PanicStation.org
uk Work & employment crises

What to do if…
work emails, calendar entries, or records are disappearing and you suspect interference

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Use an unaffected device and a trusted contact route to tell your organisation’s IT or security team now. Ask whether relevant logs and recoverable records can be preserved before non-essential changes are made, and write down exactly what is missing.

Do not do these things

  • Do not accuse or confront anyone while the cause is unknown.
  • Do not use the affected account to contact someone you suspect may be involved.
  • Do not delete, restore, move, rename, or edit affected items unless IT instructs you to.
  • Do not change mailbox rules, permissions, forwarding settings, or connected applications before IT has assessed them, unless urgent account-recovery instructions require it.
  • Do not forward work material to personal email, private cloud storage, messaging apps, or unauthorised devices.
  • Do not click links in unexpected security alerts. Reach IT through a telephone number, portal, or address you already trust.
  • Do not access another person’s account or attempt your own covert investigation.
  • Do not resign, post publicly, or send an angry message while the immediate facts are still being established.

What to do now

  1. Use a separate, trusted contact route. Call IT or security, use an approved support portal, or speak to them in person. If items are still disappearing or the problem affects payments, safety, confidential information, access controls, or an urgent deadline, say that immediately.

  2. Describe the problem factually. Give examples of missing or altered emails, calendar entries, or records. Include their subjects or names, approximate dates, where they should appear, when you last saw them, and when you first noticed the problem.

  3. Ask for technical information to be preserved. Ask whether IT can retain relevant sign-in, deletion, forwarding, mailbox-rule, permission, delegate, calendar-change, audit, backup, and recovery information before routine account changes are made. Request an incident or ticket number.

  4. Secure the account with IT’s guidance. Follow instructions about changing the password, signing out other sessions, reviewing multi-factor authentication, removing unfamiliar forwarding rules or applications, and checking the device. If no support team is available and the account is being actively misused, use the service provider’s official account-recovery route from a device you believe is safe.

  5. Create a simple timeline. Record what disappeared or changed, the date and approximate time, who was involved in the original item, any unusual alerts, and each person or team you notified. Take screenshots only if workplace policy permits it.

  6. Keep the notes somewhere approved. Use an unaffected authorised system, the organisation’s incident-reporting process, or a paper notebook. Record only what is necessary, particularly where the material contains personal, client, financial, health, or commercially sensitive information.

  7. Notify an appropriate workplace contact. Tell your manager or HR that records appear to be missing or changing and that IT has been contacted. If that route may be compromised, use another manager, a senior HR contact, the data protection or security lead, an internal reporting channel, or a trade union representative.

  8. Flag work that may now be unreliable. Identify any decision, payment, meeting, instruction, deadline, safety check, or client commitment that depended on the missing material. Ask the responsible person to verify it through another approved source before anyone relies on it.

  9. Keep proof of your report. Note the ticket number, date, time, contact method, person contacted, and the main facts reported. If the affected account is unreliable, ask for acknowledgement through another approved channel.

  10. Get independent employment advice if needed. Acas can provide workplace information in England, Scotland, and Wales. In Northern Ireland, use the Labour Relations Agency or official nidirect guidance. A trade union may also help you decide how to raise the concern without making unsupported allegations.

What can wait

You do not need to identify who caused the problem, prove a motive, reconstruct every missing item, or decide whether the cause was deliberate before reporting it.

A formal grievance, subject access request, data protection complaint, whistleblowing disclosure, external cyber report, or police report can usually wait until the immediate account and record information has been protected and you have taken appropriate advice. Escalate sooner where there is immediate danger, continuing serious wrongdoing, financial loss, or a risk that people will rely on unsafe or false records.

Decisions about resigning, making public statements, or pursuing a legal claim do not need to be made now.

Important reassurance

Disappearing records do not by themselves prove deliberate interference. Synchronisation faults, filters, retention or archive settings, permissions, shared-account activity, administrative changes, system errors, and unauthorised access can produce similar signs. Reporting promptly and keeping a neutral timeline gives the appropriate team a clearer starting point.

Scope note

This guide covers immediate steps to protect information, report the problem, and reduce further disruption. Later decisions may require assistance from IT security specialists, HR, a trade union, Acas, the Labour Relations Agency, a data protection professional, or an employment adviser.

Important note

This is general information, not legal, employment, data protection, cyber security, or other professional advice. Follow your organisation’s security, confidentiality, record-keeping, and reporting policies, and obtain advice based on your circumstances before disclosing work information outside the organisation.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us