The “All Nippon Airways Raffle Draw” email is a fake prize scam, not a real ANA or IATA promotion. The message says an e-ticket was selected for a GBP 6,000,000 award, then sends the recipient to a supposed claims agent using a public email account. Do not reply, send identification, provide bank details, or pay a release fee. A person cannot win a raffle they never entered, and IATA says messages claiming to represent it from public domains such as Gmail should be treated as fraudulent.
This lure combines airline branding, a huge cash figure, an official-sounding “Corporate Social Responsibility Raffle Draw,” and a short response deadline. Its purpose is to start a conversation in which the attacker can collect identity documents, financial information, or advance fees.
Why the ANA/IATA raffle email is fake
The wording can change, but the decisive clues stay the same:
- You did not enter the draw. A random e-ticket number does not create a valid raffle entry or ownership of a cash prize.
- The supposed claims agent uses a public mailbox. IATA states that it does not communicate through public email domains such as Gmail, Outlook, Hotmail, Yahoo, or Proton Mail. It also warns that spoofed messages can display an IATA-looking sender while sending replies somewhere else.[1]
- The prize is implausibly large. GBP 6,000,000 is used to overcome caution and make a request for documents or a smaller “processing” payment feel reasonable.
- The message asks for identification before independent verification. Passport scans, national IDs, addresses, phone numbers, occupations, and bank details can be reused for identity fraud and more convincing follow-up scams.
- The deadline creates pressure. A demand to contact a claims agent within 24 or 48 hours discourages the recipient from checking official ANA and IATA channels.
- A real name proves nothing. Fraudsters can copy the name of an airline employee or IATA executive from a public page. The sender domain, reply-to address, promotion rules, and entry history matter more.
ANA also warns that criminals impersonate ANA Group names and addresses in emails that pressure recipients to reveal personal information. ANA recommends deleting suspicious, unrecognized messages and verifying through its official site rather than through the email.[2]
Example

Subject: Congratulations On Your Winning
From: All Nippon Airways Raffle Draw <claims.agent [at] gmail [dot] com>
Dear Winner,
Your e-Ticket 2060405065098 has been selected in the ANA/IATA Corporate Social Responsibility Raffle Draw.
Prize: GBP 6,000,000
Contact the Claims Department Agent within 48 hours. To process release, reply with your full name, address, phone number, country, occupation, and a copy of identification.
Button: CONTACT CLAIMS AGENT
The exact sender, deadline, ticket number, or claimed agent may change. The scam is defined by the unsolicited prize, the unverifiable claims route, and the request for sensitive information or money.
Real ANA promotion versus the fake cash-prize message
ANA can participate in legitimate promotions, which is why the brand reference may look believable. A documented ANA-linked promotion required a qualifying purchase, registration through published campaign mechanics, a receipt, eligibility rules, named dates, and a defined travel prize. It did not secretly select unrelated inboxes for a multi-million-pound cash payment.[3]
| Check | What the result means |
|---|---|
| Entry | A real entrant completed published steps. The scam says an email address or e-ticket was selected without prior participation. |
| Rules | A real campaign lists dates, eligibility, prize terms, and the organizer on an official page. The scam supplies only a dramatic claim and private contact route. |
| Prize | A legitimate offer describes a specific published prize. The scam promises an unexplained GBP 6,000,000 cash award. |
| Contact | A real promotion can be verified from the official campaign page. The scam routes the recipient to a public mailbox or unrelated reply-to address. |
| Payment | A real prize is not unlocked by surprise processing, tax, insurance, courier, or transfer fees paid to an unknown agent. |
How to verify the sender without replying
- Expand the complete From and Reply-To fields. A display name such as “ANA Raffle Draw” is editable. If the reply goes to Gmail or another public domain, stop.
- Do not use the email button, phone number, or claims address. Open a new browser tab and type the official ANA or IATA address yourself.
- Look for published campaign mechanics. Verify when and how you entered, the official rules, the prize, eligibility, draw date, and organizer. No published entry means there is no credible win to claim.
- Check the message as a whole. A sender can be spoofed, and a compromised legitimate mailbox can pass some authentication checks. Compare the request and context, not only the visible domain. Our phishing email checklist explains the sender, link, attachment, and pressure checks.
- Use an independent message check if needed. Paste the text and headers—not private passwords or ID scans—into the Gridinsoft Email Checker before replying or opening anything.
If the message claims to be from IATA, it can be reported to fraud.reporting [at] iata [dot] org. Forwarding the original message as an attachment preserves headers better than copying only the visible text.
What the scammer may ask for next
The first email may contain no malicious attachment and no payment request. That does not make it harmless. Its job is to identify a responsive recipient. The follow-up can ask for a passport or ID card, home address, occupation, bank account, beneficiary form, or proof of identity. It may then introduce a “release certificate,” tax, insurance, courier charge, currency-conversion cost, or transfer fee.
This is the same advance-fee pattern used by other fake awards. A separate fake Tesla stock prize email uses a different brand and asset but the same sequence: an unexpected windfall, private contact, identity collection, and fees before a nonexistent payout.
What to do if you already interacted
- You only opened the email: opening a normal message without clicking, downloading, replying, or entering information is usually low risk. Mark it as phishing, block the sender, and delete it.
- You replied but sent no sensitive data: stop the conversation, save the original email and headers, block the sender, and expect follow-up messages or calls. Do not pay anyone who later offers to recover the prize.
- You sent an ID or personal details: preserve the messages, notify the issuing authority where appropriate, watch for new accounts or verification attempts, and follow the steps in our identity theft protection guide.
- You shared bank or card details: contact the bank or card issuer using the number on the real card or official app. Ask about blocking transfers, replacing cards, changing online access, and monitoring activity.
- You sent money: contact the payment provider immediately and say it was fraud. Save transaction IDs, wallet addresses, receipts, and dates. Report the incident to the relevant fraud or cybercrime authority.
- You clicked a link or opened a download: close the page, do not enter credentials, and follow the action-based steps in our phishing-link recovery guide. Change exposed passwords from a trusted device and revoke suspicious sessions.
If the email led to a downloaded file, browser extension, remote-support tool, or installed application, deleting the visible download may not remove a loader, scheduled task, browser change, or bundled component. Run a full Gridinsoft Anti-Malware scan, remove detections, reboot, and scan again if warnings, redirects, or unusual activity return.
If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.
Scan after a suspicious email downloadFAQ
Did ANA or IATA run a GBP 6 million raffle?
No credible official campaign supports the unsolicited GBP 6,000,000 claim. A message saying you won without entering and routing you to a public mailbox is a scam.
Would IATA use Gmail for a claims agent?
No. IATA says it never communicates through public email domains and tells recipients to assume messages from those domains claiming to represent IATA are fraudulent.
Does e-ticket 2060405065098 prove the prize is real?
No. A number printed in an email is not proof of a booking, raffle entry, or award. Verify any real ticket only through the airline account or booking channel you used.
Can opening the email infect my device?
Merely reading a standard email is usually lower risk than clicking a link, opening an attachment, installing software, or entering data. The correct response depends on what happened after the message opened.
What if I sent a passport or ID copy?
Stop contact, preserve evidence, notify the document issuer when appropriate, monitor accounts, and begin identity-theft recovery steps. Treat later calls or messages using the same details as untrusted.
References
- International Air Transport Association. “Email & Website Fraud Protection.” IATA, updated July 16, 2026, accessed July 20, 2026. iata.org
- ANA Holdings, Inc.; All Nippon Airways Co., Ltd. “Be Careful of Fraudulent Emails and Phone Calls to Be from ANA Group.” ANA, October 2, 2025, accessed July 20, 2026. ana.co.jp
- All Nippon Airways. “Dine at Botejyu & Fly to Japan: Promo Mechanics and Terms.” ANA Philippines, 2025, accessed July 20, 2026. ana.co.jp

