1. Do not use the message's links or phone numbers

Open the service from a saved bookmark or type its known address yourself. For a bank or vendor, use the number on a statement, card, or official website.

2. Verify using a second channel

If a coworker requests money, credentials, gift cards, payroll changes, or unusual access, call them using a number you already know. Do not reply to the same thread: a compromised mailbox can answer.

3. Inspect the request, not just the spelling

4. Report it

Use your mail provider's phishing-report button or send it to whoever manages IT. Reporting can remove similar messages from other inboxes. Then delete it.

5. If you interacted, act quickly

Tell IT or the service provider exactly what you clicked, entered, downloaded, or approved. From a known-clean device, change exposed passwords, revoke sessions, and review MFA and recovery settings. Contact financial institutions immediately if money or payment details are involved.

Do not hide the mistake. Fast, accurate reporting matters more than embarrassment. Many attacks can be contained if someone responds promptly.