PanicStation.org
us Work & employment crises

What to do if…
work emails, calendar entries, or records are disappearing and you suspect interference

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat this as a possible account or records incident without assuming who caused it. Stop making nonessential changes, note specific examples, and report the problem promptly through your employer’s official IT or security channel.

Do not do these things

  • Do not accuse or confront a coworker, manager, or administrator before the facts have been checked.
  • Avoid deleting, restoring, renaming, or reorganizing affected items unless authorized support staff direct you to do so.
  • Do not forward company, client, employee, or confidential information to a personal account or device.
  • Do not access another person’s account, bypass permissions, or investigate through unauthorized methods.
  • Do not install unapproved recovery, monitoring, or security software on a work device.
  • Avoid sending angry messages, resigning, or making another irreversible employment decision in the moment.
  • Do not keep your only incident note inside the system where records are disappearing.

What to do now

  1. Make a brief factual incident note using a method allowed by workplace policy. Record when you noticed the problem, what appears missing or changed, approximate dates, subject lines or event names, and who normally had access. Do not copy confidential contents into personal notes.

  2. Check common explanations using only approved features. Search all folders and date ranges, including archived and deleted-item folders, and check filters, calendar views, time zones, shared-calendar ownership, permissions, and any version history you are authorized to view. Avoid changing settings while checking.

  3. Contact the official IT help desk, cybersecurity team, or system administrator through a trusted workplace route. State that work emails, calendar entries, or records appear to be missing or altered, provide a few specific examples, and ask for a ticket or reference number.

  4. Ask whether relevant sign-in records, audit logs, forwarding rules, delegated access, calendar permissions, recoverable items, and backups can be reviewed and preserved. Keep the request neutral and focused on observable facts rather than a suspected person.

  5. Follow your employer’s account-security process. When directed or permitted, reset your password through the official system, enable multi-factor authentication, sign out unfamiliar sessions, and report forwarding rules, recovery details, or delegated access you do not recognize.

  6. Notify an appropriate internal contact in writing, such as your manager, HR, compliance team, records officer, privacy team, or union representative. State what appears missing, when you reported it to IT, and the ticket number. Ask for confirmation that your report was received.

  7. Tell the receiving team if the records relate to pay, hours, leave, workplace safety, discrimination, harassment, collective workplace concerns, a prior complaint, an investigation, or an instruction to preserve records. This may affect where the concern should be routed.

  8. Keep a simple chronology of new incidents, account alerts, ticket numbers, and responses. Store it only in a location permitted by workplace policy, and do not remove confidential or proprietary material from approved systems.

  9. If a personal account or personal information may also be affected, use the provider’s official recovery process from a device you trust. Check recovery details, active sessions, forwarding rules, and multi-factor authentication.

What can wait

You do not need to identify a culprit, decide whether the cause was malicious, reconstruct every missing item, confront anyone, make a legal claim, or leave your job now. First create a factual record, secure access through approved channels, and allow appropriate technical staff to examine the system.

Important reassurance

Missing items do not by themselves prove intentional interference. Synchronization problems, retention settings, changed permissions, migrations, administrative actions, and unauthorized access may produce similar signs. A calm, specific report gives the appropriate teams a better chance of working out what happened.

Scope note

This guide covers immediate first steps only. Later decisions may require help from an IT security specialist, HR or compliance contact, union representative, relevant government agency, or employment lawyer, depending on what the records concern and what is found.

Important note

This is general information, not legal, cybersecurity, employment, or records-management advice. Employer policies, contracts, collective bargaining agreements, public-sector requirements, and state law may affect what you may copy, where you may store information, and which reporting route applies.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us