Mybarpoint.xyz e-mail scam: how to spot it and what to do
Mybarpoint.xyz is a fake website that promotes survey and gift card scams. You may have accessed it accidentally while browsing the web, although redirects from potentially dangerous websites are more likely to occur.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Mybarpoint.xyz e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Mybarpoint.xyz e-mail scam: summary
| Distribution | Adware, malicious links, redirects from other websites |
|---|---|
| Name | Mybarpoint.xyz |
| Type | Scam, phishing, adware |
| Goal | Make people provide personal information, subscribe to useless services, download malicious software or subscribe to push notifications |
| Dangers | Malicious software can cause redirects to malicious websites – financial losses, malware infections, and data disclosure can be more likely |
| Symptoms | A phishing e-mail asking you to sign in |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 7 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Arrives as | |
| Pretends to be | Amazon |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 27 May 2022 |
| Facts checked | 6 October 2026 |
What the Mybarpoint.xyz e-mail scam e-mail looks like
Congratulations!
Amazon.com User!
You've been selected as a lucky user for a chance to get the $1000 Amazon Gift Card, Apple iPhone X or Samsung Galaxy! Please click OK for a chance to GET your reward
How to tell the Mybarpoint.xyz e-mail scam e-mail is fake
From our report of May 2022 · not reviewed since
- You should check your system for adware - scan it with for a quick check
Is Mybarpoint.xyz e-mail scam dangerous? What the senders want
From our report of May 2022 · not reviewed since
Mybarpoint.xyz scam wants you to click on one of the fake gifts: it's fake
Mybarpoint.xyz is a fake website that promotes survey and gift card scams.
You may have accessed it accidentally while browsing the web, although redirects from potentially dangerous websites are more likely to occur. In some rarer cases, adware could also be one of the main reasons you encounter phishing messages.
Upon entry, users are told that they have been selected by a reputable company (Google, Amazon, etc.) to receive an expensive gift - all they have to do is answer a few questions or simply select one of the three gift boxes. What people don't know is that the main goal of the Mybarpoint.xyz scam is to make them provide their personal information or subscribe to useless services.
If you have encountered this scam, you should not interact with any of its components and not provide any of your personal details. Otherwise, you might face personal information disclosure or even identity theft. Below we provide several tips on what to do in both scenarios and what to do to protect yourself in the future.


From our report of May 2022 · not reviewed since
Scam analysis
Mybarpoint.xyz is a misleading website that could promote various fake giveaways, gift cards, and other lottery-based material.
There are many variations on how this can be portrayed, but these scams usually use a name of a reputable and well-known company to make the scheme more believable.
They also attempt to imitate the looks of websites those companies use, so, for example, if you see the "You've made the 9.68-billionth search!" scam, Google's typical colors, logos, font, and other attributes would be shown. In other cases, you could be told that you were selected by Amazon for a chance to receive a pricy item:
It is important to note that if the message seems too good to be true, it likely is. High-profile companies don't randomly select people only to give them items worth hundreds or thousands of dollars - there's simply no point in them doing this.
Also, always check the URL of the page showing the message - it is pretty obvious that Mybarpoint.xyz has nothing to do with Amazon or Google.

What to do after the Mybarpoint.xyz e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you typed a password on the page the Mybarpoint.xyz message opened, assume the sender has it. Go to the real site by typing its address yourself and change the password there, choosing one you have never used.
Change it anywhere else the same password was used, and sign out all other sessions if the service offers it. Any browser on Windows 11 or Windows 10 will do, as long as you do not follow the e-mail's link.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
With two-step verification on, a stolen password alone no longer opens the account, because a sign-in from a new device also needs a code from your phone.
Switch it on for the e-mail account first, then for banking, shopping and social accounts that use that address.
Check the recovery phone, the recovery e-mail and any forwarding rules while you are in the settings, since attackers change them to come back. The pages are the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Do not reply and do not click anything else in the message. In Outlook select the e-mail and choose Report > Report phishing; in Gmail open the three-dot menu next to Reply and pick Report phishing.
That trains the filter for everyone on the service, and the message goes to the junk folder. If the e-mail came to a work address, forward it to your IT team as an attachment first.
The steps are the same in the web mail and the mail apps on Windows 11 and Windows 10.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A fake sign-in page only steals what you type, so most readers can skip this step. If the Mybarpoint.xyz e-mail made you download or open a file, delete it and scan the PC.
In Windows Security > Virus & threat protection > Scan options, run a Full scan and then Microsoft Defender Antivirus (offline scan) > Scan now. The offline scan restarts Windows 11 or Windows 10 and takes about 15 minutes.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
From our report of May 2022 · not reviewed since
Adware and malware removal
If you constantly encounter misleading messages and phishing websites, you should make sure your system is not infected.
It can locate all adware and malware to remove them effectively.
Some potentially unwanted programs might not be detected automatically as they are not inherently malicious, but they can lead to a lot of privacy and security issues sometimes. Thus, check the installed applications section and get rid of everything you find suspicious:
To thoroughly remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
PUPs can also be installed as browser extensions. In fact, it is the most common form used by their distributors, as they are easy to produce and replicate under different names if needed. The easiest way to remove unwanted add-ons is by clicking the "Extensions" button next to the settings menu.
The easiest way of doing this is by employing the repair and maintenance tool, although, if you prefer it, the manual method is also available:
MS Edge (Chromium)
MS Edge (legacy)
- Enter Control Panel into the Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till the uninstallation process is complete and click OK.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Privacy & security.
- Under Clear browsing data, pick Choose what to clear.
- Select everything (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.
- Click Safari > Clear History...
- From the drop-down menu under Clear, pick all history.
- Confirm with Clear History.
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.
Questions about Mybarpoint.xyz e-mail scam
Can reading "You've been selected as a lucky user for a chance to get…" infect my computer?
Reading it cannot. An e-mail is text and pictures, and current versions of Outlook, Gmail and other web mail services do not run code from a message just because you opened it. What can cause harm is an action:
- signing in on the page the link opens
- opening an attachment
- enabling macros in a document
The message "You've been selected as a lucky user for a chance to get…" was built to lead you to one of those steps. If you stopped at reading, delete it and use the report button so the provider can block the same wave for others. Nothing needs to be removed from Windows.
How fast do I need to react after signing in on the "You've been selected as a lucky user for a chance to get…" page?
As fast as you can. Stolen passwords are often tried within minutes, and the first thing an attacker usually changes is the recovery e-mail or phone, which locks you out. Change the password from a clean device first, then sign out everywhere and review the recovery settings.
If you are already locked out, use the provider's account recovery form straight away and mention that the page behind "You've been selected as a lucky user for a chance to get…" took your password. Warn your contacts, since a taken-over mailbox is often used to send the same phishing to them.
Could Mybarpoint.xyz be a genuine message?
We checked it, and it is not. Amazon is only the costume. The message exists to get your password, and real companies handle that inside your account, after you sign in normally, not through links, attachments or phone numbers in a message you did not expect.
Scammers copy logos and footers perfectly, so the design proves nothing. The sender address, the link target and the request are the reliable signs, and all three point to a scam here. Delete it, and if you are worried, check your account directly.
Why does Mybarpoint.xyz say that your account needs urgent attention?
Because that story works. A problem that needs fixing, a deadline and a simple solution make people act before they check.
The claim that your account needs urgent attention is the same for everyone who received Mybarpoint.xyz; it was written once and sent in bulk. Nothing about your own situation triggered it.
If you are unsure, look at the real account or service the normal way, without using the message. The claim will not be there, which settles the question. Then report the message.
What does Mybarpoint.xyz want from me?
In the end, your password. Everything else in Mybarpoint.xyz, from the logo to the deadline, is there to get you to that point without stopping to think. Knowing the goal helps you judge your risk.
If you did not give it, you lost nothing and can delete the message. If you did, the steps in this guide are ordered by what you handed over:
- passwords first
- then card and bank details
- then documents and anything you installed
- ran
Act on the highest item on that list first.
How do I contact the real Amazon?
Not through anything in Mybarpoint.xyz. Type the official website address into the browser yourself, use the app you already have, or use the phone number printed on your card, contract or a previous genuine invoice.
Search results can be risky too, because scammers buy ads for support numbers. Once you reach the real Amazon, you can ask whether there is any problem with your account and report the scam message; many companies have a dedicated address for phishing reports on their security page.
Why did I receive Mybarpoint.xyz?
Scam messages go to millions of addresses and numbers collected from data breaches, public websites and simple guessing. Receiving Mybarpoint.xyz does not mean your PC is infected or that an account of yours was hacked.
If the message includes an old password of yours, it comes from a breach of some website; change that password wherever you still use it. Mark the message as spam or phishing so your provider blocks similar ones. Never reply to ask to be removed from the list: the sender treats a reply as proof that the address works.
I entered my password on the fake page. What should I do?
Change the password on the real site right away, through its own website or app, and sign out of all sessions.
If you use the same password anywhere else, change it there too. Turn on two-step verification with an authenticator app or a passkey. Check the account for changes:
- recovery e-mail
- phone number
- forwarding rules
- recently sent messages
If you can no longer sign in, use the provider's account recovery page. Tell your contacts if the account sent messages in your name.
What is the single best habit against scams like this?
Never act on a message through the message itself. If something claims to be from Amazon and asks you to sign in, pay, call or open a file, close it and go to the service the way you always do:
- a bookmark
- the app
- the number on your card
Real problems will be visible there. This one habit defeats almost every phishing, invoice, delivery and account-suspension scam, regardless of how convincing the design is, because the scammers can copy the look but not the real account.
Will Fortect remove Mybarpoint.xyz?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Mybarpoint.xyz, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Imperva: Phishing attacks (read October 6, 2026)
- FTC: How to recognize and avoid phishing scams (read October 6, 2026)
- CISA: Recognize and report phishing (read October 6, 2026)
- Microsoft Support: Protect yourself from phishing (read October 6, 2026)
- NCSC: Phishing attacks, dealing with suspicious e-mails and messages (read October 6, 2026)