Verdict
Phishing pattern
Reviewed 2 September 2026
Why authors are a good target
An author's publishing account is a payment account. It holds bank details, tax information and a sales history, and it controls live listings. Taking it over is worth real money, and unlike a bank it usually has no fraud team watching for unusual behaviour on the author's behalf.
The messages work because the fear is plausible. Accounts genuinely do get flagged, titles genuinely do get blocked over metadata and rights questions, and an author who has had that happen once will recognise the shape of the email before they examine it.
The habit that defeats it entirely
Never sign in from a link in an email. Not this one, not any of them.
If a message says something needs attention, open the platform the way you normally do and look. A real problem will be there. A fake one will not, and you will have found that out without ever touching the sender's page.
Two-factor authentication is the second half of it: it means that even a captured password, on its own, is not enough.
Red flags
- Urgency with a deadline — act within 24 hours, or the account or title will be removed permanently.
- A sign-in link in the message, rather than an instruction to sign in the way you normally would.
- The sender's domain is close to the real one but not it, often with an extra word, a hyphen, or a different ending.
- A generic greeting, or your email address used as your name.
- A request to confirm bank details, tax information or identity documents to release a payment.
- Threatened consequences that the real platform handles differently — genuine account issues appear in the dashboard, not only in email.
How to verify it yourself
- Do not click anything in the message. Open a new tab and type the platform's address yourself, or use your own bookmark.
- Sign in normally and look for the notice in the dashboard. If it is not there, it does not exist.
- Check the sender's full address, not the display name. The display name is free text and is routinely faked.
- If you want certainty, contact the platform through the support route inside your account.
- Turn on two-factor authentication, which makes a captured password much less useful.
What legitimate outreach usually looks like
- Retailers raise account and content problems inside the account dashboard itself, where you can see them after signing in normally.
- Real notifications rarely need you to act within hours, and never require a password to be entered from an email link.
- Payment and tax details are changed by you, in the account, not supplied in response to a request.
What not to send or pay
- Your password, on any page you reached from an email.
- Two-factor codes, to anyone, for any reason.
- Bank details, tax forms or identity documents in reply to an unsolicited message.
If you already replied
- Change the password immediately, starting with the affected account, then anywhere you reused it.
- Turn on two-factor authentication now if it was not already on.
- Check the account's payment and bank details, which is what an intruder changes first.
- Review recent sign-in activity if the platform exposes it, and sign out other sessions.
- Contact the platform's real support and tell them the account may be compromised.
Redacted examples
Real solicitations, with senders, addresses and links removed. Enough to show the shape of the message and nothing more.
Subject: Action required — your publishing account has been suspended
We have detected unusual activity on your account. Your titles have been removed from sale pending verification. Sign in using the secure link below within 24 hours to restore your account, or your listings will be permanently deleted.
This page describes a pattern, not a party. It is not a legal finding about any individual sender or company, and a message resembling this pattern is not by itself proof of anything about whoever sent it. If you are unsure about a specific approach, verify it through the steps above rather than by replying.