Report a suspicious message or account activity
Preserve the evidence and use your established security escalation process.
Stop interacting with the suspicious request
Do not click additional links, open unexpected attachments, or approve an unrecognized sign-in prompt. If you already interacted, report exactly what happened without embarrassment; the sequence helps the team decide the next steps. Use your organization's security escalation channel for an active concern. If you suspect the affected mailbox is compromised, use another established contact method rather than relying only on that mailbox.
Collect the important facts
- When the message or activity appeared.
- The affected business account or device.
- Whether you clicked, downloaded, entered credentials, or approved a prompt.
- Any unexpected sign-in or forwarding behavior.
- A redacted screenshot or message details requested by the team.
Preserve the original message where possible. Do not distribute a live malicious attachment to coworkers or paste passwords into the ticket to explain what was entered.
Let the incident owner coordinate changes
The appropriate response depends on the situation and your organization's process. Avoid broad deletion, account removal, or device wiping without direction, since those actions can destroy evidence and interrupt recovery.
Keep follow-up current
Add new observations to the same incident conversation and identify the time of each event. Security and access incidents require employee review; an automated article suggestion is not confirmation that the account or device is safe.
Include this guide and what you tried in your ticket so we can pick up from there.
Contact support