Replied to a fake recruiter, media invite or review offer? Calm, practical steps, in order, based on what you actually shared.
Replying to one of these emails is not a disaster. Most of the harm in these schemes comes later, from money sent, passwords entered or documents handed over. A reply on its own gives the sender very little. What matters now is what you shared, and what you do next.
Work through the steps below in order. Stop at the ones that apply to you.
Do not reply again, even to tell them you know it is fake. A reply confirms your address is live and read by a person, which makes it more valuable. Do not click anything further in the thread. Do not open attachments.
Move the emails to a folder rather than deleting them. You may need them for a report or to check what you sent.
Read back through your own replies and list exactly what left your inbox. Be precise. The steps that follow depend on it.
Typical items, from least to most serious:
Match your list to the sections below.
You are fine. Your name, photo and biography are already public if you are an author, consultant or anyone with a website. The sender has gained nothing they could not have found.
Expect more emails from the same source, and possibly from others, because a replying address gets passed around. Mark them as junk and move on.
Expect calls and messages. Do not answer numbers you do not recognise, and do not engage with texts about the "opportunity". If it becomes a nuisance, most phones let you block and report. Changing your number is rarely necessary.
On their own these are not enough to open accounts, but they are pieces of a puzzle. Keep an eye on your post for letters about accounts or credit you did not apply for. In the UK you can register with Cifas for protective registration, which asks lenders to make extra checks before opening anything in your name. There is a fee, and it is worth paying if you also sent ID.
This is the point where it becomes worth acting rather than watching.
Identity fraud from a leaked scan can happen months later. The checks above are not a one-off.
An account number and sort code on their own allow someone to pay you, and in some cases to set up a direct debit. Contact your bank, tell them what happened, and ask them to note the account and watch for unexpected direct debits. Check your statements for a few months. If you shared card details, cancel the card and get a new one issued.
Treat that password as public.
Your email account is the master key to everything else, so start there.
Wherever you are, forward the original email to the organisation being impersonated. Large companies and broadcasters have fraud or security teams and want to know. Find the reporting address on their real website, not in the email.
In the UK, you can also forward phishing emails to report@phishing.gov.uk, which is run by the National Cyber Security Centre. It takes seconds and helps get the sending domains taken down.
These emails are built by people who do this for a living and refine what works. The fake BBC invitation I received used the right presenter's name and the right programme. The fake recruiter email used a real company. They are designed to pass a quick read. Replying is not stupidity; it is what the email was engineered to produce.
What matters is that you now know the tell. It is almost always the domain.
Before you reply to anything that asks for money, documents or a login: read the sender's domain, read the reply-to domain, and ask whether either belongs to the organisation named in the email. If not, it is not from them.
I am building Proof of Sender to make that check quick. Paste the sender address and the organisation it claims to be, and it tells you whether they match. It is early and free. Try it at proofofsender.com/demo.
Not sure about an email in front of you right now? Check the sender free. It runs in your browser and nothing is stored.