If the message was not opened or acted on
Do not reply, forward it casually or use any telephone number included in the message. Report it through the organisation's agreed route so the sender, links and attachment can be checked safely.
The IT team should search for matching messages across other mailboxes, block malicious indicators where appropriate and preserve enough information to investigate. Deleting only the original copy may leave identical messages waiting for colleagues.
If a link was opened or an attachment was run
Tell IT exactly what happened and when. If an unexpected program ran, a security warning appeared or the device began behaving unusually, disconnect it from wired and wireless networks without switching it off unless your incident procedure says otherwise. This can help contain activity while preserving useful evidence.
Do not keep testing the link or attachment. Security staff can examine it using appropriate tools and review the device, email logs and account activity.
If a password or MFA approval was provided
Treat the account as potentially compromised. Change the password from a known-safe device, revoke active sessions, review MFA methods and check for unfamiliar sign-ins, forwarding rules, inbox rules and application permissions. Other accounts using the same or a similar password also need attention.
A password change alone may not remove an attacker who has already created a forwarding rule, registered another authentication method or granted access to a malicious application.
If money or bank details were involved
Contact the bank immediately using a trusted number, alert the person responsible for finance and preserve the message trail. Verify any supplier-bank-detail change using a known contact method rather than replying to the email chain.
The organisation should follow its incident and reporting obligations, including advice from its insurer, legal adviser or relevant authority where personal data, fraud or a material service disruption may be involved.
Reduce the chance of the next message succeeding
- Give staff a simple, blame-free way to report suspicious messages.
- Use layered filtering and anti-spoofing controls such as SPF, DKIM and DMARC.
- Require strong MFA and limit administrator privileges.
- Monitor sign-ins, mailbox-rule changes and unusual account activity.
- Keep a short incident checklist with named contacts and decision owners.
Official sources and further reading
These primary sources were checked when this article was last reviewed.
