Stop interacting with the message and contact your IT or security team through a known channel. Explain whether you opened a link, entered credentials, approved an authentication prompt, or downloaded a file.
Do not use the suspicious message to reach a password-reset page or contact number. Your support team can help secure the account and determine whether the device, sessions, mailbox settings, or other systems need investigation.
Preserve the message and relevant details according to your organization’s process. The response should follow what actually happened and the information that may have been exposed.
Further reading: CISA: recognizing and reporting phishing ↗Need help applying this?
We can review your environment and help define a practical next step.
Start a conversation