize and Avoid Phishing Scams, where it says criminals use email to steal passwords, account numbers, or Social Security numbers. A common story, the Commission adds, is a problem with an account when there is no problem, which is exactly how a fake quarantine report earns a click. Another common story is that you must confirm personal information right now, when you do not, and the Commission’s advice is to contact the company with a phone number or website you already know is real, not with the information in the unexpected message. A Review Quarantined Messages button that arrived inside a Failed Incoming Messages Report is information in the email, which is why it is a poor place to start a quarantine review.

CISA says the same thing from the systems side on avoiding social engineering and phishing, where it tells people not to reveal personal or financial information in email. It also tells people not to use a link from a surprise message to reach a login they already have, which is the whole move inside Review Quarantined Messages. If a quarantine report feels off, you verify it without using anything in the report, which is the opposite of typing your mailbox password so three purchase orders can finish delivering. Microsoft’s guide to spotting phishing adds a practical check that fits this letter: treat a mismatched sender as a warning, and slow down when a message wants an immediate click through a button you did not request.

A real quota problem can exist, because hosts do cap mailboxes, and oversized attachments do bounce, and a panel you already pay can show you a storage bar without asking you to retype the password on a stranger’s overlay. That check still lives on a page you reach the way you always reach the account, by opening the webmail bookmark you already keep or by typing the host you already pay, not by letting a cold table choose the next screen. The letter already arrived in the mailbox it claims is too full to accept mail, which is a contradiction you can sit with for a moment longer than the orange button wants you to.

How The Scam Works

1. A quarantine report lands

The message arrives in the same Outlook or hosted webmail you already trust, with the subject Failed Incoming Messages Report, and with a display name that says cPanel Webmail Support as if a panel desk had a queue. There is no long pitch and no attachment you have to open, and the whole card fits on a phone screen on purpose, because a short quarantine report is easier to believe than a letter that asks for a Social Security number in the first line. If you are already signed in to webmail, the folders on the left and the search bar on the top make the fake note feel native, and you are not visiting a strange site yet because you are still reading mail.

The letter only has to survive the few seconds between the subject and Review Quarantined Messages, and people who would ignore a lottery note will still open a quarantine report that looks like the host they already pay. Accounts payable lives on that kind of dread, and so does anyone whose job is to keep purchase orders moving through a Monday, because a blocked PO is a vendor who thinks you went silent. A table of three Read items is enough to invent the rest of the afternoon, whether that is a revised order, a client who will not wait, or a domain the boss will ask about, and the costume only has to last until the button.

2. The name copies cPanel webmail

cPanel is not a made-up control panel invented for one inbox, and Roundcube is not a made-up webmail invented for one footer, which is the load-bearing detail of the costume. You do not need a long story when the letterhead already sounds like the window you use to read mail and the panel your host uses to run that mail. Those names already live in the muscle memory of people who keep a domain mailbox, which is why the costume works in a few seconds. The people who wrote the letter are not the cPanel company and are not the Roundcube project, even though they borrowed both names so a five-second glance would survive. An orange bar plus a 2004-2026 copyright line do the rest of that glance, and neither line is a certificate you can take to a real help desk.

A real desk would not need that costume, because a real desk already has a panel you can open without a surprise button, and a thief does need it, because the thief is not inside the product and is not inside your host. Display names are cheap, and anyone can set From to cPanel Webmail Support, which Microsoft’s phishing page treats as a reason to slow down rather than as a badge you can trust. The names are there so you will skip the check, and a support desk you already pay does not need a cold overlay to prove you own the mailbox it just delivered mail into.

3. Quota and blocked mail are the hurry

The body does not threaten arrest or dangle a prize, and instead it regrets that incoming messages were quarantined because attached files exceeded the allowed server quota, which is a quieter hurry than a lockout clock. Revised PO, PO, and Orders are the filenames a busy desk already fears losing, and they are stamped 8/17/2026 5:57:25 PM as if the same second had caught three different files, which is specific enough to feel like a log and sloppy enough to be a template. Please ensure your storage limits are maintained to prevent future disruptions is the second beat of the same hurry, because disruption is a word hosts actually use, and because it turns a maybe later into a now.

Urgency is the point of the quota claim, not evidence of a real storage bar that a host would enforce through a button in a cold email. A real quota problem, when a host actually has one, is visible inside the panel you already open, and it usually comes with a path you can walk without proving your password to a stranger. A fake one cannot wait, because the people who wrote it need you to press Review Quarantined Messages before you read the address bar and before you notice that the same mailbox just received the warning it claims it could not accept.

4. Review Quarantined Messages is the handoff

You click Review Quarantined Messages because that is what a review link is for, and the click is the moment the quota costume can drop. The next page is not a quarantine folder with three files you can download, and it is not a log of oversized attachments you can match against last week’s mail. It is a door to a page the letter already picked, and there is no honest reason for a quarantine review to live on a surprise site you reached from an unexpected email. You are already sitting inside the mailbox that supposedly could not take the files, which is the contradiction the orange button hopes you will not sit with.

A real review would open inside the webmail you already use, or it would sit as a banner on the panel your host already gave you, and it would not ask you to prove you are you so a purchase order can finish landing. It would not need a fresh login to show you mail that the same account just listed as Read. CISA tells people not to follow a link in a message that then asks for that kind of information, and Review Quarantined Messages is the detour from a letter you trust to a page you should not finish. The button is written as a folder you can open, and what it actually does is hand you off to a page the letter already chose.

5. Re-authentication copies the inbox

When the destination loads, the background often looks like an ordinary provider error, which is a useful stage set because an error feels like a system talking rather than like a stranger asking for a key. On top of that screen sits an overlay titled Re-Authentication Required, with your address already filled in, and with a password field that claims a repair cannot continue until you sign in again. The overlay identifies the provider from the address it already has, so a Gmail mailbox gets a Google-looking box, and other mailboxes get the layout they already see every morning. That is how a quarantine report turns into a copied inbox without changing the story on the button, and it is why the overlay feels like a continuation rather than like a new request.

Padlock icons and HTTPS do not establish that the overlay belongs to the host it imitates, because they only mean the connection to that particular page is encrypted. Your address sitting in the box can feel like recognition even though the address was taken from the message, the link, or the bulk list that received the same report. Do not finish that form to see whether the three purchase orders then appear, because a copied login does not become safer when you only wanted a quarantined PO. The address in that tab is a door you should stop using rather than a clue you need to collect, and a screenshot with the link unclicked is enough if you need a second pair of eyes.

6. They want the mailbox password

If you type the password they have the first key, and if a text, an authenticator prompt, or an email code arrives while that overlay is still open they want the second key too. The story will sound helpful, asking you to confirm so the repair can continue, or to approve so the quarantined files can be released. It may also ask you to enter a code to verify your work account, and each line is the same request for access to the mailbox you were already sitting in. The Failed Incoming Messages Report was never sitting behind that box, because the mailbox was, and the people who wrote the letter designed the quota table so you would not notice the swap.

Microsoft’s phishing page tells you to change the password on every affected account if you think you typed it on the wrong site, and to turn on multifactor authentication if it is not already on, which is the same advice the FTC gives in consumer language. Treat the password as burned and treat the code as burned, and do not reuse either one on the next page that promises to unlock a quarantine folder. You should not type the same password into the host, the bank, or payroll as a courtesy refresh, because a copied overlay does not get to supervise those other accounts either. Change those passwords on sites you open yourself, one at a time, after the fake tab is gone, because a copied overlay does not get to watch the rest of the recovery.

Once they can open the account they are not hunting for a Revised PO that exceeded a quota, because they are reading the last invoice you sent and the last invoice you received. They also read the thread with a vendor who pays by wire, and then they write the next message in your voice, which is how a quarantine report becomes a payment problem. A bill that looks like last month’s bill is enough, and a new-account, same-firm line is enough, and if they add a forwarding rule they can keep a copy after you change the password until someone deletes the rule. A compromised mailbox is not a nuisance in that setting, because it is a way to move a payment without ever calling you again, which is why a quarantine report that asked for a password was never about a blocked purchase order.

7. A second crew sells recovery

The last move is often social, and it may not even be the same people, because a day later you can get a call, a text, or a fresh email that already knows you opened a Failed Incoming Messages Report. They will offer to release the quarantine, raise the quota, or recover three purchase orders you never received, and then they will ask for a code, a remote-access session, a second password, or a cleanup fee. Hang up, because a stranger who found you is not your incident responder, and a cPanel or Roundcube desk that called you after Review Quarantined Messages is not the product whose name was printed on the card.

That is why a quiet admission that you already clicked, even if you did not pay anyone, is not the end of the story, because you may not have paid while the person who trusts you might. Tell the people who send you money and the people you pay, and tell a real coworker, if you actually share the mailbox, on a number you already have rather than on a number that arrived after Review Quarantined Messages. A 30-second call from you is cheaper than a week of wires that look like your week, and the second crew is counting on shame to keep you quiet long enough for the first crew’s mail to land.

What To Do If You Have Fallen Victim to This Scam

If you only opened the email and closed it without following the button, you are not finished with the message, but you are not looking at a device infection from reading alone. If you pressed Review Quarantined Messages and then typed a password, a code, or personal information, treat the account as touched and move in this order, because speed matters more than naming the exact kit they used. The goal is to take the mailbox back before someone else sends the next purchase order or invoice in your name.

  1. Write down what you typed, including the time and the subject Failed Incoming Messages Report, then stop using that tab. Note the three table rows labeled Revised PO, PO, and Orders, whether you entered a password, and whether you approved a code or an app prompt. Close the overlay and do not keep checking it to see if a quarantined file appears, and do not forward the live button to a friend so they can look. Send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.
  2. Open your real mail yourself in a new tab you type, then change the password to one you have not used anywhere else. Use the official site or the app you already trust, and do not return to the quarantine report for a reset link. If this is a Microsoft account, follow Microsoft’s steps to recover a hacked or compromised Microsoft account. If you cannot sign in, use the official reset path, not a link from the quarantine report, and if this is Gmail or a workplace portal, open that product the same way from an address you typed.
  3. Sign out of other sessions everywhere you can, then turn multifactor authentication back on before you do anything else with the mailbox. Review recent activity and sign out of sessions you did not start, then confirm the extra lock is on, preferably with an authenticator app, a passkey, or a security key rather than a text message alone. If you approved a prompt you did not start, assume that session is not yours until you kill it, and remove recovery phones and recovery addresses you did not add. A password change that leaves an old session running is only half a change, and if you reused that password on banking, payroll, or the hosting panel, change those on their own sites after you type those sites yourself.
  4. Look for inbox rules, automatic forwarding, and mail that left without you, because those are the quiet ways a stolen mailbox keeps working after a password change. Check the Sent folder and look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create, search for other Failed Incoming Messages Report notes you did not expect, and if this is a work account, call IT before you spend an hour hunting, because they can dump sessions and pull the audit faster than you can. Also look at Deleted, Junk, and custom folders, because an attacker who is already inside often hides the security alerts that would have told you they were there.
  5. Protect every account that shares the inbox, starting with banking, cloud storage, shopping, social media, payroll, and the hosting panel that sends reset mail to the same address. Replace reused passwords while you revoke suspicious sessions on those sites too, after you type those sites yourself rather than following anything in the report. If personal, financial, or identity information went into the overlay, contact the relevant bank or provider directly using a number from a statement or a card in the drawer, not a number that appeared after Review Quarantined Messages. United States victims can use IdentityTheft.gov to build a recovery plan based on the information that was stolen, which is more useful than waiting to see whether a vendor already paid on a fake PO.
  6. Tell the people who might get the next copy of this letter, including contacts who already received messages from your account this week. Warn them not to open unexpected quarantine or purchase-order links that appeared to come from you, and tell them to call you on a number they already have. If you handle invoices, payroll, or vendor payments at work, tell your administrator the same day, because a hijacked mailbox can change payment instructions in a thread that already looks like yours. A 30-second call on a number you already have is cheaper than a week of wires that look like your week, and shame is the delay the second shift is counting on.
  7. Report the email through the controls your mail product already publishes, then scan the device if Review Quarantined Messages saved a file or pushed a viewer. In Outlook, use Report and then Report phishing, the path Microsoft publishes on its phishing help page, and in Gmail use Google’s reporting control from the same phishing help page they publish for this. Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org, file at the FTC’s ReportFraud site, and send a cyber report to the FBI’s IC3 if money or identity data moved. If Review Quarantined Messages saved a file or pushed a viewer, run a full scan with Malwarebytes or the antivirus you already keep updated, knowing that the scan does not get a password back and the password change does that.

If someone forwarded you the notice, send them this page instead of the Review Quarantined Messages button, because these quota reports travel in office threads when they look like work. Do not install a new cleaner you just searched for because a follow-up email recommended it, and do not approve a remote-access session for a person who already knows the subject line and offers to release the quarantine. A stranger who found you after Failed Incoming Messages Report is not your incident responder, and a recovery desk that called you after Re-Authentication Required is not the product whose name was printed on the orange bar.

If you actually keep mail on a host that uses cPanel or Roundcube, treat this letter as a reminder to open that product from a bookmark you already keep, not from mail, and look at the real storage bar and the real inbox. If the panel shows no quarantine, then no quarantine is waiting, and if a real attachment did bounce, it will still be sitting in a bounce you can read without typing a password into an overlay. A fake quota report does not become real because you were waiting on a purchase order, and waiting is the opening they wrote the subject for.

The Bottom Line

A note that says Failed Incoming Messages Report, arrives as cPanel Webmail Support, and writes as Roundcube Webmail Support is a login hunt wearing a quarantine folder. It claims incoming mail was quarantined because attachments exceeded quota, lists Revised PO, PO, and Orders at 8/17/2026 5:57:25 PM, and offers Review Quarantined Messages as if those three files were waiting behind a button. The products whose names were borrowed are real, and they are not the senders of this mail, and they do not ask you to re-authenticate on an overlay from an unsolicited inbox notice just to see three purchase orders. Review Quarantined Messages is how they get you onto that overlay, Re-Authentication Required is how they collect the password, and the mailbox is what they use next, including the contacts, the reset codes, and the vendor threads that already trust your name.

Open the mail service you already pay by typing it yourself if you need to know whether anything is wrong with the account, and open the host panel the same way if you need to know whether a real quota bar is red. If you already typed the password, change it on the provider’s own page, kill the other sessions, inspect forwarding rules, and tell the people who send you money before the next email goes out as you. The quarantined files were only costume for a password harvest, and Review Quarantined Messages was how they asked you to hand the inbox over.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Swedish Yellow Vitamin Neuropathy Scam Exposed: Fake Cure Investigation

Next

Payroll Statement Email EXPOSED: Fake Pay Stubs Steal Logins