Check the email
- Suspicious email arrivesEmployee
For employees who get a suspicious email: what to check, how to report it, and what to do right away if you clicked, typed a password or paid.
Don't click links, open attachments, reply or use unsubscribe links while you check.
- Look for the warning signsEmployee
Sender address that doesn't match the company, or a lookalike such as amazan.com. Hover over links to see the real address. Shortened links hide it.
Urgency or threats, such as an account on hold. Requests for passwords, payment, gift cards or new bank details. Unexpected attachments. A generic greeting.
Perfect spelling and grammar don't make it safe. Attackers use AI to write convincing messages.
- Could it be phishing?Employee
- Yes or not sure: go to step 4, Report it with the Report phishing button
- Probably genuine: go to step 5, Check with the sender through a known contact
- Check with the sender through a known contactEmployee
Use a phone number or website you already know, not details from the email. Never confirm by replying.
- Did the sender confirm it's real?Employee
- Yes: go to step 7, Genuine email. Carry on
- No: go to step 4, Report it with the Report phishing button
- Genuine email. Carry onEmployee
- Did you click a link, open an attachment or reply?Employee
- Reported. Delete it and stay alertEmployee
The report button usually removes the email. Watch for similar messages, and don't forward it to colleagues.
- Tell security right away, even if you're unsureEmployee
Say what you clicked, opened or typed, and when. Fast reports limit the damage, and good security teams don't blame people for reporting.
Act fast if you clicked
- Did you open an attachment or install anything?Employee
- Yes: go to step 12, Disconnect the device from the network
- No: go to step 13, No file opened
- Disconnect the device from the networkEmployee
Unplug the network cable and turn off Wi-Fi. Don't try to clean it yourself unless security asks you to.
Run a full antivirus scan only if security tells you to.
Then go to step 14, Did you enter a password or a code on the page?
- No file openedEmployee
- Did you enter a password or a code on the page?Employee
- Yes: go to step 15, Change that password now on another device
- No: go to step 17, No password entered
- Change that password now on another deviceEmployee
Go to the real site by typing its address yourself, not through the email. Change any other account that uses the same password.
- Sign out everywhere and check your MFA settingsEmployee
Use the account's option to sign out all sessions. Check that no new MFA device or email forwarding rule was added. Turn on MFA if it was off.
Then go to step 18, Did you send money, bank details or company data?
- No password enteredEmployee
- Did you send money, bank details or company data?Employee
- Yes: go to step 19, Call finance and the bank immediately
- No: go to step 20, No money or data sent
- Call finance and the bank immediatelyEmployee
Speed matters. Ask the bank whether the payment can be stopped or recalled. Use the number on your card or statement.
If you sent card details, cancel the card. Report data you sent, such as customer records, to security and your privacy lead.
Then go to step 21, Hand over to the security team
- No money or data sentEmployee
- Hand over to the security teamEmployee
Security triage
- Review the reported emailSecurity
Check the headers, links and attachments. Find everyone else who got the same email.
- Remove the email from every mailbox and block the sender and linksSecurity
Add the sender, domains and link addresses to your email and web filters.
- Did anyone click, enter details or run a file?Security
- Close the report and thank the reporterSecurity
Quick feedback shows staff that reporting is worth it.
- Reset credentials and revoke sessions for affected accountsSecurity
Re-provision accounts that may be compromised. Audit account access afterwards to confirm the attacker no longer has it. Check for new MFA devices and mailbox rules.
- Isolate and examine affected devicesSecurity
Isolating the workstation stops malware spreading. Have the malware analyzed, remove it, then restore or rebuild the device and confirm it works.
- Was money, personal data or a wider system affected?Security
- Escalate to a full security incidentSecurity
Bring in finance, legal and privacy. Personal data breaches may have legal reporting deadlines.
US organizations can report to CISA at report@cisa.gov or the FBI's IC3. In the UK, report fraud to Report Fraud or Police Scotland.
- Contained. Close with lessons learnedSecurity
Share a short warning about this email with staff if others may get it.