Skip to content
Tallgrass
← SOPs & KB

IT-SOP-03 · SOP · SharePoint / IT

Reporting Phishing and Suspicious Email

Owner Dana Whitfield · updated 2026-05-20

Use the Report button in Outlook. Do not forward or open attachments. If you clicked a link or entered your password, call IT immediately: password reset, session revoke, MFA check. Payment or bank-change requests by email are always verified by phone.

If you only received it

Use Report > Phishing in Outlook. Do not forward it, reply, or open attachments. Delete it after reporting.

If you clicked, opened or typed your password

Call IT now (ext. 4400). IT will:

  1. Reset your password and revoke all sessions.
  2. Check MFA methods and sign-in logs for the last 7 days.
  3. Check inbox rules and forwarding.
  4. Search for the same message across all mailboxes and remove it.

Payment and bank-detail changes

Any email asking to change vendor bank details or send an urgent wire is verified by phone using a number already on file, never one in the email. Finance does not act on email alone.