PanicStation.org
uk Technology & digital loss

What to do if…
you receive a data export is ready email for an account you did not request

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat it as either a phishing attempt or a sign someone may have access to your account. Do not click the email’s links; go directly to the service in your browser or app, secure the account, and cancel or remove any export you did not request if the service allows it.

Do not do these things

  • Don’t click “download export”, “review export”, or similar links in the email, even if the branding looks perfect.
  • Don’t reply to the email or use any phone numbers, chat links, or support links inside it.
  • Don’t assume it is harmless because it is “only a copy”; exports can include private messages, files, account details, contacts, or other sensitive data.
  • Don’t rush into deleting the account right now; that can make recovery harder and may not stop someone who is already signed in.
  • Don’t reuse an old password or a small variation of one after a suspected account compromise.

What to do now

  1. Pause and switch channels.
    Open a new browser tab, type the service’s web address yourself, use a trusted bookmark, or open the official app. Do not use the email to navigate.

  2. Check whether the export is real inside the account.
    Look for an area called “Data export”, “Download your data”, “Privacy”, “Security”, or similar.

    • If you cannot find any export activity inside the account, treat the email as suspicious and go to steps 7 and 8.
    • If you find an export you did not request, assume the account may be compromised and continue.
  3. If you cannot sign in, use the provider’s official recovery route.
    Go to the provider’s official website, trusted bookmark, or official app and look for its help or account recovery pages. If you use a search engine, choose only a result that clearly points to the provider’s official domain.

  4. Secure the account immediately.
    In the account’s security settings, use the closest available options to:

    • Change the password to a new, unique password.
    • Sign out of all devices, end active sessions, or remove unfamiliar devices.
    • Turn on 2-step verification, 2FA, or MFA using an option you can complete now.
  5. Remove anything that could keep someone in the account.
    Check for:

    • Email addresses or phone numbers you do not recognise.
    • Forwarding rules, filters, or auto-replies, especially on email accounts.
    • Connected apps, third-party access, linked accounts, or authorised devices you do not recognise.
    • Recovery options that are not yours.
  6. Cancel or remove the export if the service allows it.
    Use any option such as “Cancel export”, “Delete download”, or “Revoke access”. Take screenshots of the export page, recent sign-ins, unfamiliar devices, and any unusual settings before you change them, unless taking screenshots would expose more sensitive data.

  7. If this might be your email account, secure email next.
    Your email is often the reset route for other accounts. Change your email password, sign out of all sessions, turn on 2-step verification, and check forwarding rules and filters for anything you did not create.

  8. Report the message safely.
    If it looks like a scam email, forward it to [email protected] without clicking its links. If you have lost money or been hacked after responding to a phishing message, use Report Fraud if you are in England, Wales, or Northern Ireland; if you are in Scotland, contact Police Scotland on 101.

  9. If this is a work, school, or organisation account, contact internal support now.
    Use your organisation’s normal IT or security channel, not anything in the email. Ask them to check sign-ins, revoke sessions, and confirm whether a data export was started.

What can wait

  • You do not need to decide right now whether to delete the account, confront anyone, or replace every device.
  • You can wait to review every privacy setting once you have stopped access by changing the password, ending sessions, and turning on 2-step verification.
  • Deeper checking can wait until the account is secured, unless your work, school, bank, or another service tells you to act sooner.

Important reassurance

A “data export is ready” message can feel final, but it is often either a phishing lure or an account action that can still be checked and contained. Going directly to the service, changing the password, ending sessions, and turning on 2-step verification are strong first steps.

Scope note

These are first steps only to stabilise the situation and reduce further access. Later decisions may need help from the platform, your organisation’s IT or security team, fraud support, or another specialist service.

Important note

This is general information, not legal, financial, technical, or professional advice. Different services label exports and security controls differently, so use the closest equivalent settings available.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us