A message saying your eBay account will be suspended in one hour may display the real eBay logo and a familiar order number. eBay's phishing guidance says important genuine account messages also appear in eBay Messages, and that eBay will not request a password or full card details through an email link. The safest verification is to open eBay yourself and inspect the in-account copy.
Before you start
Do not tap the email link, call its phone number or open its attachment. Save the email intact if you will report it. If you already entered a password or payment data, begin account and card recovery immediately rather than finishing the verification exercise first.Do it step by step
- Open a fresh browser tab and type ebay.com or use the official app. Sign in through that known route and open eBay Messages. Search for a matching notice, including its subject and timestamp.
- If no matching important message appears, treat the email as suspicious. Inspect the sender's full address and linked domain without visiting it. A lookalike domain, attachment or demand for sensitive information strengthens the warning.
- If a matching notice does appear, follow the steps from within eBay's account pages, not from the original email. Check account status and recent orders. An in-account message helps authenticate the communication, but still read the requested action critically.
- Forward the suspicious email as an attachment to spoof@ebay.com, following eBay's reporting guidance. For a suspicious phone call, hang up, contact eBay through its official route and report the caller's number and request.
- If you entered your eBay password, change it through eBay and review account contact details, addresses, bids, listings and purchases. Change the email account password too if it could be exposed, and contact the card issuer for disclosed payment details.
- Delete the phishing email only after preserving what you need for reports. Tell anyone else who handles the household or business eBay account about the attempted impersonation without forwarding a live malicious link.