You open your inbox, and there’s an email saying your photos are about to be deleted.

There’s a date, a warning, and a big button telling you to fix it.

That’s the kind of message that makes you stop what you’re doing and pay attention.

And if you use iCloud, you might be on the receiving end of a message like this.

Your panicked reaction is what these scam emails are designed to trigger.

They usually say something has gone wrong with your account.

It might be that your storage is full, your payment has failed, or your account has been blocked.

Then they add pressure with a deadline and a quick way to “resolve” the problem.

But really, the link in the email is the problem.

It takes you to a page that looks very similar to Apple’s login screen, but it isn’t real.

If you enter your details, they go straight to the attacker.

From there, it can lead to access to your files, your email, and potentially other accounts if the same password is used elsewhere.

What makes this harder to spot is the timing.

These emails can arrive alongside genuine notifications about storage or billing, so nothing immediately feels out of place.

If you take a moment to look more closely, there are often small signs.

The sender address might not match Apple’s usual domain.

The wording can feel slightly off, and sometimes there are grammar mistakes that a large company wouldn’t normally make.

The safest way to handle this is not to use the link in the email at all.

If you’re unsure, go directly to your account through your device settings or by typing the official website into your browser.

That way you know you’re in the right place.

Many attacks now rely on persuasion rather than technical tricks. They’re built to create urgency and get a quick reaction.

Taking a few seconds to pause and check is often enough to avoid a much bigger problem.

And remind your team to do the same thing. Particularly on company devices.

If you saw an email like this, would you recognise it as a scam straight away?