Stop when you see these signals.
- Sender domain does not match the real service
- Login button goes to a lookalike or short URL
- Urgent deadline
- Requests for password, OTP, backup codes, or recovery email
- Generic greeting and unusual attachments
The email claims your account is locked, suspended, or has suspicious activity. The login button leads to a fake page that steals credentials and sometimes OTPs.
Your account has been locked due to unusual activity. Sign in within 24 hours to restore access.
People react quickly when they believe email, banking, work, or social access is at risk.
No. Display names are easy to fake. Check the real sender address and destination URL.
Change the password immediately from the real site, log out other sessions, and review recovery settings.
Paste a suspicious URL and open WhatsApp with the link prefilled so Kaval can check phishing, lookalike domains, unsafe payment prompts, and next steps.
Ask Kaval on WhatsApp about suspected email, phone, password, or account exposure without exposing a public breach enumeration lookup.
Not sure if a link is safe? Learn how to check suspicious URLs for phishing, malware, and scams using free tools and red-flag indicators.
A step-by-step account cleanup plan after phishing, OTP sharing, fake support calls, remote access, malware, or payment scams.