scammers exploit payment notice scam to steal credentials via fake online sign-in pages

Cybercriminals are leveraging convincing payment notification emails to deceive recipients into revealing login details through fake sign-in pages, posing a significant risk to personal and financial security.

A payment notice promising money in your bank account may look routine, calm and even helpful. That is exactly why the “We Have Processed Your Payment” scam has been circulating: it uses the idea of an incoming deposit to nudge people into clicking a link they think will show a statement, when in fact it leads to a fake sign-in page designed to steal credentials.

According to the scam analysis, the email often appears to be sent for information only, says no immediate action is needed and includes details such as a payee name, payment reference and a note that the funds may take up to 48 hours to show up. Those touches make the message feel credible, especially if the recipient is expecting a reimbursement, benefit payment or some other account adjustment.

The campaign also borrows the name, address and contact details of AccertaClaim ServiCorp Inc., a real Canadian claims administrator. But the accurate company information is only camouflage. The real Accerta service uses its own official portal and an Access ID, not a Google-style login on an unrelated hosting domain.

The link in the email does not display a payment statement. Instead, it opens a copied Google sign-in page that asks for an email address and password. Google’s own security guidance says it will not ask for passwords, usernames or bank details in unsolicited messages, and it urges users to check recent security activity and report suspicious emails.

Once the details are entered, the attacker can collect the login information and try it against the victim’s real mailbox or other services. That creates a wider risk than the original false payment claim: a compromised inbox can expose financial alerts, benefit letters, password-reset messages and private conversations, while also helping criminals send more convincing follow-up scams.

The safest response is to ignore the email link and verify any deposit through the bank, plan administrator or claims portal opened independently through a saved bookmark or official website. If a password has already been entered, the account should be secured immediately, recent sessions reviewed, and any unfamiliar forwarding rules or recovery details removed.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.