Risk

What to Do When You Receive a Suspicious Email

A suspicious message does not automatically mean an account has been compromised. What employees do next can determine whether the threat is contained or becomes an incident.

Suspicious emails often try to create urgency.

They may appear to come from a leader, vendor, bank, delivery service, coworker or familiar platform. The message may ask the recipient to open a file, follow a link, scan a QR code, approve a sign-in, change payment instructions or provide information quickly.

The safest response is to slow down.

The main point

Do not click, reply, download, scan, approve or call a number provided in a suspicious message. Report it through the organization’s approved process.

CISA recommends reporting suspected phishing rather than interacting with the message. Many email platforms include a phishing-reporting feature that preserves information the security team may need.

If the organization has a different reporting process, employees should follow that process.

Signs that deserve another look

A message may be suspicious when it includes:

  • Unexpected urgency, pressure or secrecy
  • A request to change payment or banking information
  • An unfamiliar or slightly altered sender address
  • An unexpected attachment, shared document or QR code
  • A request for a password, verification code or MFA approval
  • A login page reached through an unsolicited message
  • A request that bypasses a normal approval process
  • Unusual language or behavior from a familiar person

No single sign proves that a message is malicious.

A familiar logo, display name or writing style is not proof that the message is legitimate.

What to do first

Stop interacting

Leave links, attachments, buttons, QR codes and reply fields untouched.

Do not call a phone number included in the message. Do not use a link in the message to visit the organization’s website.

Report the message

Use the email platform’s reporting feature or the reporting method established by the organization.

Do not forward a suspicious message to coworkers unless the organization’s reporting process specifically asks you to do so. A normal forward may expose additional people to the same links or attachments.

When necessary, notify IT through a new message, approved ticket or phone call.

Verify through another channel

Contact the supposed sender using a phone number, website, chat or email address you already trust.

Do not use contact information supplied by the suspicious message.

Independent verification is especially important for:

  • Payment changes
  • Gift-card purchases
  • Payroll or direct-deposit changes
  • Password resets
  • Requests for sensitive information
  • Urgent executive instructions

What to do after interacting

Close the page and report what happened.

Tell IT which link was opened, when it happened and which device was used. A review may still be appropriate even when no password or information was entered.

You entered a password

Contact IT immediately.

Use the legitimate service or an approved company process to change the affected password. IT may also need to:

  • Revoke active sessions
  • Review recent sign-ins
  • Check forwarding and mailbox rules
  • Review MFA methods
  • Reset account-recovery information

Review any other account using the same or a similar password.

You approved an MFA request

Report it immediately.

An approval may have granted account access even if the password is changed afterward. IT may need to revoke sessions, review sign-in activity and reset authentication methods.

You opened an attachment or installed software

Stop using the device and contact IT immediately.

Follow the organization’s incident-response instructions. If policy directs you to isolate the device, disconnect its network access without continuing to browse, email or open files.

Do not wait for visible symptoms.

You sent money or sensitive information

Notify leadership, finance, IT and the relevant financial institution immediately.

Use trusted contact information rather than numbers or links from the original message. Speed may improve the organization’s ability to stop or recover a fraudulent payment.

Create a reporting culture

Employees should be encouraged to report suspicious messages and mistakes quickly.

Shame and fear cause delays. Delays make incidents more difficult to contain.

A clear reporting method and calm response help employees speak up before a small event becomes a larger one.

What to avoid

Do not:

  • Reply to ask whether the message is legitimate.
  • Use contact information from the message.
  • Forward it casually to coworkers.
  • Approve an unexpected sign-in request.
  • Assume a familiar display name proves who sent it.
  • Delete the message before following the reporting process.
  • Wait for symptoms after opening a file or entering a password.

When to involve IT

Report suspicious messages when they target company accounts, devices, money, information or employees.

Immediate help is necessary after any interaction involving:

  • Passwords
  • MFA
  • Attachments
  • Installed software
  • Payment instructions
  • Sensitive information

The right first response is simple: stop, report and verify through another channel.

Need help improving email protection and response procedures? Book a consultation.

Sources and further reading

On this page
More Insights

Related Posts

Explore more from The Infrastructure Journal.

Protection

A Backup Is Not Complete Until It Has Been Tested

Having backup software is not the same…
Strategy

When Your Business Needs a Technology Roadmap

A technology roadmap helps organizations plan upgrades,…
Cloud

What to Know Before Moving Business Systems to the Cloud

Cloud services can improve access and flexibility,…
Get Started

Start with a solid foundation

Build systems that support your business without constant fixes or workarounds.