Rebis.live e-mail scam: how to spot it and what to do
When you go to a high-risk website and click on a misleading or fraudulent link, Rebis.live may be the site that appears. Some users, on the other hand, might already have adware or other malware installed, resulting in deceptive browser redirects to this page.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Rebis.live e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Rebis.live e-mail scam: summary
| Distribution | Redirects from other malicious websites, adware |
|---|---|
| Damage | Loss of finances due to fake subscriptions; redirects to other malware-laden, scam websites; installation of potentially unwanted or malicious software |
| Name | Rebis.live |
| Type | Scam, phishing, redirect, adware |
| Operation | Claims that viruses have been found on the system and that security software has expired – it needs to be renewed immediately. Also, asks to download malicious software and enable push notifications |
| Symptoms | A phishing e-mail asking you to sign in |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 7 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Arrives as | |
| Pretends to be | Microsoft |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 7 September 2022 |
| Facts checked | 7 October 2026 |
How to tell the Rebis.live e-mail scam e-mail is fake
From our report of Sep 2022 · not reviewed since
- Users would be shown a system scan by a respected security firm Norton, after which results would appear.
- You should not interact with the contents shown by a scam website, check your system for adware or malware infections with security software
- After removal of unwanted software, make sure you clean your browsers from cookies and other trackers with
- Because Norton is one of the most well-known and long-standing security firms, many people may connect its name with something trustworthy.
Is Rebis.live e-mail scam dangerous? What the senders want
From our report of Sep 2022 · not reviewed since
Rebis.live deceives people into buying unnecessary software with fake virus infection alerts
When you go to a high-risk website and click on a misleading or fraudulent link, Rebis.live may be the site that appears.
Some users, on the other hand, might already have adware or other malware installed, resulting in deceptive browser redirects to this page.
They say the system has been infected with viruses that must be eliminated and that the software's license is expired, and users must renew their subscriptions. However, everything about these claims is fake, as they are not created by anyone else by scammers seeking to profit from phishing messages.
Those who do believe the fake scan results provided by Rebis.live will be asked to click the "Proceed" button, which would immediately redirect to what seems to be a subscription page of security software. While the advertised software might be legitimate, it may not always be the case, and you might be shown malware-laden links.
It is also important to note that clicks anywhere on the page might lead you to other websites of similar nature, including Scanprotectiontoday.com, Cadom.live, Stally.click, and many others. The site also asks you to enable push notifications right after you enter, which could result in additional issues with intrusive ads being shown on your desktop regularly.

From our report of Sep 2022 · not reviewed since
How the scam is operated and what to look out for
The branding, logos, and feel of the protection software help Rebis.live get more credibility in a way by making users believe that the warning is genuine.
Many people fall for this tech support scam that uses false positives from what appear to be legitimate security scans in order to scare users into thinking their system is infected. In reality, these results can easily be faked with the help of simple page elements. The "detections" and pop-ups that are shown in the course of a few seconds are just an imitation.
The only way to get reliable virus scan results is through a reputable anti-malware program installed on your system. So if you see any warnings about virus infections upon accessing a website, know that they are most likely fake and immediately leave the page.
If users click the "Proceed" button, they are immediately redirected to a website where they must buy anti-malware. You don't need an additional tool if you already have anti-malware installed. Furthermore, scammers might send you to a site where you may download bogus security software that would actually harm your system.
Therefore, the best thing is not to interact with any buttons or links and definitely not purchase any software offered in such dubious methods. Not only may you disclose your credit card details to criminals during the purchase process, but you might also infect your device with malicious software.

From our report of Sep 2022 · not reviewed since
Check your system thoroughly
More often than not, users come across scam websites when they are already on a high-risk site.
For example, pirate movie streaming sites or illegal torrents typically have fake "Download" buttons and malicious scripts. From there, users might be redirected to any suspicious website, like Rebis.live.
If your browser is directing you to ad-filled or otherwise questionable sites, it's time to check for infections on your device. Adware, for example, is questionable software that specializes in delivering users pop-ups, deals, discounts, redirects, and other annoying advertisements while also monitoring user information in the background.
Thus, to get rid of the redirects to suspicious phishing websites and intrusive ads, you should check your system for adware. Besides, security software can check the computer for other, more dangerous viruses that could be running in the background and performing malicious tasks without you knowing anything about it.
Since adware tends to monitor online user behavior, taking care of one's privacy is also important. Of course, you can also do this manually if you want to:
MS Edge (Chromium)
- Click the Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
- Click Safari > Clear History...
- From the drop-down menu under Clear, pick all history.
- Confirm with Clear History.
What to do after the Rebis.live e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you entered a password after clicking the link in the Rebis.live message, treat that account as known to the sender.
Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.
Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.
Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.
While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.
Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A page that only asked for a password installs nothing, so most readers can skip this step.
If the Rebis.live e-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.
In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
From our report of Sep 2022 · not reviewed since
Get rid of the push notifications
While the primary goal of Rebis.live is to deceive visitors into clicking affiliate links, it also makes use of additional strategies for monetization if users allow it.
Users are invited to turn on push notifications as soon as they enter - a genuine browser API function is utilized to deliver any sort of information right onto their screens.
Such fake websites are known to misuse the push notification feature for their own benefit and flood users with fake ads and links to malicious websites, thus, we don't recommend interacting with any of these.
MS Edge (Chromium)
- Open the Google Chrome browser and go to Menu > Settings.
- Locate the Privacy and security section and pick Site Settings > Notifications.
- Look at the Allow section and look for a suspicious URL.
- Click the three vertical dots next to it and pick Block. This should remove unwanted notifications from Google Chrome.
- Open Mozilla Firefox and go to Menu > Options.
- Click on Privacy & Security section.
- Under Permissions, you should be able to see Notifications. Click the Settings button next to it.
- In the Settings – Notification Permissions window, click on the drop-down menu by the URL in question.
- Select Block and then click on Save Changes. This should remove unwanted notifications from Mozilla Firefox.
- Open Microsoft Edge, and go to Settings.
- Select Site permissions.
- Go to Notifications on the right.
- Under Allow, you will find the unwanted entry.
- Click on More actions and select Block.
- Click on Safari > Preferences...
- Go to the Websites tab and, under General, select Notifications.
- Select the web address in question, click the drop-down menu and select Deny.
Questions about Rebis.live e-mail scam
Is Rebis.live really from Microsoft?
No. It is sent by scammers who copy the name and look of Microsoft. The sender address and the links do not belong to it, and the message asks for your password, which a real company does not request through an unexpected message.
If you want to be sure about your account, open the website or app of Microsoft the way you normally do, not through the message, and look for notices there. Then delete the message and report it as phishing. If you already followed its instructions, use the steps in this guide for your case.
Is it true that your account needs urgent attention?
No. The claim that your account needs urgent attention is the hook of Rebis.live, invented to give you a reason to act quickly. Scammers pick a story that could plausibly apply to many people, so it may feel relevant to you, but nothing in the message is based on your real accounts or devices.
If the claim concerns a service you use, check it there directly, by opening the website or app yourself. You will find no such problem. Then delete the message and report it as phishing.
What happens if I do what Rebis.live asks?
The scammers get your password, and they use it quickly. Passwords are tried on the real service within minutes, cards are charged or added to phone wallets, remote access is used to open your bank, and crypto is moved on at once.
Documents surface later as accounts in your name. If you already did what the message asked, do not wait to see what happens; follow the steps in this guide for your case today. Speed matters more than anything else here.
Will Microsoft refund me if I fell for Rebis.live?
Microsoft did not send the message and is not responsible for it, so a refund usually comes from your bank or card issuer, not from the brand. Call the bank first if you paid.
It still helps to tell the real company: they can secure your account, add notes for their fraud team and take down pages that use their name. Contact them through their official website or app only, never through the message or a search ad. Keep the message as evidence.
Should I reply or unsubscribe?
No. A reply confirms that your address is active and read, which leads to more scams. The unsubscribe link in a scam message is part of the scam and may lead to a phishing page. Mark the message as spam or phishing and delete it.
Block the sender if your mail app allows it, though scammers change addresses often. If the scam came by text message, do not reply STOP either. If it came through social media, use the platform's report function and block the account.
How do I report Rebis.live to my mail provider?
Use the built-in button. In Outlook, select the message and choose Report > Report phishing. In Gmail, open the message, click the three-dot menu and choose Report phishing.
Scam text messages can be forwarded to your carrier's spam number, which is 7726 in the US and the UK.
On social networks, use the report option on the message or the profile. Reporting trains the filters that protect you and other users, and it takes a few seconds. Then delete the message.
How can I spot messages like Rebis.live in future?
Check the sender's actual address, not only the name. Hover over links before clicking and compare the domain with the real one. Be suspicious of urgency, threats, prizes, unexpected invoices and requests for passwords, codes, card data or crypto.
Do not call phone numbers from unexpected messages; use the number on the official site or your card. When in doubt, go to the service directly through its app or a bookmark. Phishing protection and two-step verification limit the damage when a scam gets through.
Can just reading Rebis.live harm my PC?
No. Reading the e-mail does nothing to the PC. The risk lies in what the message wants you to do: your password. Every one of those needs an action from you, such as a click, a typed password, a payment or a call.
If you stopped at reading, you are fine. Delete it and report it. If you are unsure whether you clicked something, check your browser history for the time you read the message, and act on what you find there.
How quickly do scammers use a phished password?
Often within minutes. Phishing kits send each password to the operators as soon as it is typed, and many test it automatically on the real service. Some kits also pass the two-step code through in real time.
That is why the first hour matters: change the password, end all sessions and check that the recovery details are still yours. If nothing has changed by then, you were probably fast enough, but keep watching for login alerts and password-reset e-mails for a few weeks.
Will Fortect remove Rebis.live?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Rebis.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Proofpoint: What Is Phishing? (read October 7, 2026)
- WeLiveSecurity: Malicious scripts in compromised websites and how to protect yourself (read October 7, 2026)
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)
- Microsoft Support: Protect yourself from phishing (read October 7, 2026)