Webmail Password Reset Request Scam: Fake Cancel Login Fully Exposed Now

A password-reset warning can feel routine until it says your mailbox will disappear. That small jolt of uncertainty is exactly what this message is built to create.

The email looks administrative, uses familiar account language, and offers an obvious way to stop the change. Before pressing anything, there are important details worth examining.

Fake Webmail Password Reset Request email with a Cancel Reset button

Overview

What the message claims

The Webmail Password Reset Request email says somebody asked to deactivate or reset the recipient’s mailbox. It presents the request as a recent, pending account action.

One observed version displayed a request time and warned that the option to object would expire after 48 hours. A prominent “Cancel Reset” button offered apparent relief.

Nothing in the email proves that a real administrator created the request. Its wording is designed to make recipients react before checking their provider’s genuine account portal.

What the sender actually wants

The button does not safely cancel anything. It leads toward a counterfeit webmail sign-in page controlled by criminals, not the organization that manages the mailbox.

Any email address and password entered there can be collected immediately. The fake page may then show an error, redirect elsewhere, or quietly stop responding.

The message is therefore a credential-phishing attempt. Its real objective is account access, which can expose conversations, saved documents, contacts, password resets, and business records.

The clearest warning signs

  • An unexpected reset or deactivation request arrives without prior account activity.
  • The sender uses generic Webmail or Mail Services branding instead of a recognizable provider identity.
  • A short deadline pressures the recipient to use an embedded button.
  • The linked page asks for a password before explaining or confirming the supposed request.
  • The destination domain does not match the organization’s normal webmail address.
  • The notice provides no trustworthy ticket number, administrator contact, or independently verifiable account event.

The combination matters more than one awkward sentence. Professional-looking spacing and familiar colors cannot authenticate an email or the website opened from it.

How the Webmail Password Reset Request Scam Works

Step 1: The email creates a believable account emergency

Criminals begin with a subject and opening line that resemble an internal service notification. Password resets and mailbox changes are common enough to sound plausible.

The warning is deliberately personal without containing much personal information. It may repeat the recipient’s address, which is already visible to anyone who sent the message.

A precise time can make the event feel recorded by a real system. However, a timestamp is simple text and offers no evidence of a genuine administrative log.

The threat is usually loss of access, deactivation, or an unwanted password change. Each possibility encourages immediate action because email connects to so many other accounts.

Step 2: A deadline narrows the recipient’s attention

The 48-hour expiration claim introduces urgency without sounding as frantic as a five-minute warning. That makes the message appear more measured and potentially more credible.

Recipients are guided toward a single decision: approve the change through inaction, or press “Cancel Reset.” The safer third option, opening webmail independently, is not emphasized.

This framing is a classic social-engineering technique. It turns a suspicious link into what seems like a protective button, reducing the hesitation that normally surrounds unexpected messages.

Step 3: The Cancel Reset button opens a counterfeit portal

The visible button can hide an unrelated destination. On desktop mail clients, hovering may reveal it, but shortened links and redirectors can make inspection less straightforward.

The landing page copies a generic login panel or imitates the recipient’s provider. Branding may be loaded dynamically after the visitor’s email domain is recognized.

The address bar remains the most useful clue. A convincing logo inside the page cannot make an unrelated domain legitimate.

Fake webmail login page opened by the Cancel Reset button

Some fake portals prefill the email address, making the page feel connected to the mailbox. That address may simply have been passed through the link itself.

Others display a loading animation or security message before showing the password field. These pauses imitate normal authentication while the page prepares its collection form.

A padlock does not settle the question. Phishing sites can use encrypted connections, so the page address and its ownership remain more important than connection encryption.

Step 4: Submitted credentials are sent to the attacker

When the victim presses Sign In, the form transmits the entered details to infrastructure selected by the scammer. No real reset request needs to exist.

The page may reject the first password and request it again. This can help criminals capture alternate passwords when victims assume they mistyped the original one.

After collection, the visitor might be forwarded to a real login page. The successful second attempt can hide the theft because the eventual destination behaves normally.

Stolen credentials may be tested automatically within minutes. Delaying a password change gives an intruder time to establish access and inspect valuable messages.

Step 5: The mailbox becomes a route into other accounts

Email access is unusually powerful because password-reset links for shopping, banking, cloud storage, social media, and workplace services often arrive in the same inbox.

An intruder can search for invoices, contracts, tax documents, identification records, and conversations about payments. That information supports more convincing fraud against the account owner’s contacts.

Business mailboxes can expose internal discussions and vendor relationships. A criminal may wait for a genuine payment conversation, then insert altered bank instructions at a believable moment.

Attackers also examine sent mail to understand writing style. Replies written in the victim’s tone are harder for colleagues and relatives to recognize as fraudulent.

Step 6: Persistence hides the compromise

Changing the password is not always enough after account entry. A criminal may create forwarding rules, add recovery details, authorize an application, or preserve an active session.

Mailbox rules can quietly move security notifications into Trash or Archive. The owner sees fewer warnings while copies of incoming messages continue reaching another address.

Connected applications may retain access through tokens even after the visible browser session ends. Reviewing authorizations is therefore an essential part of recovery.

A compromised account may later send the same lure to trusted contacts. Familiar senders reduce suspicion and help the campaign spread through workplaces or personal address books.

Why This Phishing Email Can Look Convincing

The message borrows the plain style used by many real hosting panels. Sparse branding can seem normal when small organizations rely on generic webmail systems.

Its button also appears defensive. People are accustomed to selecting “This wasn’t me” in legitimate alerts, so “Cancel Reset” matches an established security habit.

The criminals do not need perfect grammar when the core story fits a familiar situation. A recipient who recently changed settings may connect that real event to the false warning.

Remote work adds another complication. Employees may not know whether an administrator initiated maintenance, especially when mail services are managed by an outside provider.

That uncertainty should lead to independent verification, not interaction with the email. A legitimate administrator can confirm an event through a known channel.

How to Verify a Webmail Password Reset Notice

Open the account from a trusted route

Use a saved bookmark, your organization’s portal, or an address supplied by the administrator. Do not reach the account by copying the suspicious button’s destination.

Look for recent security activity after signing in normally. A real reset, recovery change, or deactivation request may appear in the account’s own event history.

Inspect the actual sender and destination

Expand the sender details rather than trusting the display name. Compare the domain character by character with earlier messages known to be legitimate.

Hover over the button without clicking. If the destination is unrelated, misspelled, newly introduced, or hidden behind an unfamiliar redirect, treat it as hostile.

Ask the administrator through a known channel

Call the support number already stored in company documentation or contact the usual administrator directly. Never use contact information supplied only inside the questionable email.

Give them the subject, arrival time, and sender address. They can check server logs without asking you to submit a password through a message link.

Examine the request logic

Consider whether cancelling a password change would realistically require the current password on an unrelated page. Legitimate services usually keep sensitive actions inside their established account portal.

Generic branding, unsupported deadlines, and missing account details strengthen the phishing assessment. No single visual element should overrule those inconsistencies.

What to Do If You Fell Victim to This Scam

  1. Change the mailbox password from a clean route. Type the official portal address yourself. Choose a unique password that was never used on another service.
  2. End every active session. Use the account security page to sign out other browsers and devices. This can invalidate access the attacker still holds.
  3. Enable strong multi-factor authentication. Prefer an authenticator application or security key where available. Do not approve unexpected prompts during recovery.
  4. Review recovery information. Remove unfamiliar phone numbers, addresses, backup codes, and trusted devices. Confirm that every recovery option belongs to you.
  5. Inspect rules and forwarding. Check Inbox, Archive, Trash, spam settings, filters, delegates, and automatic forwarding for changes you did not create.
  6. Revoke connected applications. Remove unknown OAuth grants, mail clients, add-ins, and application passwords. Reconnect legitimate tools only after the account is secured.
  7. Change reused passwords elsewhere. Start with financial, cloud, work, and social accounts. Each replacement should be different and stored in a password manager.
  8. Scan the computer. Run a full Malwarebytes scan to detect credential stealers or other threats that may have accompanied the phishing page.
  9. Block malicious advertising and redirects. AdGuard can reduce exposure to deceptive pages, but it does not replace careful link verification or account controls.
  10. Notify affected contacts and administrators. Warn them if suspicious messages were sent from your account. Business users should report possible data exposure immediately.

Is Your Device Infected? Run a Free Malware Scan

Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Anti-Malware Free — one of the most trusted malware removal tools available.

The free version detects and removes the most common threats, including:

  • Adware — the cause of those annoying pop-ups
  • Browser hijackers — unwanted redirects and changed homepages
  • Trojans and spyware — hidden programs stealing your data
  • Potentially unwanted programs (PUPs) — software you never asked for

👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The whole process takes about 5 minutes.

Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android

Run a Malware Scan with Malwarebytes for Windows

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

When the scan finishes, click Quarantine to remove everything Malwarebytes found. That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.

If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:

Run a Malware Scan with Malwarebytes for Mac

Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.

  1. Download Malwarebytes for Mac

    Click the button below to download the latest version of Malwarebytes for Mac.

    DOWNLOAD MALWAREBYTES FOR MAC (FREE)
    (The link opens in a new page where your download will start)
  2. Open the Malwarebytes setup file

    When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

    Double-click on setup file to install Malwarebytes

  3. Follow the On-Screen Prompts to Install Malwarebytes

    The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.

    Click Continue to install Malwarebytes for Mac

    Click again on Continue to install Malwarebytes for Mac

    Click Install to install Malwarebytes on Mac

    When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.

  4. Select “Personal Computer” or “Work Computer”

    Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
    Select Personal Computer or Work Computer mac

  5. Start the Scan

    Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
    Click on Scan button to start a system scan Mac

  6. Wait for the Scan to Finish

    Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
    Wait for Malwarebytes for Mac to scan for malware

  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
    Review the malicious programs and click on Quarantine to remove malware

  8. Restart Your Mac

    Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
    Malwarebytes For Mac requesting to restart computer

Once the scan is done, remove every threat it detected. Your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.

If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.

Run a Malware Scan with Malwarebytes for Android

Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.

  1. Download Malwarebytes for Android.

    You can download Malwarebytes for Android by clicking the link below.

    MALWAREBYTES FOR ANDROID DOWNLOAD LINK
    (The above link will open a new page from where you can download Malwarebytes for Android)
  2. Install Malwarebytes for Android on your phone.

    In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

    Tap Install to install Malwarebytes for Android

    When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
    Malwarebytes for Android - Open App

  3. Follow the on-screen prompts to complete the setup process

    When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
    This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
    Malwarebytes Setup Screen 1
    Tap on “Got it” to proceed to the next step.
    Malwarebytes Setup Screen 2
    Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
    Malwarebytes Setup Screen 3
    Tap on “Allow” to permit Malwarebytes to access the files on your phone.
    Malwarebytes Setup Screen 4

  4. Update database and run a scan with Malwarebytes for Android

    You will now be prompted to update the Malwarebytes database and run a full system scan.

    Malwarebytes fix issue

    Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

    Update database and run Malwarebytes scan on phone

  5. Wait for the Malwarebytes scan to complete.

    Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning Android for Vmalware

  6. Click on “Remove Selected”.

    When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
    Remove malware from your phone

  7. Restart your phone.

    Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.


After the scan, tap Remove Selected to delete all detected threats. Your Android phone is now clean — no more malicious apps, adware, or browser redirects.

If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:

Stay Protected: Block Ads and Malicious Sites

Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.

We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.

👉 Download AdGuard and browse safely

Act even if the fake page showed an error. The submission may have reached the attacker before that error appeared.

If the mailbox belongs to an employer, do not quietly handle the incident alone. Security staff may need to preserve logs, revoke sessions, and examine connected systems.

Mailbox security dashboard used to review sessions and recovery settings

What to Check After Regaining Control

Read the Sent folder for messages you did not write. Also inspect deleted and archived mail because attackers often remove their replies and security notifications.

Search for terms related to forwarding, password resets, invoices, verification codes, and recovery changes. This can reveal how the intruder used the mailbox.

Review account activity by location, browser, and time. A location alone is not conclusive, but unfamiliar sessions aligned with the phishing event deserve investigation.

Check whether important messages were marked as read. An attacker may monitor conversations without sending anything, especially when waiting for financial information.

Confirm the display name and signature. Criminals sometimes add alternate reply addresses or altered payment details that survive after the password is changed.

For workplace accounts, compare audit records with known user activity. Administrators should examine rule creation, OAuth consent, exports, and unusual authentication events.

How to Avoid Similar Mailbox Lures

Treat every unexpected security button as an invitation to verify independently. Open the service separately and look for the same alert inside the authenticated account.

Use unique passwords so one stolen credential cannot unlock several services. A password manager removes the need to build memorable variations around the same phrase.

Enable multi-factor authentication before an incident. It provides another barrier, although criminals may still attempt real-time phishing or repeatedly send approval prompts.

Organizations should publish one recognized support route. Employees who know exactly where to report suspicious mail are less likely to use contact details supplied by attackers.

Mail administrators can strengthen filtering and external-sender warnings. Those controls help, but training should still explain that compromised trusted accounts can send malicious messages.

Keep browsers and security software updated. Phishing is primarily a deception problem, yet outdated software can turn a bad click into a broader device compromise.

Frequently Asked Questions

Is the Webmail Password Reset Request email genuine?

The version described here is fraudulent. Verify any similar notice through your normal webmail portal because legitimate providers can send separate, genuine security alerts.

Does clicking Cancel Reset immediately expose my password?

A click may reveal technical information and confirm activity, but credential theft usually occurs when details are submitted. Close the page and scan the device.

What if I entered only my email address?

Expect more targeted phishing because the attacker now knows the address is active. Do not respond, and watch for follow-up messages that reference the first alert.

Will multi-factor authentication keep the account safe?

It significantly improves protection, but it is not absolute. Never share a verification code or approve a prompt you did not initiate.

Why did the fake page redirect to my real provider?

The redirect can make the incident look like a harmless login error. Credentials may already have been captured before the genuine page appeared.

Should I reply to ask whether the request is real?

No. Replying confirms the address is monitored and keeps communication inside the attacker’s channel. Contact the provider or administrator using details you already trust.

The Bottom Line

The Webmail Password Reset Request scam turns a supposed protective action into a credential trap. The safest response is independent verification through the real account portal.

If information was submitted, secure the mailbox completely, not just its password. Sessions, forwarding rules, recovery options, and connected applications all require careful review.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Next

Orthora-footwear.com EXPOSED – Scam or Legit? Investigation