Confidential Messages Queued Email Scam: Password Trap

The subject line says this is your final warning. Somewhere inside your mailbox, the email claims, a confidential message is waiting and compliance requires you to review it now.

That sense of unfinished business is the bait. The Confidential Messages Queued email scam leads to a counterfeit webmail sign-in page built to capture the username and password you normally use to read email.

Reconstructed Confidential Messages Queued phishing email
Reconstructed example of the Confidential Messages Queued phishing email. This illustration is not the original message.

Overview

The Confidential Messages Queued email scam impersonates an automated message from an email provider or an organization’s secure messaging system. An observed version used the subject “Action Required – Final Warning!” and claimed that a confidential message had been queued for review.

The email does not identify a real sender, explain what the message concerns, or provide a verifiable ticket number. Instead, it says that reviewing the message is necessary to “maintain compliance” and protect the recipient’s email account.

The alert invents a problem that cannot be checked inside the email

A vague pending message is difficult to disprove. It could sound like a legal notice, an HR communication, a customer request, or an encrypted message from a colleague. That ambiguity encourages a cautious employee to investigate.

The supposed solution is a “Review Messages” button. The button does not open a genuine mailbox feature. It sends the recipient away from the provider’s normal website and toward an attacker-controlled login flow.

The fake sign-in adapts to the person being targeted

The phishing page may place a Roundcube-style login box over a background that resembles Gmail or another familiar provider. Other versions can change the colors, logo, or background according to the recipient’s email domain.

This visual matching is not evidence that the page belongs to the provider. Phishing kits can read an address included in the link, extract the domain, and load an appropriate template before the victim types anything.

The real target is access to the inbox

  • The recipient’s full email address and current password
  • One-time codes or approval prompts requested after the password
  • Private messages, attachments, contacts, and calendars
  • Password-reset links for other services connected to the inbox
  • Business conversations that can support invoice or impersonation fraud

Roundcube, Gmail, and legitimate email providers are not responsible for this campaign. Their names and interface styles are copied because people recognize them and may enter credentials without first checking the page address.

What the “Confidential Message” Claim Is Really Doing

“Confidential” discourages ordinary verification

The word suggests that the contents should not be discussed openly. A recipient may hesitate to forward the email to a colleague or ask whether anyone else received it, which gives the scam more room to work.

Real confidential systems still provide a recognizable service name, an established portal, and a way to verify the notification independently. Secrecy is not a reason to trust an unidentified button.

“Queued” makes the message sound technical

Queued email is a real concept, but the term is misused here. A normal delivery queue is managed by mail servers. End users are not generally required to submit their mailbox password through a message link to release one email.

Secure-message portals may notify recipients about protected content, but users should reach those portals through a known bookmark or the organization’s official website. The notification itself should not be the only proof that the portal exists.

“Maintain compliance” creates workplace pressure

Compliance language sounds serious while remaining conveniently unspecific. The message does not name a regulation, policy, case, administrator, or retention rule. It simply implies that delay could put the recipient at fault.

Scammers benefit when an employee worries more about missing a required action than about checking the destination. A real compliance team can confirm its own notice through internal channels.

How the Confidential Messages Queued Email Scam Works

Step 1: The campaign reaches a personal or business inbox

Attackers send the message to addresses collected from data breaches, public company pages, professional profiles, mailing lists, or earlier compromises. The campaign may be broad, even when the email address appears personalized.

A business address can be especially valuable because it may provide access to cloud files, internal contacts, customer records, and trusted conversations.

Step 2: A final-warning subject creates urgency

The subject suggests that earlier notices were ignored, even if none were sent. The recipient is placed in the uncomfortable position of feeling late before the message has been evaluated.

A date or countdown may be included to make the alert feel generated by a system. Urgency is a persuasion device, not proof of authenticity.

Step 3: The body describes a confidential pending message

The email says action is required but withholds the information needed to judge the request. There is no sender name, subject preview, service history, or reliable support contact.

This information gap is intentional. Curiosity and concern push the recipient toward the only visible route, the review button.

Step 4: The review button opens an unrelated website

An observed campaign used a compromised or abused third-party domain rather than the official domain of an email provider. Future versions may rotate through newly registered sites, hacked websites, redirectors, or cloud-hosting services.

The exact address can change quickly. What matters is that the destination is not the normal login page reached by typing the provider’s address independently.

Step 5: A familiar webmail screen appears

The page may show a Roundcube login over a Gmail-like background, or it may imitate Microsoft 365, Yahoo, or a private webmail portal. The recipient’s address may already appear in the username field.

Prefilling an address only proves that it was passed through the link or recorded earlier. It does not show that the provider recognized the user.

Step 6: The fake form records the password

When the victim selects “Sign in,” the form sends the entered credentials to infrastructure controlled by the phisher. The page may then claim the password was incorrect and ask for it again.

That second prompt can collect alternate passwords or make the victim believe the first attempt failed harmlessly. The first submission should be treated as exposed.

Step 7: The attacker tests the real account

Criminals may sign in immediately, use automated tools, or sell the credentials to another group. If multifactor authentication is enabled, the victim may receive a real approval prompt or be asked for a one-time code.

Approving an unexpected prompt can complete the takeover. Repeated prompts are sometimes used to wear down the account owner.

Step 8: The mailbox is used for further fraud

Inside the account, an attacker can read sensitive mail, request password resets, steal documents, and impersonate the victim. Hidden forwarding rules may be created so future messages are copied outside the organization.

A compromised business account can be used to enter real invoice threads or send phishing links to colleagues. The original fake notification may disappear, while the more damaging activity continues quietly.

Warning Signs You Can Check Before Clicking

  • The subject uses “final warning” even though no earlier notice exists.
  • The message refers to compliance but names no policy or administrator.
  • The confidential sender and the message subject are both withheld.
  • The sender domain does not match the recipient’s real provider or organization.
  • The button leads to an unrelated, misspelled, compromised, or cloud-hosted address.
  • A message-review page asks for the same password used for the entire mailbox.
  • The login interface combines branding from two different email services.
  • The page requests a one-time code after an unexpected password prompt.

Polished design cannot cancel these inconsistencies. A familiar logo can be copied in seconds, while the page address and the surrounding workflow reveal who is actually asking for the password.

How to Verify a Pending Secure Message Safely

Open the mailbox through your normal route

Close the notification and use your saved bookmark, official app, or a web address you type yourself. Check notifications, quarantine, secure messages, and account alerts after signing in normally.

If no matching notice appears, do not return to the email button. A legitimate service should make the same pending item visible inside the authenticated account.

Ask the administrator through a separate channel

For a work account, contact IT or the security team using the help desk details already provided by the organization. Include the subject, sender, and time received without clicking the link.

Do not call a number supplied only by the suspicious email. An attacker can operate both the fake page and the supposed support channel.

Inspect the full sender and destination

Display the complete From, Reply-To, and return-path information when possible. Hover over the button on a computer to preview the destination without opening it.

A long address can hide its true registered domain among subdomains and paths. Read from the domain ending backward and compare it with the provider’s documented domains.

Preserve the message for investigation

Report the email using the mail client’s phishing function or forward it as an attachment to the security team. Forwarding as an attachment preserves headers that can help identify other recipients and block related messages.

What an Attacker Can Do With Email Credentials

Email is often the recovery channel for banking, shopping, social media, cloud storage, and workplace services. Control of the inbox can let an attacker reset passwords even when the original password was not reused.

Private conversations also provide context. A criminal can learn how the victim writes, who approves payments, when someone is traveling, and which vendors are expecting money.

For a business, the attacker may search for words such as “invoice,” “wire,” “payroll,” and “contract.” They can then reply inside a genuine thread, making a fraudulent request much harder to spot.

Contacts may receive phishing from the real account. Recipients who would ignore an unknown sender may trust a colleague’s address, signature, and conversation history.

How Organizations Can Reduce This Risk

Use phishing-resistant multifactor authentication where available and require reauthentication for sensitive changes. A strong second factor can prevent a stolen password from becoming a successful sign-in.

Monitor for unfamiliar forwarding rules, impossible travel, new authentication methods, and unusual downloads. Fast alerts shorten the time an intruder can remain inside a mailbox.

Train employees to open secure portals independently. Awareness exercises should include generic webmail alerts, not only messages that misuse famous delivery or banking brands.

Give staff a simple reporting path and respond without blame. People report faster when they know that an accidental click will be handled as an incident to contain, not a mistake to hide.

What to Do if You Have Fallen Victim to This Scam

  1. Stop interacting with the page. Do not retry the password, submit a second password, or approve any sign-in request.
  2. Use a clean route to the real provider. Open the official app or type the provider’s known address instead of following the email link.
  3. Change the exposed password immediately. Create a strong, unique password that is not used by any other account.
  4. Replace every reused password. Prioritize financial, cloud, workplace, and social accounts connected to the same email address.
  5. Sign out active sessions. Revoke unfamiliar devices, app passwords, connected applications, recovery methods, and authentication tokens.
  6. Inspect the mailbox. Check forwarding, filters, delegates, automatic replies, sent mail, deleted mail, and recent security activity.
  7. Strengthen multifactor authentication. Remove methods you do not recognize and use an authenticator app or security key when the service supports it.
  8. Tell your organization promptly. A security team can search for other recipients, block the infrastructure, review logs, and warn contacts.
  9. Warn people who received unusual messages. Use another trusted channel and tell them not to follow recent links or payment instructions.
  10. Review linked accounts. Look for password resets, changed bank details, purchases, file access, or profile updates that you did not make.
  11. Scan the device if anything downloaded. Malwarebytes can check for information stealers, malicious extensions, and remote-access tools that may have accompanied the phishing page.
  12. Report and block the campaign. Submit the original email to your provider and security team. AdGuard’s web filtering can add another barrier when a future link points to a recognized scam site.

Is Your Device Infected? Run a Free Malware Scan

Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Anti-Malware Free — one of the most trusted malware removal tools available.

The free version detects and removes the most common threats, including:

  • Adware — the cause of those annoying pop-ups
  • Browser hijackers — unwanted redirects and changed homepages
  • Trojans and spyware — hidden programs stealing your data
  • Potentially unwanted programs (PUPs) — software you never asked for

👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The whole process takes about 5 minutes.

Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android

Run a Malware Scan with Malwarebytes for Windows

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

When the scan finishes, click Quarantine to remove everything Malwarebytes found. That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.

If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:

Run a Malware Scan with Malwarebytes for Mac

Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.

  1. Download Malwarebytes for Mac

    Click the button below to download the latest version of Malwarebytes for Mac.

    DOWNLOAD MALWAREBYTES FOR MAC (FREE)
    (The link opens in a new page where your download will start)
  2. Open the Malwarebytes setup file

    When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

    Double-click on setup file to install Malwarebytes

  3. Follow the On-Screen Prompts to Install Malwarebytes

    The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.

    Click Continue to install Malwarebytes for Mac

    Click again on Continue to install Malwarebytes for Mac

    Click Install to install Malwarebytes on Mac

    When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.

  4. Select “Personal Computer” or “Work Computer”

    Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
    Select Personal Computer or Work Computer mac

  5. Start the Scan

    Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
    Click on Scan button to start a system scan Mac

  6. Wait for the Scan to Finish

    Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
    Wait for Malwarebytes for Mac to scan for malware

  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
    Review the malicious programs and click on Quarantine to remove malware

  8. Restart Your Mac

    Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
    Malwarebytes For Mac requesting to restart computer

Once the scan is done, remove every threat it detected. Your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.

If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.

Run a Malware Scan with Malwarebytes for Android

Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.

  1. Download Malwarebytes for Android.

    You can download Malwarebytes for Android by clicking the link below.

    MALWAREBYTES FOR ANDROID DOWNLOAD LINK
    (The above link will open a new page from where you can download Malwarebytes for Android)
  2. Install Malwarebytes for Android on your phone.

    In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

    Tap Install to install Malwarebytes for Android

    When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
    Malwarebytes for Android - Open App

  3. Follow the on-screen prompts to complete the setup process

    When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
    This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
    Malwarebytes Setup Screen 1
    Tap on “Got it” to proceed to the next step.
    Malwarebytes Setup Screen 2
    Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
    Malwarebytes Setup Screen 3
    Tap on “Allow” to permit Malwarebytes to access the files on your phone.
    Malwarebytes Setup Screen 4

  4. Update database and run a scan with Malwarebytes for Android

    You will now be prompted to update the Malwarebytes database and run a full system scan.

    Malwarebytes fix issue

    Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

    Update database and run Malwarebytes scan on phone

  5. Wait for the Malwarebytes scan to complete.

    Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning Android for Vmalware

  6. Click on “Remove Selected”.

    When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
    Remove malware from your phone

  7. Restart your phone.

    Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.


After the scan, tap Remove Selected to delete all detected threats. Your Android phone is now clean — no more malicious apps, adware, or browser redirects.

If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:

Stay Protected: Block Ads and Malicious Sites

Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.

We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.

👉 Download AdGuard and browse safely

Frequently Asked Questions

Is a confidential message really waiting for me?

The email provides no reliable proof. Sign in through your provider’s official app or website and ask your administrator independently. Do not use the review button to find out.

Why does the page already know my email address?

The address can be embedded in the phishing link or collected from the mailing list. A prefilled username does not mean the page is connected to your provider.

Is Roundcube itself unsafe?

No. Roundcube is legitimate webmail software. Scammers copy its sign-in appearance just as they copy other recognizable services.

Am I compromised if I only opened the link?

Credential theft usually requires entering information, but a malicious page can also attempt downloads or exploit outdated software. Report the click, close the page, update the device, and scan it if anything unusual occurred.

What if the fake page said my password was wrong?

Assume the password was captured. Fake error messages are commonly used to request another entry or hide the successful theft.

Can multifactor authentication protect me?

It provides important protection, but you must reject unexpected prompts and never give a one-time code to a page reached through a suspicious email. Phishing-resistant methods offer stronger protection.

The Bottom Line

The Confidential Messages Queued email scam turns a vague compliance warning into a counterfeit webmail sign-in. The missing sender, unexplained urgency, and unrelated destination are stronger evidence than any familiar logo on the page.

Open your mailbox through its official route and verify secure-message notices with the real administrator. If you entered a password, change it immediately, revoke sessions, inspect mailbox rules, and report the incident before the account is used against your contacts.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Secure Adobe PDF Credit Card Email Scam: Credential Trap

Next

Mail Services Disable Notice Email Scam: Fake Restriction