Phishing emails are fraudulent messages designed to trick you into revealing your email password or personal information. A common scam targets hosting customers by pretending their email account is about to be suspended or their password is expiring.
Cynet will never send you an email asking you to click a link to reactivate your email account or keep your password. If you receive such an email, it is a scam.
How to Recognise a Phishing Email
Example 1: Fake Account Suspension
Hi [your name],
Your email account [email protected] will be disconnected because
you failed to resolve errors on your email.
You have 24 hours to retrieve your account or your account will be
suspended.
Kindly follow the instructions below to retrieve your Email now
[RETRIEVE ACCOUNT NOW]
Regards,
[email protected]
Example 2: Fake Password Expiry
Good day [your name],
The password for [email protected] will expire in 24 hours.
Action required Fix this below:
[Keep Same Password]
Thank you.
Red Flags to Watch For
- Urgent threats — "24 hours", "account will be suspended", "immediate action required"
- Generic greetings — "Dear Customer" or "Hi User" instead of your actual name
- Suspicious links — Hover over buttons/links without clicking — the URL will point to an unfamiliar domain, not
cynet.com.my - Poor grammar and formatting — Awkward phrasing, inconsistent fonts, or spelling mistakes
- Sent from your own address — Phishing emails often spoof the "From" field to look like they come from your own email or domain
- Asks for your password — No legitimate company will ever ask you to enter your password through an email link
- Mismatched sender — The display name says "Cynet Support" but the actual email address is from an unrelated domain
What to Do If You Receive a Phishing Email
- Do not click any links or buttons in the email
- Do not reply to the email or provide any personal information
- Do not download any attachments
- Delete the email — Move it to Trash and empty your Trash folder
- Report it as spam/phishing in your email client so future messages are filtered
Remember: If you're ever unsure whether an email from Cynet is legitimate, log in to the Cynet client area directly at manage.cynet.com.my — do not use any links from the email. If there's a genuine issue with your account, you'll see it in the client area dashboard.
I Clicked the Link — What Should I Do?
If you've already clicked a phishing link and entered your email password, take these steps immediately:
Step 1: Change Your Email Password
- Log in to cPanel at
yourdomain.com/cpanel(or via the Cynet client area) - Go to Email Accounts
- Click Manage next to the affected email account
- Enter a new, strong password — use the password generator for maximum security
- Click Update Email Settings
Important: Choose a password you have not used anywhere else.
Step 2: Check for Unauthorised Changes
Review your email account settings for anything the attacker may have modified:
- Forwarders — Go to cPanel → Forwarders — delete any forwarding rules you didn't create (attackers often add a silent forward to their own address)
- Autoresponders — Go to cPanel → Autoresponders — disable any autoresponders you didn't set up
- Filters — Go to cPanel → Email Filters → select the account — remove any suspicious filter rules (e.g., rules that auto-delete or forward incoming mail)
- Signature — Log in to webmail and check your email signature hasn't been changed to include phishing links
Step 3: Scan Your Computer
Run a full virus and malware scan on your computer using your antivirus software. Phishing pages sometimes attempt to install malware or keyloggers.
Recommended free tools:
- Malwarebytes — malwarebytes.com
- Windows Defender — Built into Windows 10/11
Step 4: Check for Sent Spam
Log in to webmail (yourdomain.com/webmail) and review your Sent folder. If the attacker used your account to send spam:
- Delete the spam messages from your Sent folder
- Check cPanel → Track Delivery for unusual outbound emails
- If your account is on an outgoing mail hold, release it (see Fix: Outgoing Mail Hold)
Step 5: Notify Cynet Support
Contact Cynet support to report the incident. We can:
- Check if your account was used to send spam
- Verify no further unauthorised access is occurring
- Unblock your IP or email if the server flagged suspicious activity
- Help you review and secure your account
How to Protect Yourself
- Never enter your password via an email link — Always navigate to cPanel or webmail directly by typing the URL in your browser
- Use strong, unique passwords — At least 12 characters with a mix of uppercase, lowercase, numbers, and symbols
- Enable Two-Factor Authentication (2FA) — In cPanel → Security → Two-Factor Authentication
- Keep your software updated — Keep your browser, operating system, and antivirus up to date
- Be sceptical of urgency — Legitimate companies give reasonable notice and don't threaten immediate suspension via email
- Verify with Cynet directly — If in doubt, log in to manage.cynet.com.my or contact support through official channels