What to do if…
you receive a data export is ready email for an account you did not request
Short answer
Treat the email as suspicious until you verify it from the official site or app. Do not click links in the email; go directly to the account, check whether an export exists, and secure the account if anything looks unfamiliar.
Do not do these things
- Do not click “download export” links or open attachments from the email.
- Do not call support numbers or use “verify your account” links provided in the message.
- Do not reply with passwords, codes, ID documents, payment details, or personal information.
- Do not reuse an old password or a small variation of it.
- Do not wait for another alert before checking and securing the account.
What to do now
-
Navigate without using the email.
Open the official app, use a trusted bookmark, or type the service’s address yourself. Sign in only through that route. -
Check whether a data export is really pending or ready.
Look in the account for areas such as “Privacy,” “Security,” “Download your data,” “Export,” or “Recent activity.”- If you do not see an export or matching activity, treat the email as phishing and report it through safe channels.
- If you see an export you did not request, treat the account as possibly compromised.
-
If you cannot sign in, use the provider’s official recovery process.
Go to the service’s help or recovery page from the official website or app, not from the email. After you regain access, continue securing the account. -
End other access and change the password.
In security settings, use options such as “sign out of all devices,” “revoke sessions,” or “remove devices” if available. Then change the password to a new, unique password you do not use anywhere else. -
Turn on two-factor authentication.
Use an authenticator app or security key if the account offers one. Text-message codes are still better than no two-factor authentication if that is the only option available. -
Check for ways someone could stay in the account.
Remove anything you do not recognize, especially:- recovery email addresses, recovery phone numbers, or secondary addresses
- email forwarding, filters, or mailbox rules
- connected apps, authorized applications, API tokens, or third-party access
- devices or sessions you do not recognize
-
Cancel or delete the export if the service allows it.
Look for options such as “cancel export,” “delete download,” or “revoke download link.” If you need to contact support, screenshots of the export page and recent sign-in activity may help. -
Report the email safely.
Use your email app’s built-in “report phishing,” “report spam,” or “report junk” option. You can also report phishing to the FTC and forward phishing emails to the Anti-Phishing Working Group. -
Use IdentityTheft.gov if you see signs of identity theft.
Do this if you notice new accounts you did not open, financial alerts you cannot explain, tax or benefits misuse, or other signs that your personal information is being used. -
If this is a work or school account, contact IT or security.
Use your organization’s normal helpdesk or security channel, not the email. Ask them to review sign-ins, revoke sessions, and confirm whether a data export was created.
What can wait
- You do not have to decide now whether to delete the account.
- You do not have to change every low-priority password before securing this account.
- You can review older connected apps, old devices, and account privacy settings after you have regained control, ended unknown sessions, changed the password, and turned on two-factor authentication.
- You can decide later whether to contact customer support again, monitor for more alerts, or do a fuller identity-theft review.
Important reassurance
This kind of email is meant to create urgency, whether it is a real account notice or a phishing attempt. Moving carefully is safer than moving fast: avoid the email links, verify from the official site or app, and secure the account one step at a time.
Scope note
These are first steps to reduce immediate harm and stop further access. If an export was created or downloaded, later decisions may need help from the platform, your employer or school, identity-theft support, or another specialist.
Important note
This is general information, not legal, medical, financial, therapeutic, cybersecurity, or professional advice. Services handle exports and security settings differently, so use the closest matching official settings and support routes for the account involved.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.