Free cybersecurity training for organizations of any size. Schedule yours today ›

The “Bad Review” Email Scam: That 1-Star Alert Might Be a Trap

The Security BriefApril 1, 2026

Scammers are sending fake 1-star review alerts that steal business logins. Here's how the scam works, and how to keep your team out of it.

Few things make a business owner’s stomach drop faster than the words “1-star review.” Your reputation is how you win customers, so when an email says someone just trashed it, your first instinct is to click and see the damage.

Scammers know that. And right now, they’re using it against businesses just like yours.

There’s a scam making the rounds that disguises itself as a review notification. The good news: once you know how it works, it’s easy to spot, and even easier to avoid.

How the scam works

It starts with an email claiming your company received negative feedback. The subject line or message usually says something like:

  • “You received a new 1-star review”
  • “Customer left negative feedback”
  • “Your rating has dropped”
  • “Action required to respond”

The message is dressed up to look like it came from a legitimate platform (Google, Yelp, or Facebook), complete with a convincing button to “view” or “respond to” the review.

Click that button, and you land on a login page that looks remarkably like the real Google, Facebook, or your email provider. But it isn’t. If you type in your username and password, the attackers capture them on the spot.

From there, things can escalate quickly. With access to your account, attackers can send emails as you (targeting your coworkers, clients, or vendors) or use that foothold to work their way deeper into your organization.

Why this one fools smart people

This scam works because it creates urgency around something you genuinely care about: your reputation.

When you believe a bad review needs immediate attention, reacting quickly feels like the responsible thing to do. That sense of urgency is exactly what the message is designed to trigger. It’s not a sign of carelessness. It’s a sign the scam is well-crafted.

The biggest red flag: the link

One of the most reliable tells is the link itself. Hover your mouse over it (don’t click) and look at where it actually goes.

A legitimate notification will point to a real domain like google.com, yelp.com, or facebook.com. The scam version will point somewhere else, often a misspelled or unfamiliar web address that’s hoping you won’t look too closely.

How to protect yourself

A few simple habits will keep you and your team out of this trap:

  • Don’t click links in unexpected review emails. If you weren’t expecting the notification, treat it with suspicion.
  • Hover before you click. Confirm the link actually leads to the platform it claims to be from.
  • Go to the source directly. Open a browser and navigate to Google, Yelp, or Facebook yourself to check whether a review really exists.
  • Pause before entering credentials. When in doubt, stop and double-check before typing your login information anywhere.
  • Use identity threat detection (ITDR). This monitors for suspicious logins and unusual account activity, so even if credentials slip out, you catch it early.

Not sure if an email is legit? Ask us

If a message like this lands in your inbox and something feels off, don’t agonize over it alone. We’re always happy to take a quick look and help you verify before anything gets clicked. That two-minute check has saved more than a few businesses a very bad week.

And if you’d like to know how your defenses stack up overall, start with our free 60-second Security Score or talk to our team. A little prevention now beats a lot of cleanup later.

Ready to get started?

Get a free quote, or talk to our team about your IT needs.