If a page says you have only a few minutes to keep an account, accept a job, avoid a penalty, or receive a refund, stop before you do anything. The countdown is meant to keep you from checking the request.
Don't sign in, pay, call, download a file, or scan a QR code from the message. Open the real service through its official app, a bookmark you created earlier, or a web address you already know. If you entered a password or sent money, secure the account or payment method immediately.
A deadline scam website is a phishing page that uses a fake expiration date, countdown, or threat to pressure you into revealing information or sending money. The page may copy the look of a bank, government agency, employer, delivery company, or familiar online service.
How deadline scams work
The message usually combines three things:
- A familiar name or brand
- A consequence for not acting quickly
- A link, attachment, phone number, or QR code that leads to the scammer
The request might say:
- "Verify your account today or it will be closed."
- "Pay this overdue invoice before service is suspended."
- "Complete job onboarding now to receive your first payment."
- "Confirm your refund or delivery before the link expires."
- "Submit your tax or business filing within 24 hours."
The fake page can ask for a password, Social Security number, tax details, bank login, card number, identity document, or one-time authentication code. An attachment may install malware instead of opening a legitimate form.
Reported campaigns have included fake Microsoft Teams login pages on lookalike domains and IRS-themed messages carrying malicious ZIP files. The details change, so a domain list is not a permanent safety check. Microsoft gives examples such as micros0ft.com, where a zero replaces an "o," and rnicrosoft.com, where letters imitate the "m." See Microsoft's phishing guidance and this reported phishing campaign analysis.
Why the fake deadline feels convincing
Urgency narrows your attention. Fear of losing a job, missing a payment, being fined, or having an account closed can make the first instruction seem more important than checking who sent it.
Scammers also borrow pressure from real events. CISA explains that social engineers take advantage of current events, economic concerns, health scares, holidays, and other situations that already have people on alert.
A genuine tax, payment, employment, or account deadline can exist. The countdown itself doesn't prove that the notice is genuine. A legitimate organization should give you another way to confirm it: its official app, an account portal you open yourself, or a support number found independently.
Warning signs to look for
One mistake may be harmless. Several of these signs together call for a pause:
- You weren't expecting the message. You have no known renewal, invoice, job offer, delivery, refund, or account problem that matches it.
- The sender doesn't match. The display name looks familiar, but the full email address, phone number, or text sender does not belong to the organization.
- The web address is a lookalike. It has misspellings, extra words, unusual punctuation, substituted letters, or an unfamiliar domain ending.
- The request is unusually sensitive. An unsolicited page asks for a password, one-time code, bank login, Social Security number, or identity document.
- Payment must happen a strange way. Gift cards, cryptocurrency, wire transfers, prepaid cards, or payment to a personal account are major warning signs.
- The message includes an unexpected file or QR code. It presents that item as the only way to meet the deadline.
- The threat is extreme. You are told to keep the matter secret, avoid normal support, or act before a countdown reaches zero.
- The page changes quality from screen to screen. Typos, broken links, outdated logos, and inconsistent branding can expose a copied site.
- The message supplies its own verification route. Its only phone number, email address, or support link leads back to the sender.
- You are told to weaken your security. That includes disabling antivirus protection, ignoring a browser warning, or sharing a two-factor code.
Don't use grammar as your only test. A convincing scam can be well written, and a legitimate organization can make a typo. The Federal Trade Commission's phishing guidance describes the pressure to click links and provide personal information that appears in many of these messages.
Check the request without helping the scammer
1. Stop interacting with the message
Don't reply, call the number in the message, open its attachment, or enter information just to see what happens. If you already opened the page, close it. Don't go back to inspect it.
You can save a screenshot without clicking anything on the page. Include the sender and visible address if you need to report it later.
2. Start with a trusted route
Open the organization's official app, use a bookmark you made before, or type a known address into the browser yourself. Don't use the message's link, QR code, phone number, or email address.
For a bank, tax agency, delivery company, or online account, sign in through the normal service and look for the same notice there. If you need support, use a number from a statement, payment card, or official website that you found separately.
3. Read the domain, not just the brand
The organization named on a page may not control the website. In microsoft.com.example.net, for example, example.net controls the address. Look for misspellings, extra hyphens, added words, and unfamiliar domain endings.
HTTPS only encrypts the connection between your browser and the site. It doesn't prove that the site operator is legitimate. Fake sites can use HTTPS.
4. Confirm the exact deadline
Ask the organization whether the message, invoice, job offer, account warning, or website is real. Use a contact method you already trust.
At work, check with a known colleague or the IT team. For a client or supplier, call the established contact instead of replying to the urgent email. For a government notice, find the agency's website yourself and use its published contact information.
5. Treat security tools as clues
Spam filters, browser warnings, antivirus programs, and reputation checkers can help, but none guarantees that an unfamiliar site is safe. Don't upload private documents or a sensitive link to a random "scam checker." Independent verification matters more than a green padlock or polished design.
If you already used the website
Don't wait for the countdown to expire. Take the steps that fit what happened.
You opened the page but entered nothing
Close it and check the browser's download folder and notifications. If a file downloaded, don't open it. Let your security software quarantine or remove it, or follow your employer's instructions if it's a work device. Update the browser and security software, then run a scan.
Tell your employer's IT or security team promptly if the device or account belongs to work. Avoid continuing to use a work account on a device that may have downloaded malware until your organization tells you what to do.
You entered a password or authentication code
Use a device you trust and:
- Change the password on the affected account.
- Change it anywhere else you reused it.
- Sign out of other sessions and review recent login activity.
- Check recovery email addresses, phone numbers, forwarding rules, and connected apps.
- Turn on multifactor authentication if it wasn't already enabled.
If you disclosed a two-factor or one-time code, tell the account provider exactly what happened. The code may already have been used, and the attacker may have created an active session. Changing the password alone might not end that access.
You entered card or bank information, or sent money
Call the bank, card issuer, payment app, or other provider using an official number. Say that the payment or information was connected to a scam. Ask what can still be blocked, recalled, or disputed.
Act quickly. The available response depends on the payment method, whether the transaction has settled, and the provider's rules.
- Credit or debit card: Ask the issuer about blocking the card and disputing the transaction.
- Bank transfer or wire: Contact the sending bank immediately and ask about a fraud review, freeze, or recall.
- Peer-to-peer payment app: Report the transaction in the app and contact the linked bank or card issuer.
- Gift card: Contact the issuer through its official support channel, keep the receipt, and provide card details only to that issuer.
- Cryptocurrency: Contact the exchange or service used to send the funds and preserve the transaction ID. Recovery isn't guaranteed.
- Account credentials: Secure the account as well as the payment method because stolen login details may be reused elsewhere.
The FTC's guidance on what to do after a scam covers steps for debit cards, gift cards, cryptocurrency, and other payment methods. A report to an agency is separate from a request for a refund, reversal, or dispute through the payment provider.
You submitted identity information
Contact the affected account or service and ask what protective steps apply. Keep a record of exactly what you sent, including identity documents, tax information, account numbers, and the date of submission. Monitor the account for unusual activity and tell the provider about anything suspicious.
Don't send more documents to someone who promises to recover your money. Recovery services that demand an upfront fee or another urgent payment can be a second scam.
Extra checks for work-related requests
Job seekers
Look for the position on the employer's official careers page and contact the company using information you find yourself. Be cautious when a recruiter demands money for equipment, training, background checks, or access to work before you have verified the employer.
Don't buy gift cards, move money through your personal account, or send an identity document just because an offer supposedly expires that day.
Freelancers
Confirm the client through the platform where you found the work or through a known business contact. Treat unexpected project briefs and ZIP files carefully, especially when urgency is used to discourage questions.
Before sending tax forms, identity documents, or bank details, confirm who will receive them and why. A genuine project deadline doesn't require you to skip basic account and payment checks.
Businesses
Require a second person to approve urgent invoices, new bank details, payroll changes, and supplier payment requests. Call a known number instead of replying to the email that requested the change.
For tax or compliance notices, go directly to the relevant agency's official portal. A message mentioning a filing deadline, penalty, or extension still needs independent verification.
How to report a deadline scam
Reporting may help providers and investigators connect related complaints, but it won't guarantee a takedown or refund.
- Report the message to the FTC. Use ReportFraud.ftc.gov. You can forward phishing emails to
[email protected]and suspicious text messages toSPAMat7726. - File an IC3 complaint when the scam involved a website, money, stolen credentials, malware, or identity information. The IC3 FAQ says trained analysts review complaints and may share information with law enforcement or partner agencies. IC3 does not conduct investigations or provide the status of an individual complaint.
- Notify the impersonated company or platform through its official fraud, abuse, or account-security channel.
- Tell your employer or work platform if applicants, clients, coworkers, or business accounts could be affected.
- Report the domain to its registrar or hosting provider through an independently found abuse page when possible. Don't revisit the site or contact its operator to collect more information.
Save the full message, sender details, exact website address, screenshots, dates and times, payment receipts, transaction IDs, phone numbers, and related conversations. Don't open suspicious files. Redact passwords, full account numbers, and other private information that isn't needed for the report.
Common questions
Can a legitimate website use a countdown?
Yes. A countdown by itself doesn't prove fraud. Confirm the date in the organization's official app or website, then contact support through a separately obtained channel if anything remains unclear.
Does HTTPS mean the website is safe?
No. HTTPS protects the connection, not the identity or honesty of the site operator. Check the domain and verify the request outside the message.
Can you get money back after paying?
Possibly, but there is no universal guarantee. Contact the payment provider immediately and ask about its fraud, reversal, or dispute process. The options depend on the payment rail and transaction details.
What if you shared a two-factor code?
Treat the account as compromised. Change the password from a trusted device, end active sessions, review recovery settings, and contact the provider's security team. Tell the provider that a one-time code was disclosed.
If the suspicious message is open now, close it and open the real service through a saved bookmark or official app. If money moved, call the payment provider before spending time investigating the website.