Phishing and mailbox takeover remain common ways for attackers to reach business systems. Early recognition and a clear reporting process can reduce the impact of a suspicious message or compromised account.
Warning signs in an email
- Unexpected password-reset, payment or document-sharing requests.
- A familiar display name using an unfamiliar or misspelled email address.
- Urgent instructions asking the recipient to bypass the normal approval process.
- Links that do not match the visible company or service name.
- Attachments that request macros, sign-in details or security changes.
Warning signs after a mailbox is compromised
- Unrecognized forwarding or inbox rules.
- Messages marked as read or deleted without the user’s action.
- Sign-ins from unfamiliar locations, devices or applications.
- Contacts reporting unusual requests from the account.
- Unexpected changes to MFA methods, recovery details or delegated access.
Immediate response steps
- Disconnect or isolate the affected device when malicious activity is suspected.
- Reset the account password from a known-clean device.
- Revoke active sessions and review registered MFA methods.
- Remove suspicious forwarding rules, delegates and application permissions.
- Review message trace, login activity and sent items.
- Notify affected contacts when a malicious message may have been sent.
Controls that reduce risk
Use MFA, least-privilege administration, SPF, DKIM, DMARC, secure email filtering, user reporting tools, endpoint protection and regular awareness guidance. Technical controls work best when users know exactly how to report a suspicious message.
Important reporting note
Do not forward a suspicious attachment to multiple colleagues. Use the approved reporting route or contact the IT support team so the message can be reviewed without increasing exposure.