SECURITY SUPPORT GUIDE

Phishing Email Reported

Security troubleshooting guide

Knowledge Base / Security / Phishing Email Reported

Problem

A user reports a suspicious email that appears to be fake, urgent, or designed to steal credentials or money.

Phishing emails are often designed to look legitimate and encourage users to click, reply, or enter information. The best defense is to report, preserve evidence, and isolate risk quickly.

Symptoms to check

  • Email creates urgency, asks for login details, or claims an account is at risk.
  • Links appear similar to official services but use a suspicious domain or shortened URL.
  • Several users report the same sender or subject line.

Possible causes

  • Fake sender address or spoofed domain.
  • Credential harvesting or fake invoice or payment request.
  • Campaign targeting multiple users at once.

Resolution

  1. Do not click links or open attachments. Keep the message in the mailbox and gather the sender address, subject, time received, and any screenshot or copied text for review.
  2. Report the email through the approved security or help-desk method and include whether the user opened the message, clicked a link, or entered any information.
  3. If the user clicked a link or provided credentials, follow the security workflow to reset the password, review sign-ins, and check for suspicious mailbox activity.
  4. Check whether additional users received the same message and share the sample with the security team for broader detection and blocking.
  5. Delete the message after it has been captured for investigation, in line with company policy, and verify the user can continue working normally.

Prevention and preparation

  • Train users to report suspicious mail instead of acting on it.
  • Encourage the use of official reporting buttons and company-approved verification steps.
  • Keep an escalation path ready for broader phishing campaigns.

Related guides

Still not fixed? Escalate to the security team immediately if login credentials were entered or the email appears to be part of a wider campaign.

Submit a ticket

Last reviewed: October 2026