Suspicious emails often try to create urgency.
They may appear to come from a leader, vendor, bank, delivery service, coworker or familiar platform. The message may ask the recipient to open a file, follow a link, scan a QR code, approve a sign-in, change payment instructions or provide information quickly.
The safest response is to slow down.
The main point
Do not click, reply, download, scan, approve or call a number provided in a suspicious message. Report it through the organization’s approved process.
CISA recommends reporting suspected phishing rather than interacting with the message. Many email platforms include a phishing-reporting feature that preserves information the security team may need.
If the organization has a different reporting process, employees should follow that process.
Signs that deserve another look
A message may be suspicious when it includes:
- Unexpected urgency, pressure or secrecy
- A request to change payment or banking information
- An unfamiliar or slightly altered sender address
- An unexpected attachment, shared document or QR code
- A request for a password, verification code or MFA approval
- A login page reached through an unsolicited message
- A request that bypasses a normal approval process
- Unusual language or behavior from a familiar person
No single sign proves that a message is malicious.
A familiar logo, display name or writing style is not proof that the message is legitimate.
What to do first
Stop interacting
Leave links, attachments, buttons, QR codes and reply fields untouched.
Do not call a phone number included in the message. Do not use a link in the message to visit the organization’s website.
Report the message
Use the email platform’s reporting feature or the reporting method established by the organization.
Do not forward a suspicious message to coworkers unless the organization’s reporting process specifically asks you to do so. A normal forward may expose additional people to the same links or attachments.
When necessary, notify IT through a new message, approved ticket or phone call.
Verify through another channel
Contact the supposed sender using a phone number, website, chat or email address you already trust.
Do not use contact information supplied by the suspicious message.
Independent verification is especially important for:
- Payment changes
- Gift-card purchases
- Payroll or direct-deposit changes
- Password resets
- Requests for sensitive information
- Urgent executive instructions
What to do after interacting
You clicked a link but entered nothing
Close the page and report what happened.
Tell IT which link was opened, when it happened and which device was used. A review may still be appropriate even when no password or information was entered.
You entered a password
Contact IT immediately.
Use the legitimate service or an approved company process to change the affected password. IT may also need to:
- Revoke active sessions
- Review recent sign-ins
- Check forwarding and mailbox rules
- Review MFA methods
- Reset account-recovery information
Review any other account using the same or a similar password.
You approved an MFA request
Report it immediately.
An approval may have granted account access even if the password is changed afterward. IT may need to revoke sessions, review sign-in activity and reset authentication methods.
You opened an attachment or installed software
Stop using the device and contact IT immediately.
Follow the organization’s incident-response instructions. If policy directs you to isolate the device, disconnect its network access without continuing to browse, email or open files.
Do not wait for visible symptoms.
You sent money or sensitive information
Notify leadership, finance, IT and the relevant financial institution immediately.
Use trusted contact information rather than numbers or links from the original message. Speed may improve the organization’s ability to stop or recover a fraudulent payment.
Create a reporting culture
Employees should be encouraged to report suspicious messages and mistakes quickly.
Shame and fear cause delays. Delays make incidents more difficult to contain.
A clear reporting method and calm response help employees speak up before a small event becomes a larger one.
What to avoid
Do not:
- Reply to ask whether the message is legitimate.
- Use contact information from the message.
- Forward it casually to coworkers.
- Approve an unexpected sign-in request.
- Assume a familiar display name proves who sent it.
- Delete the message before following the reporting process.
- Wait for symptoms after opening a file or entering a password.
When to involve IT
Report suspicious messages when they target company accounts, devices, money, information or employees.
Immediate help is necessary after any interaction involving:
- Passwords
- MFA
- Attachments
- Installed software
- Payment instructions
- Sensitive information
The right first response is simple: stop, report and verify through another channel.
Need help improving email protection and response procedures? Book a consultation.