PanicStation.org
uk Work & employment crises

What to do if…
you notice emails or messages being sent from your work account that you did not send

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat this as a suspected account compromise. Stop using the account for normal work and contact your IT or security helpdesk immediately using a trusted route, so they can secure the account, force sign-out, and check for suspicious sign-ins, forwarding, and rules.

Do not do these things

  • Do not delete sent emails, alerts, sent items, forwarding rules, inbox rules, or other evidence; leave technical logs for IT.
  • Do not keep using the account to “see what happens”.
  • Do not reply to the suspicious messages from the affected account.
  • Do not click links or open attachments connected to the incident, even if they look internal.
  • Do not reset passwords from a device you think may be compromised unless IT tells you to.
  • Do not send a mass apology or explanation unless your organisation asks you to; it may spread malicious links further or conflict with incident handling.
  • Do not assume this is your fault or try to hide it; quick reporting helps limit harm.

What to do now

  1. Pause and switch channel. Stop sending emails or work messages from the affected account. Use a different trusted route, such as a phone call, known helpdesk number, in-person contact, or an approved backup channel.

  2. Report it to IT or security immediately. Say: “I’m seeing emails or messages sent from my work account that I did not send. Please treat this as suspected account compromise.” Ask them to check or arrange:

    • restricting or securing your account sign-in;
    • forcing sign-out of active sessions;
    • resetting your password safely;
    • confirming multi-factor authentication is enabled and working;
    • recent sign-ins, unusual locations, and failed sign-in attempts;
    • mailbox forwarding, inbox rules, auto-replies, delegate access, and connected apps;
    • whether Teams, Slack, Microsoft 365, Google Workspace, or other linked work tools were also used.
  3. Preserve a minimal internal record. Write down the timestamps, recipients, subject lines, message platform, and any security alerts you saw. Take screenshots only if your organisation allows it, and share them only through an approved internal incident channel.

  4. Do not remove suspicious settings yourself unless IT asks. If IT says it is safe for you to look, check for unexpected forwarding, new inbox rules, auto-replies, unknown delegate access, and unfamiliar connected apps. Tell IT what you find before deleting or changing anything.

  5. Warn the right internal people quickly. Tell your manager, briefly, that your work account may have sent unauthorised messages. With IT or security, identify who received the messages so the organisation can warn them not to click links, open attachments, or follow changed payment or login instructions.

  6. Escalate payment or invoice risk now. If any message mentioned invoices, bank details, gift cards, payment approvals, supplier changes, payroll, or urgent transfers, contact your finance or payments team through a trusted route so they can pause or verify activity.

  7. Flag possible personal-data exposure. If the account may contain or have sent personal, client, patient, pupil, employee, HR, financial, or confidential information, tell IT, your manager, or your data-protection lead. Your organisation may need to assess whether any regulatory or customer notifications are required.

  8. Secure related work access with IT guidance. If you reused the same password on other work systems, tell IT and update those passwords using a safe device or process. Keep multi-factor authentication on.

  9. Report the suspected phishing source safely. Use your organisation’s phishing reporting process first. If policy allows and it does not disclose confidential work information, suspicious emails can also be forwarded to the UK suspicious email reporting service.

What can wait

  • You do not need to work out exactly how it happened right now.
  • You do not need to decide whether this becomes an HR, legal, or disciplinary matter right now.
  • You do not need to write a detailed explanation for everyone who received a message unless your organisation asks you to.
  • You do not need to fix mailbox settings, investigate logs, or contact external recipients on your own.

Important reassurance

Seeing messages sent from your account can feel alarming and embarrassing, but this is a known attack pattern. Reporting quickly, stopping normal use of the account, and preserving evidence are the actions most likely to reduce harm.

Scope note

These are first steps only. After the account is contained, your organisation may need specialist IT security, HR, data-protection, legal, finance, or communications support.

Important note

This is general information, not legal, financial, cybersecurity, employment, or professional advice. Follow your employer’s IT, security, data-protection, and incident-reporting policies, and use approved internal channels.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us