You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.
Have a Great Day!
Home > Self Service > How to Identify and Report a Suspicious Email
How to Identify and Report a Suspicious Email
print icon

Article ID: KB26080015

Quick answer

Pause before selecting an unexpected link, opening an attachment, approving a multifactor authentication (MFA) request, or responding to an urgent request for money or private information. Report suspicious messages through your organization's approved reporting method. Contact PCMIT immediately if you interacted with the message.

Common warning signs

  • The sender's display name looks familiar, but the complete email address is different or misspelled.
  • The message creates unusual urgency, fear, secrecy, or pressure.
  • A link or button points to an unexpected domain.
  • The message asks for a password, MFA code, payment, gift card, bank change, payroll change, or confidential file.
  • An attachment or shared-document notice was unexpected.
  • The grammar, tone, signature, or request does not match the supposed sender.
  • The message claims an account, mailbox, invoice, or payroll service will be disabled unless you act immediately.

A professional-looking logo or signature does not prove a message is genuine.

Before you interact

Do not select links, open attachments, reply, or call a number supplied only by the suspicious message.

Check the complete sender address, not only the display name.

Verify unusual requests through a known phone number, official website, or separate trusted conversation.

Never disclose a password or MFA code, and never approve an MFA request you did not initiate.

Report the message safely

  1. In Outlook, select the suspicious message without selecting a link or attachment inside it.
  2. Use your organization's approved Report phishing or Report message control when available.
  3. If the approved reporting control is unavailable, contact the PCMIT Help Desk and preserve the original message for review.
  4. Do not forward a suspicious attachment to coworkers. Forwarding can increase exposure and may remove useful technical context.
  5. Delete the message only after it has been reported or when your organization's security procedure directs you to do so.

If you already interacted

  1. Stop using the message or website. Do not enter additional information.
  2. Call PCMIT immediately at 888-910-1114.
  3. State exactly what happened: selected a link, opened an attachment, entered a password, approved MFA, supplied information, or sent money.
  4. Do not delete evidence, repeatedly reset accounts, run cleanup tools, or turn off the computer unless PCMIT or your organization's incident procedure directs you.
  5. If money or banking information may be at risk, follow your organization's finance-fraud procedure in addition to contacting PCMIT.

Expected result

The suspicious message is reported without additional interaction, and PCMIT receives enough information to evaluate account, device, and organizational risk.

⚠️ Stop and contact PCMIT immediately when

⚠️ You entered a password or MFA code, or approved an unfamiliar MFA request.

⚠️ You followed a payment, bank-account, payroll, gift-card, or confidential-data request.

⚠️ An attachment ran or the computer began behaving unexpectedly.

⚠️ Files were renamed, encrypted, deleted, or replaced by a ransom note.

⚠️ The message came from a coworker's real account, or you sent private information before recognizing the risk.

Contact the PCMIT Help Desk

Never include a password, MFA code, recovery key, or other secret in a report.

Sources


Article ID: KB26080015 | Copyright © 2010 PCM Internet Technologies Corp. All rights reserved. | PCMIT Help Desk Powered by PCMIT-AIVA AI Platform Automation | help.pcmitcorp.com
Feedback
0 out of 0 found this helpful

scroll to top icon