What to do if…
you receive unexpected account verification or welcome emails at your work address
Short answer
Treat this as a possible workplace security incident: do not click links in the messages, keep the emails, and report it to your organisation’s IT or security team through your normal internal route.
Do not do these things
- Do not click “verify”, “unsubscribe”, “reset password”, attachment links, or sign-in buttons in the unexpected messages.
- Do not forward the emails to your personal account or upload them to personal storage.
- Do not delete the emails, empty deleted items, or tidy the mailbox until IT or security has told you what to keep.
- Do not try to take over unknown accounts by repeatedly resetting passwords or guessing what happened.
- Do not send a warning to clients, customers, or a large internal group unless your organisation tells you to.
What to do now
-
Report it through your workplace’s official process now.
Use your IT helpdesk, security channel, or approved “report phishing” workflow. Say: “I’m receiving sign-up, verification, or password reset emails for services I do not recognise using my work email address.” -
Preserve the evidence without clicking.
Keep the messages in your mailbox. Note the subject lines, the time received, the sender shown, and any service names. If your organisation asks you to report suspicious email in a specific way, such as using a built-in reporting button or forwarding as an attachment, use that method. -
Use the UK suspicious-email fallback only if it fits your workplace process.
If you cannot quickly find an internal reporting route, and your workplace allows external reporting, suspicious emails can be forwarded to [email protected]. This reports suspicious messages to the NCSC; it does not replace your workplace incident process or restore access to any account. -
Ask IT or security to check for mailbox misuse.
Ask them to check for unusual sign-ins, new inbox rules, unexpected auto-forwarding, unfamiliar delegated access or shared mailbox permissions, unusual sent items, and unknown connected apps. -
Secure your work account using your organisation’s approved method.
If IT or security tells you to, reset your password to a new unique one, sign out of other sessions or devices, and confirm multi-factor authentication is enabled and working. Follow your employer’s exact steps, especially if you use Single Sign-On. -
Make a short list of the unknown account emails.
Search your mailbox for words such as “welcome”, “verify”, “confirm your email”, “subscription”, and “password reset”. List the service name, date and time, and what the email claims. Give that list to IT or security. -
Escalate internally if there is any sign of data exposure or impersonation.
If an email suggests company or personal data was entered, or if colleagues report messages from you that you did not send, tell your manager and your organisation’s data protection, privacy, or compliance contact if you have one. Ask them to assess whether this may be a personal data breach and whether any notification is needed.
What can wait
- You do not need to contact every website immediately or spend hours trying to close accounts today.
- You do not need to decide whether this is “identity theft” right now; first confirm whether your work mailbox or account was accessed.
- You do not need to warn clients, customers, or your whole team unless IT or security confirms there is a real risk of impersonation or data access.
- External fraud or cyber-crime reporting can usually wait until your employer has confirmed what happened, unless you have lost money, been hacked outside work, or been told to report now.
Important reassurance
Unexpected sign-up or verification emails can happen because of typos, automated abuse, or someone trying to misuse an email address. The cautious first steps are simple: do not click, report it quickly, keep the evidence, and let your organisation check whether the mailbox itself was accessed.
Scope note
These are first steps for the first hours or day. Later decisions, such as closing specific accounts, contacting providers, wider communications, HR steps, or formal reporting, may need specialist help from your employer’s IT, security, privacy, legal, or HR teams.
Important note
This is general information, not legal, medical, financial, therapeutic, cyber-security, or other professional advice. Follow your employer’s policies and incident response instructions. If money has been lost or you believe cyber crime or fraud has happened outside your workplace systems, reporting routes vary within the UK, so use official UK guidance to choose the right route.
Additional Resources
- National Cyber Security Centre — Report a scam email
- GOV.UK — Avoid and report internet scams and phishing
- National Cyber Security Centre — Recovering a hacked account
- Information Commissioner's Office — Personal data breaches: a guide
- National Cyber Security Centre — Small organisations guide to cyber security
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.