PanicStation.org
uk Work & employment crises

What to do if…
you are asked to share your work login details or approve an unexpected multi-factor prompt

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Do not share your login details, one-time code, recovery code, or password, and do not approve a sign-in prompt you did not start. Treat it as a possible account-takeover attempt and contact your organisation’s IT, service desk, or security team using a trusted route.

Do not do these things

  • Do not tell anyone your password, temporary password, one-time code, or backup or recovery codes, even if they claim to be IT, a manager, or a supplier.
  • Do not approve an MFA, verify sign-in, or number-matching request you did not start, even to make repeated prompts stop.
  • Do not trust a request just because it uses familiar branding such as Microsoft or Google.
  • Do not continue in the same channel that contacted you, such as replying to the email, using their helpdesk link, or calling back their number.
  • Do not try to fix it quietly if you already shared details or approved a prompt.
  • Do not forward suspicious work emails outside your organisation if your employer’s policy says not to.

What to do now

  1. Stop the request.

    • If it is an MFA push: choose Deny or Reject if that option is available, or ignore it.
    • If a person is asking: say “I can’t share login details” and end the call or chat.
  2. Report it using a trusted internal route. Use your company intranet, known service desk number, security mailbox, or reporting button. Do not use contact details from the suspicious message. Tell them:

    • what you were asked to do;
    • when it happened;
    • how you were contacted;
    • whether you clicked anything, typed anything, shared anything, or approved anything.
  3. If you already shared details or approved a prompt, say this clearly. Ask IT or security to treat it as urgent. They may need to reset your password, sign out active sessions, revoke access tokens, lock the account, or review account activity. You do not need to know which of these applies.

  4. Secure the account only through your normal work route or as IT/security instructs. If your organisation allows you to act before they respond, use your usual company sign-in page or app to change your password. Check only obvious account changes, such as unexpected recovery details, unfamiliar devices, or new email forwarding rules.

  5. Preserve the evidence without spreading it. Take screenshots of the message or prompt if you can, including the sender, address or number, time, and request text. Keep the email, chat, caller details, or notification details for IT/security.

  6. If it was a phone call, verify internally before speaking further. Hang up and call your service desk using a number from your intranet, staff directory, badge, or other route you already trust. Do not use a number the caller gave you.

  7. If it was a suspicious email or text and your employer permits external reporting, report it safely.

    • Suspicious emails can be forwarded to [email protected].
    • Suspicious texts can be forwarded to 7726, which is free in the UK. Only do this if it fits your employer’s policy and does not expose restricted work information.
  8. Escalate internally if there are signs of wider impact. Tell IT/security if colleagues received the same request, mail was sent from your account, payroll or bank-change emails appeared, files changed unexpectedly, or more MFA prompts keep arriving.

What can wait

  • You do not need to work out who did it right now.
  • You do not need to prove it was malicious before reporting.
  • You do not need to warn the whole organisation yourself; IT/security can decide what message is needed.
  • You do not need to decide today whether this is an HR or disciplinary matter.
  • You do not need to change every password you have before the targeted work account is contained.

Important reassurance

These requests are designed to create pressure and confusion. Denying the prompt, ending the conversation, and reporting quickly are the right first steps, even if it later turns out to be a false alarm.

Scope note

These are first steps only to stabilise the situation and limit damage. Later decisions may need your organisation’s IT, security, HR, data-protection, or specialist professional support.

Important note

This guide is general information, not legal, financial, therapeutic, technical, or professional advice. Follow your employer’s official IT and security policies; if instructions conflict, prioritise your organisation’s incident process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us