IT-SOP-03 · SOP · SharePoint / IT
Reporting Phishing and Suspicious Email
Owner Dana Whitfield · updated 2026-05-20
Use the Report button in Outlook. Do not forward or open attachments. If you clicked a link or entered your password, call IT immediately: password reset, session revoke, MFA check. Payment or bank-change requests by email are always verified by phone.
If you only received it
Use Report > Phishing in Outlook. Do not forward it, reply, or open attachments. Delete it after reporting.
If you clicked, opened or typed your password
Call IT now (ext. 4400). IT will:
- Reset your password and revoke all sessions.
- Check MFA methods and sign-in logs for the last 7 days.
- Check inbox rules and forwarding.
- Search for the same message across all mailboxes and remove it.
Payment and bank-detail changes
Any email asking to change vendor bank details or send an urgent wire is verified by phone using a number already on file, never one in the email. Finance does not act on email alone.