{"id":407480,"date":"2026-08-31T06:58:54","date_gmt":"2026-08-31T06:58:54","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=407480"},"modified":"2026-08-31T06:58:54","modified_gmt":"2026-08-31T06:58:54","slug":"pre-2021-report-files-email-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/pre-2021-report-files-email-scam\/","title":{"rendered":"Pre-2021 Report Files Email EXPOSED: Fake Hosting Cleanup Steals Logins"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A storage notice is the kind of mail a hosting customer actually opens, because old report files and a cleanup date are chores a tired desk already expected to finish this quarter. The subject in this case is Notice: Cleanup of Pre-2021 Report Files, which is enough of a filing label to survive the few seconds between the inbox list and the reading pane.<\/p><div id=\"mwtad1147473206\" class=\"mwtadhigh-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"7453445881\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The body writes as a hosting storage desk, thanks you for your understanding, and says all report files dated before January 1, 2021 will be removed to manage storage costs and liability. It adds that approximately five years of reports will remain available, that older files are rarely accessed and continue to consume space, and that you should review the plan and contact them promptly if any specific files need to be retained. The only control on offer is labeled Check Files, and a confidential footer sits under the thanks as if a clerk had already filed the note.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you actually keep reports on a host you already pay, you look at those files the way you already do, on a page you type yourself, rather than letting a surprise cleanup choose the next screen. A real archive, when one exists, is still sitting in the panel you already use, and it will still be there after you leave this letter alone.<\/p><div id=\"mwtad3579370910\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full mt-screenshot\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Outlook view of a Notice Cleanup of Pre-2021 Report Files email with a Check Files button\" class=\"wp-image-407479 lazyload\" title=\"\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/pre2021-reports-hero.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/pre2021-reports-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/pre2021-reports-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/pre2021-reports-hero-1024x683.png 1024w\"><\/figure>\n\n\n\n<div id=\"mwtad4258073094\" class=\"mwtadheader-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2917133959\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The letter wants you to treat a hosting storage cleanup as closed business, then uses Check Files to walk you onto a page that copies a mail login. That copied page asks for the password you already use at work, which is the harvest sitting behind a review of old reports. The next screen claims your previous session has expired and asks you to enter the address and the password so you can continue. What they take first is that login, and after that they take the mailbox itself. They take threads with vendors, reset codes that land an hour later, and people who already answer when your name is on the From line.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This cleanup of report files dated before January 1, 2021 is a different costume from a blocked cPanel sign-in and from a server password expired notice. All three borrow the furniture of a host, but they do not ask for the same click. A blocked panel scare asks you to unlock a control panel, while an expired server password asks you to refresh a secret the host supposedly already holds. This one asks you to review old reports so a storage bill does not keep growing, which is a quieter hurry than a lockout. The operator of this letter is not your host talking, and Check Files is not a file manager. The harvest sitting behind the button is a copied webmail form rather than a list of archives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anyone can type Hosting Storage into a display name, which means a tidy heading does not prove that a provider scheduled a deletion. It also does not prove that anyone asked you to review files from this message. People who steal inboxes borrow letterhead from storage, reports, and liability language because they want you to treat the note as a chore you already meant to finish. They do not want you to treat it as a stranger asking for the key to your mail. A real host that actually keeps your reports will still show those files after you open the panel yourself. It will not collect a mailbox password in order to show you a cutoff of January 1, 2021.<\/p><div id=\"mwtad2903006184\" class=\"mwtadp2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The Federal Trade Commission describes this shape in ordinary language in <a href=\"https:\/\/consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams\" target=\"_blank\" rel=\"noopener\">How To Recognize and Avoid Phishing Scams<\/a>. The FTC says scammers use email to steal passwords, account numbers, or Social Security numbers, and that a common story is a problem with an account when there is no problem. Another common story is that you must confirm a document, a payment, or a cleanup, when you do not. The Commission&#8217;s advice is to contact the company with a phone number or website you already know is real, rather than with the information in the email. A Check Files button that arrived inside an unexpected storage notice is information in the email, which is why it is a poor place to start a review of old reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISA says the same thing from the systems side on <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/avoiding-social-engineering-and-phishing-attacks\" target=\"_blank\" rel=\"noopener\">Avoiding Social Engineering and Phishing Attacks<\/a>. CISA tells people not to reveal personal or financial information in email, and not to follow links sent in email when a message asks for that information. On <a href=\"https:\/\/www.cisa.gov\/audiences\/small-and-medium-businesses\/secure-your-business\/teach-employees-avoid-phishing\" target=\"_blank\" rel=\"noopener\">Teach Employees to Avoid Phishing<\/a>, CISA tells staff that if a message feels off, they should verify it without using any phone number or link in the message. That means using a number you already have and a site you already type, rather than anything printed in the surprise note. That habit is the opposite of fetching a report archive from a letter you did not request. It is also the opposite of typing a mailbox password so a cleanup can supposedly finish loading.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Check Files is the click<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Read the button the way a tired administrator reads it between two other alerts, because Check sounds like you are opening a record that already exists. Files sounds like reports the host already stored, which is how a rectangle becomes an errand instead of a warning. The subject has already done the notice, and the January 1, 2021 cutoff has already done the filing date. The line about storage costs and liability has already done the paperwork, so by the time your eye hits the rectangle the errand feels mostly finished. Promptly is the word that turns a five year archive into something you should finish before lunch, which is why the letter places that hurry next to the only control that works.<\/p><div id=\"mwtad293165188\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A real storage cleanup does not need that rectangle in a surprise email, because if a host actually planned to delete old reports, the files and dates would already be visible after you open the product yourself. A notice that truly posted would already be sitting in front of the person who pays the bill. An unexpected Check Files does not sit between those screens, which is the quiet tell once you look past the cutoff. What the button actually does is take you off the inbox and onto a page the sender controls. On a phone, where hovering is awkward, many people never see the real destination before the next page fills the display.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Storage costs and liability are doing borrowed work<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Keep the names straight, because the campaign depends on mixing them up: hosts exist, and people pay them for disk. A cleanup of files dated before January 1, 2021 is a believable chore to put next to a storage bill. Approximately five years of reports remaining, and a claim that unused archives continue to consume space, are doing the work a ledger line usually does. A controller can picture the disk without checking whether anyone at the host issued that plan, which is the point of the cutoff. Those details can be typed by anyone who has seen a hosting invoice, and matching them to a real archive is work the letter hopes you will skip because the cutoff already looks filed.<\/p>\n\n\n\n<div id=\"mwtad1566207455\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">Display names are cheap, and anyone can set a From line to read Hosting Storage, just as anyone can paste a thank you sentence under a teal bar. Delivery only proves they knew the mailbox that received the mail. It does not prove they hold your reports, scheduled a deletion, or sit inside the company that bills you for disk. Microsoft&#8217;s <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-phishing-0c7ea947-ba98-3bd9-7184-430e1f860a44\" target=\"_blank\" rel=\"noopener\">guide to spotting phishing<\/a> tells you to treat mismatched senders as a warning and to slow down when a message wants an immediate click. A footer that hurries you toward Check Files is that kind of click, because the hurry is the whole costume.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not reply to ask whether the pre-2021 files are real, because a reply teaches them the inbox is live and it lands wherever they pointed the return path. Do not call a number that appears only in the letter, and if you actually pay a host, open the panel you already use and look for the reports there. If a coworker claims the archive is about to vanish, call them on a number from last month&#8217;s thread rather than from this cleanup, because a stolen storage heading is not a reason to start a new conversation with the people who wrote it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The page after the files copies a login<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After Check Files, the story changes, because the inbox promised a review of old reports while the next screen promises a sign-in. It is built to look like the mail service you already use, so a Gmail address often sees a page dressed as Gmail. A Microsoft address often lands on a page dressed as Outlook or a work portal, and other providers get the costume that matches their own mail. The page says the previous session has expired, and your address may already be sitting in the box. The language is the language you see every morning, which is how a careful person finishes a login they never meant to start.<\/p>\n\n\n\n<div id=\"mwtad1512659128\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">A padlock in the browser does not fix that, because encryption only means the path is private. It does not mean the person at the other end is Google, Microsoft, or the host that bills you. HTTPS can wrap a stolen password as neatly as a real one, and an accurate logo is not a certificate. You should trust the complete domain and the way you reached it rather than the artwork inside the page. Google&#8217;s <a href=\"https:\/\/support.google.com\/mail\/answer\/8253\" target=\"_blank\" rel=\"noopener\">advice on phishing in Gmail<\/a> is blunt on this point: Gmail will not ask you for your password over email. If a storage click then presents a login, you should not type it, even to see whether a file list appears next.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not finish that form to see whether a file list then appears, because a copied sign-in does not become safer when you only wanted to keep a report from before 2021. Open a new tab, type the mail service you already pay or open the app you already installed, and look at the account from the inside, since a mailbox that is truly yours will still be there and a fake cleanup will not. If you already typed the password, treat it as burned even if the window now says the session cannot be restored, because a dead tab is not proof the letter was harmless.<\/p>\n\n\n\n<div id=\"mwtad4039243871\" class=\"mwtadheader-2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9284335404\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How The Scam Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. A cleanup notice lands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It arrives in the same Outlook or Gmail you already trust, wearing the subject Notice: Cleanup of Pre-2021 Report Files. The display name presents itself as a hosting storage desk, which is enough of a costume to survive a glance in a busy inbox. There is no prize and no threat that the mailbox will be deleted at midnight, because the whole note is built to fit on a phone screen as a courtesy a finance person already expected. People who would ignore a lottery message will still open a storage cleanup that looks like a disk chore they have been waiting to file. That is why the letter stays short, and why it borrows the tone of a closed invoice rather than a prize.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are already signed in to webmail, the folders on the left and the search bar on the top make the fake note feel native. You are not visiting a strange site yet, and you are only reading mail, which is why the costume works. The letter only has to survive the few seconds between the subject and Check Files. A January 1, 2021 cutoff next to five years of remaining reports is enough to buy those seconds inside a hosting folder.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. It pretends to be hosting storage<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Hosts belong to a real industry that workplaces already pay for, and that fact is the load bearing detail in a letter that only has a few seconds to look like operations mail. When you have ever approved a disk add-on, forwarded a backup invoice, or seen storage on a corporate card statement, you fill in the rest yourself. Even if you have never opened a file manager, the phrase cleanup of report files still sounds like money. The people who wrote the letter did not need to sit inside your host to borrow a storage heading, a liability line, and a cutoff that would survive a five second glance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A teal bar and a tidy cutoff block do the rest of the glance, and the promptly line is sitting there if anyone wants a reason not to check with a human. A real desk would not need that costume, because a thief does, and the thief is not inside the company that bills you for disk. The thief is only inside your inbox if the Check Files click works, which is why the name on the letter is doing borrowed work rather than proving a deletion was scheduled.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Pre-2021 files are the hurry<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">January 1, 2021, approximately five years of reports remaining, and a claim that older files are rarely accessed are doing the work a calendar usually does. A controller can picture the unused archive, the growing bill, and the liability of keeping dead files without checking whether anyone at the host actually set that cutoff. That is the point of putting a round looking date next to a storage story, because a date feels filed even when nobody issued it. Those details can be typed by anyone who has seen a retention policy. Matching them to a real file list is work the letter hopes you will skip because the year already looks filed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Operations teams live on that kind of date, because vendors send reminders, controllers ask for retention windows, and a late cleanup that posted without a conversation is a real kind of Monday. The lure is borrowing that Monday, and it does not need a long pitch when it can offer a cutoff, a five year kept window, and a liability line that a tired person can already imagine matching to last year&#8217;s backup bill. A blocked cPanel sign-in uses a different clock, and a server password expired notice uses a different clock, while this one uses the age of the files as the reason you should not wait.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Check Files is the handoff<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The letter tells you to review the plan and contact them promptly if you need any specific files retained, and then it offers Check Files as the only way to start that review. You click because a files link is supposed to open an archive, and because promptly is a word that makes a January 1, 2021 cutoff feel like an errand you should finish before lunch. Then the next page asks you to sign in as if you were opening mail, instead of showing a file list with dates in the title bar. There is no ticket number you can read back from the host&#8217;s own product, and there is no retention line that matches a panel you opened yourself. There is only a request for the same credentials you use to open the inbox you are already sitting in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That request is the tell, because you are already in mail, and a real file list would open inside the panel after you typed the product yourself. It would not ask you to prove you are you so you can see reports the sender already claimed were waiting. CISA&#8217;s advice is not to follow a link in a message that then asks for that kind of information. Check Files is the detour, because the button is a handoff from a letter you trust to a page you should not.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. The expired session copies webmail<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The page that follows is dressed as the provider you already use, often with the same colors, the same Sign in label, and the same field for the work address or the personal one. It says the previous session has expired and that you need to authenticate to continue, and that sentence is doing the whole job. There is no protected report archive waiting behind the form, which is why the expired session line exists. The costume changes with the mailbox, so Gmail users get a Gmail shaped door and other users get the door that matches their own mail. Familiar is the point of that costume, because a page that looks like morning mail is easier to finish.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One examined copy of this cleanup sat on EdgeOne, which is enough of a name without pasting a path that the next reader might follow. Those pages move, and a copied link is how the next person gets hurt. The quieter tell is the habit: a storage review that demands a mailbox password is not a storage review. Do not finish that form to see whether it is real, because a copied login does not become safer when you only wanted a list of reports dated before 2021.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Type the official site of your mail service in a new tab if you need to check the account, then leave the cleanup tab alone and close it. The address in that tab is a door you should stop using rather than a clue you need to collect. Do not send the live button to a coworker so they can check the files. If you need a second pair of eyes, send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. They want the mailbox password<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you type the password they have the first key, and if a text, an authenticator prompt, or an email code arrives while that tab is still open they want the second key too. The story will sound helpful, asking you to confirm so the files can load, or to approve so the expired session can resume. It may also ask you to enter the code to verify your work account, and each line is the same request for access to the mailbox you were already sitting in. The pre-2021 reports were never sitting behind that box, because the mailbox was. The people who wrote the letter designed the storage block so you would not notice the swap.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s phishing page tells you to change the password on every affected account if you think you typed it on the wrong site, and to turn on multifactor authentication if it is not already on. That is the same advice the FTC gives in consumer language, and it still applies after a storage letter. Treat the password as burned and treat the code as burned, and do not reuse either one on the next page that promises to unlock a file list. You should not type the same password into the host, the bank, or payroll as a courtesy refresh. Change those passwords on sites you open yourself, one at a time, after the fake tab is gone, because a copied login does not get to supervise the cleanup.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once they can open the account they are not hunting for a 2021 report, because they are reading the last invoice you sent and the last invoice you received. They also read the thread with a vendor who pays by wire, and then they write the next message in your voice. A bill that looks like last month&#8217;s bill is enough, and a new account, same firm line is enough. If they add a forwarding rule they can keep a copy after you change the password until someone deletes the rule. A compromised mailbox is not a nuisance in that setting, because it is a way to move a payment without ever calling you again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. A second crew sells recovery<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The last move is often social, and it may not even be the same people, because a day later you can get a call, a text, or a fresh email that already knows you opened a storage cleanup. They will offer to lock the host, pull the reports, or stop a deletion you never approved. Then they will ask for a code, a remote access session, a second password, or a cleanup fee. Hang up, because a stranger who found you is not your incident responder. A hosting security desk that called you after Check Files is not the company that bills you for disk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is why a quiet admission that you already clicked, even if you did not pay anyone, is not the end of the story, because you may not have paid while the person who trusts you might. Tell the people who send you money and the people you pay, and tell a real coworker, if you actually share a host, on a number you already have rather than on a number that arrived after Check Files. A 30 second call from you is cheaper than a week of wires that look like your week, and the second crew is counting on shame to keep you quiet long enough for the first crew&#8217;s mail to land.<\/p>\n\n\n\n<div id=\"mwtad669593886\" class=\"mwtadheader-3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5345090394\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What To Do If You Have Fallen Victim to This Scam<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you only opened the email and closed it, you are not finished, but you are not doomed, and if you pressed Check Files and then typed, treat the account as touched and move in this order. Speed beats waiting to name the exact kit they used, because the goal is to take the mailbox back before someone else sends the next invoice in your name. Write down what you remember before the details fade, then stay on official pages you open yourself rather than on anything that arrived inside the storage letter.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Write down what you typed, including the time and the subject Notice: Cleanup of Pre-2021 Report Files, then stop using that tab.<\/strong> Write down whether you entered a password and whether you approved a code or an app prompt, then close the cleanup page. Do not keep checking it to see if a file list appears, and do not forward the live button to a friend so they can look. Send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.<\/li>\n<li><strong>Open your real mail yourself in a new tab you type, then change the password to one you have not used anywhere else.<\/strong> Use the official site or the app you already trust, and do not return to the cleanup letter for a reset link. If this is a Microsoft account, follow Microsoft&#8217;s steps to <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/my-outlook-com-account-has-been-hacked-35993ac5-ac2f-494e-aacb-5232dda453d8\" target=\"_blank\" rel=\"noopener\">recover a hacked or compromised Microsoft account<\/a>. If you cannot sign in, use the official reset path, and if this is Gmail or a workplace portal, open that product the same way, from an address you typed.<\/li>\n<li><strong>Sign out of other sessions everywhere you can, then turn multifactor authentication back on before you do anything else with the mailbox.<\/strong> Review recent activity and sign out of sessions you did not start, and if you approved a prompt you did not begin, assume that session is not yours until you kill it, and remove recovery phones and recovery addresses you did not add. A password change that leaves an old session running is only half a change, and if you reuse that password on banking, payroll, or the host, change those on their own sites too, after you type those sites yourself.<\/li>\n<li><strong>Look for inbox rules, automatic forwarding, and mail that left without you, because those are the quiet ways a stolen mailbox keeps working after a password change.<\/strong> Check the Sent folder and look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create, search for other storage cleanups you did not expect, and if this is a work account, call IT before you spend an hour hunting, because they can dump sessions and pull the audit faster than you can.<\/li>\n<li><strong>Call the people who pay you and the people you pay, using a number from last year&#8217;s invoice, a card in the drawer, or a listing you already trust.<\/strong> Tell them a fake hosting cleanup tried to take the mailbox, so they should not honor a new account number or a rushed updated wiring note that arrives this week. If you actually share a host, say that out loud on a number you already have, because the lure picked a storage name for a reason. A coworker who already clicked Check Files still needs a human check in the real panel.<\/li>\n<li><strong>Tell the bank the same day if invoices, payroll, or deposit files live in that inbox, and ask them to watch for a change of account request.<\/strong> Call any payroll or processor vendor as well, because a charge you did not make and a transfer you approved because a message looked like you are different problems, and time still matters on both. Do not invent a dollar figure for a loss you have not seen, and report what you actually typed and what you actually see on the statement. If you use a host and a real card is on file, open that product yourself and look there, not in this email.<\/li>\n<li><strong>Report the email through the controls your mail product already publishes, then scan the device if Check Files saved a file or pushed a viewer.<\/strong> In Outlook, use Report and then Report phishing, the path Microsoft publishes on its <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-phishing-0c7ea947-ba98-3bd9-7184-430e1f860a44\" target=\"_blank\" rel=\"noopener\">phishing help page<\/a>, and in Gmail use Google&#8217;s reporting control from the same <a href=\"https:\/\/support.google.com\/mail\/answer\/8253\" target=\"_blank\" rel=\"noopener\">phishing help page<\/a> they publish for this. Forward a copy to the Anti-Phishing Working Group at <a href=\"mailto:reportphishing@apwg.org\">reportphishing@apwg.org<\/a>, then file the same facts at <a href=\"https:\/\/reportfraud.ftc.gov\/\" target=\"_blank\" rel=\"noopener\">the FTC&#8217;s ReportFraud site<\/a> and, if you want a law enforcement copy, at the <a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">FBI&#8217;s IC3<\/a>. If a password, a bank account, or a Social Security number went into that page, use <a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">IdentityTheft.gov<\/a> for the next steps. If a file landed, run a full scan with <strong>Malwarebytes<\/strong> or the antivirus you already keep updated, remembering that the scan does not get a password back and the password change does that.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If someone forwarded you the note, send them this page instead of the Check Files button, because these cleanups travel in office threads when they look like work, which is part of how they move. Do not install a new cleaner you just searched for because a follow-up email recommended it, since that search is how people add a second problem. The recovery call that already knows the subject line belongs to the same family as step seven above, so hang up and stay on the official path you opened yourself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you use a host every day, treat this letter as a reminder to open the product from a bookmark you already keep, not from mail, and look at the real files and the real retention settings. If the panel shows no cleanup, then no cleanup posted, and if something did post, it will still be there after you ignore Check Files. A fake storage notice does not become real because you were waiting on a disk change, and waiting is the opening they wrote the subject for.<\/p>\n\n\n\n<div id=\"mwtad343441124\" class=\"mwtadheader-4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A note that says Notice: Cleanup of Pre-2021 Report Files, writes as a hosting storage desk, and claims files dated before January 1, 2021 will be removed to manage storage costs and liability, is a login behind a cleanup. It says about five years of reports will remain, and it offers Check Files because a review is supposedly waiting. The industry name belongs to real companies, while the operator of this letter does not. The click is the door they built so you would type a mailbox password instead of opening the panel yourself. After that they use the inbox to write as you, and the recovery call that already knows the subject is the second shift.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open the mail service you already pay by typing it yourself if you need to know whether anything is wrong. Open the host you already use the same way, from a site you already type, if you need to know whether a pre-2021 archive actually sits there. If you already typed the password, change it on the provider&#8217;s own page, kill the other sessions, and tell the people who send you money before the next email goes out as you. The report files were never the point of the letter, because the mailbox was what they came to collect.<\/p>\n\n\n<div id=\"mwtad2506780563\" class=\"mwtadfinal mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3077074880\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A storage cleanup of old report files is not the host talking. Check Files is a login form.<\/p>\n","protected":false},"author":51,"featured_media":407479,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2847,49],"tags":[],"class_list":["post-407480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-investment-scams","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=407480"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407480\/revisions"}],"predecessor-version":[{"id":407488,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407480\/revisions\/407488"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/407479"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=407480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=407480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=407480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}