If the message was not opened or acted on

Do not reply, forward it casually or use any telephone number included in the message. Report it through the organisation's agreed route so the sender, links and attachment can be checked safely.

The IT team should search for matching messages across other mailboxes, block malicious indicators where appropriate and preserve enough information to investigate. Deleting only the original copy may leave identical messages waiting for colleagues.

If a link was opened or an attachment was run

Tell IT exactly what happened and when. If an unexpected program ran, a security warning appeared or the device began behaving unusually, disconnect it from wired and wireless networks without switching it off unless your incident procedure says otherwise. This can help contain activity while preserving useful evidence.

Do not keep testing the link or attachment. Security staff can examine it using appropriate tools and review the device, email logs and account activity.

If a password or MFA approval was provided

Treat the account as potentially compromised. Change the password from a known-safe device, revoke active sessions, review MFA methods and check for unfamiliar sign-ins, forwarding rules, inbox rules and application permissions. Other accounts using the same or a similar password also need attention.

A password change alone may not remove an attacker who has already created a forwarding rule, registered another authentication method or granted access to a malicious application.

If money or bank details were involved

Contact the bank immediately using a trusted number, alert the person responsible for finance and preserve the message trail. Verify any supplier-bank-detail change using a known contact method rather than replying to the email chain.

The organisation should follow its incident and reporting obligations, including advice from its insurer, legal adviser or relevant authority where personal data, fraud or a material service disruption may be involved.

Reduce the chance of the next message succeeding

  • Give staff a simple, blame-free way to report suspicious messages.
  • Use layered filtering and anti-spoofing controls such as SPF, DKIM and DMARC.
  • Require strong MFA and limit administrator privileges.
  • Monitor sign-ins, mailbox-rule changes and unusual account activity.
  • Keep a short incident checklist with named contacts and decision owners.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team