Ufxxs.xyz e-mail scam: how to spot it and what to do

Ufxxs.xyz is a shady website that tries to trick people into downloading a bogus browser extension. Users may infect their PC with a browser hijacker or another type of PUP (potentially unwanted program).

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Ufxxs.xyz e-mail scam yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Screenshot of Ufxxs.xyz: ufxxs xyz
Ufxxs.xyz as our 2022 report showed it.

Ufxxs.xyz e-mail scam: summary

DistributionShady websites; deceptive ads; freeware installations
NAMEUfxxs.xyz
TYPEPhishing attempt; adware
SYMPTOMSA page pops up asking users to install a browser extension to be able to proceed further
DANGERSUsers can be tricked into installing a browser hijacker or other types of PUPs
NameUfxxs.xyz
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
TypePhishing message
SymptomsA phishing e-mail asking you to sign in
Evidence7 write-ups by security sites; details still limited
Arrives asE-mail
Pretends to beA well-known company
ClaimYour account needs urgent attention
Asks forYour password
First seen15 April 2022
Facts checked6 October 2026

What the Ufxxs.xyz e-mail scam e-mail looks like

Text of a phishing e-mail asking you to sign in, as people saw it

a phishing e-mail asking you to sign in

TO CONTINUE - ADD EXTENSION TO CHROME

From our report of Apr 2022 · not reviewed since

Freeware distribution platforms

There is a possibility that Ufxxs.xyz opened without any user input.

This can happen if you have an adware infection - advertising-supported software. Most commonly, it is spread through freeware distribution platforms. They include additional programs in the installers to make their activity profitable.

You should be very careful during the installation process or use only official web stores and developer websites that are trustworthy. Always choose the "Custom" or "Advanced" installation methods, read the Privacy Policy and Terms of Use to find out what the program will be capable of doing. The most important part is to check the file list and untick the boxes next to any unrelated apps.

Is Ufxxs.xyz e-mail scam dangerous? What the senders want

From our report of Apr 2022 · not reviewed since

Ufxxs.xyz could infect your system with a browser hijacker or adware if you press "Continue"

Ufxxs.xyz is a shady website that tries to trick people into downloading a bogus browser extension.

Users may infect their PC with a browser hijacker or another type of PUP (potentially unwanted program). This can cause the main browser settings to change, like the homepage, new tab address, and search engine.

Users may also start experiencing an increased amount of commercial content, like pop-ups, banners, and redirects. Crooks often use rogue advertising networks that place ads leading to dangerous websites. As a result, people can end up on pages that try to trick them into providing personal information, downloading PUPs, and even malware.

Screenshot of Ufxxs.xyz: ufxxs xyz
Ufxxs.xyz in our 2022 report.

From our report of Apr 2022 · not reviewed since

Ufxxs.xyz in detail

Ufxxs.xyz is a promotional website for a dubious application.

It uses social engineering techniques to make people install an unknown browser plugin. It displays a deceptive message on the screen:

Fraudsters want to convince users that they have to download a third-party app to be able to access the content on the site. A legitimate website should never ask you to allow push notifications or install any software to get something in return. This is a very shady practice used by those who want to monetize user activity.

Usually, such pages hide in other suspicious sites. Often, they engage in illegal activities because they are unregulated. For example, illegal streaming platforms are full of deceptive ads, sneaky redirects, fake "Download" and "Play" buttons. Less IT-savvy people can be easily fooled into thinking that they need a browser plugin in order to watch the movie or TV show they selected.

Nowadays, there are plenty of legitimate streaming services, like Netflix or Hulu that require only a small subscription fee. People can consume as much content as they want. Also, avoid clicking on random links, like URLs embedded in the messages from strangers or on online forums.

Ufxxs.xyz: ufxxs xyz ads
Ufxxs.xyz in our 2022 report.

What to do after the Ufxxs.xyz e-mail

If you only received the message and clicked nothing, step 3 is all you need.

If you clicked the link or typed anything on the page it opened, do every step, starting with the password.

  1. Step 1: Change the password you typed on the fake page

    If you entered a password after clicking the link in the Ufxxs.xyz message, treat that account as known to the sender.

    Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.

    Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

    Microsoft account Security page with Change password at the top
    Microsoft account, Security page (account.microsoft.com/security): Change password.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  2. Step 2: Turn on two-step verification

    Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.

    Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.

    While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

    Microsoft account Manage how I sign in page with the sign-in methods
    Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  3. Step 3: Report the e-mail and delete it

    Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.

    Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

    Outlook Report menu with Report phishing selected
    New Outlook for Windows and Outlook on the web: Report > Report phishing.

    Full procedure with screenshots: Report a phishing e-mail

  4. Step 4: Scan the PC if you opened a file from the message

    A page that only asked for a password installs nothing, so most readers can skip this step.

    If the Ufxxs.xyz e-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.

    In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

From our report of Apr 2022 · not reviewed since

Removal process

If you have installed an extension from Ufxxs.xyz, you should definitely remove it.

MS Edge (Chromium)

  • Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  • In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
  • Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  • From the list, pick the extension and click on the Gear icon.
  • Click on Uninstall at the bottom.
  • Open Edge and click select Settings > Extensions.
  • Delete unwanted extensions by clicking Remove.
  • Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  • Select Add-ons.
  • In here, select unwanted plugin and click Remove.
  • Click Safari > Preferences...
  • In the new window, pick Extensions.
  • Select the unwanted extension and select Uninstall.

From our report of Apr 2022 · not reviewed since

Protect your privacy

You should clear your browsers to get rid of all the data that might have been collected about you.

Cookies are small data files that can contain information, like your IP address, geolocation, links you click on, and things you purchase online. This data can be sold to advertising networks or other third parties.

We suggest using a maintenance tool that can take care of this automatically. It will fully clear your browsers from cookies and cache, which will result in better performance of your machine. Besides, it can fix various complicated system errors that are caused by corrupted files, and registry issues, which is especially helpful after a virus infection.

From our report of Apr 2022 · not reviewed since

Get rid of potentially unwanted programs

If you still experience an increased amount of commercial content, pop-ups, banners, or redirects, you should check your system for adware.

The infection most commonly occurs when people do not pay attention during installation and browse through shady sites. If the previous removal method did not get rid of the intruder, you most likely have an adware infection.

Crooks often disguise PUPs as "handy" tools that you would not even suspect. It could look like an antivirus, system optimizer, media player, or else. If you are not sure what to do and you do not want to risk eliminating the wrong files, we suggest using professional security tools.

and can scan your machine, identify suspicious processes running in your machine, eliminate them, and prevent such infections in the future by giving you a warning before a malicious program can make any changes. If manual removal is what you still prefer, we have instructions for Windows and Mac machines:

To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:

  • Enter Control Panel into Windows search box and hit Enter or click on the search result.
  • Under Programs, select Uninstall a program.
  • From the list, find the entry of the suspicious program.
  • Right-click on the application and select Uninstall.
  • If User Account Control shows up, click Yes.
  • Wait till uninstallation process is complete and click OK.
  • Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
  • In Control Panel, select Programs > Uninstall a program.
  • Pick the unwanted application by clicking on it once.
  • At the top, click Uninstall/Change.
  • In the confirmation prompt, pick Yes.
  • Click OK once the removal process is finished.
  • From the menu bar, select Go > Applications.
  • In the Applications folder, look for all related entries.
  • Click on the app and drag it to Trash (or right-click and pick Move to Trash)
  • Select Go > Go to Folder.
  • Enter /Library/Application Support and click Go or press Enter.
  • In the Application Support folder, look for any dubious entries and then delete them.
  • Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.

Questions about Ufxxs.xyz e-mail scam

I opened the "TO CONTINUE - ADD EXTENSION TO CHROME" e-mail. Am I hacked?

No. Opening and reading a phishing e-mail does not give anyone access to your account or your PC. Modern mail programs block scripts and remote content by default, so reading the message "TO CONTINUE - ADD EXTENSION TO CHROME" only showed you text and pictures.

The danger comes from clicking the button and typing your password on the page it opens, or from opening an attached file. If you did neither, report the message as phishing and delete it.

If you clicked but closed the page without typing anything, there is also nothing to fix. If you did type a password, change it from another device and turn on two-step verification.

I typed my password after "TO CONTINUE - ADD EXTENSION TO CHROME". What now?

Act within the hour. From another device, open the real site of the account the message "TO CONTINUE - ADD EXTENSION TO CHROME" imitated and change the password. If the same password is used anywhere else, change it there too.

Sign out of all other sessions, check the recovery e-mail and phone number, and look for mail forwarding rules or filters you did not create. Then turn on two-step verification with an authenticator app or a passkey.

If the fake page also asked for a card number or a bank login, call your bank and ask them to block the card. Finally, report the e-mail so others are warned.

Is Ufxxs.xyz really from a well-known company?

No. It is sent by scammers who copy the name and look of a well-known company. The sender address and the links do not belong to it, and the message asks for your password, which a real company does not request through an unexpected message.

If you want to be sure about your account, open the website or app of a well-known company the way you normally do, not through the message, and look for notices there. Then delete the message and report it as phishing. If you already followed its instructions, use the steps in this guide for your case.

Is it true that your account needs urgent attention?

No. The claim that your account needs urgent attention is the hook of Ufxxs.xyz, invented to give you a reason to act quickly. Scammers pick a story that could plausibly apply to many people, so it may feel relevant to you, but nothing in the message is based on your real accounts or devices.

If the claim concerns a service you use, check it there directly, by opening the website or app yourself. You will find no such problem. Then delete the message and report it as phishing.

What happens if I do what Ufxxs.xyz asks?

The scammers get your password, and they use it quickly. Passwords are tried on the real service within minutes, cards are charged or added to phone wallets, remote access is used to open your bank, and crypto is moved on at once.

Documents surface later as accounts in your name. If you already did what the message asked, do not wait to see what happens; follow the steps in this guide for your case today. Speed matters more than anything else here.

Will a well-known company refund me if I fell for Ufxxs.xyz?

A well-known company did not send the message and is not responsible for it, so a refund usually comes from your bank or card issuer, not from the brand. Call the bank first if you paid.

It still helps to tell the real company: they can secure your account, add notes for their fraud team and take down pages that use their name. Contact them through their official website or app only, never through the message or a search ad. Keep the message as evidence.

How do I report Ufxxs.xyz to my mail provider?

Use the built-in button. In Outlook, select the message and choose Report > Report phishing. In Gmail, open the message, click the three-dot menu and choose Report phishing.

Scam text messages can be forwarded to your carrier's spam number, which is 7726 in the US and the UK.

On social networks, use the report option on the message or the profile. Reporting trains the filters that protect you and other users, and it takes a few seconds. Then delete the message.

How urgent is Ufxxs.xyz?

Urgent enough to act today, not urgent enough to panic. The sign reported, an e-mail with the subject "TO CONTINUE - ADD EXTENSION TO CHROME", means someone is using or testing your details. Changing the password and turning on two-step verification takes ten minutes and usually locks them out.

If a payment is involved, the sooner the bank knows, the better the chance of getting it back. Do not respond to calls or messages that arrive right after the incident, even if they claim to be from your bank: call the bank yourself.

Could malware on my computer cause Ufxxs.xyz?

It can, but it is not the most common cause. Information stealers copy saved passwords and session cookies from browsers, which can lead to an e-mail with the subject "TO CONTINUE - ADD EXTENSION TO CHROME". More often, the password came from a breach or a phishing page.

To be sure, run a full scan in Windows Security and check Installed apps and browser extensions. If anything is found, clean the PC first and change passwords afterwards from a clean device, because changing them on an infected PC lets the malware take the new ones too.

Will Fortect remove Ufxxs.xyz?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Ufxxs.xyz, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Ufxxs.xyz e-mail scam

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year