What to do if…
you get repeated password reset emails for work accounts you did not request
Short answer
Do not click links or open attachments in the reset emails. Contact your company IT or security team through a trusted route now so they can verify the reset activity and secure your account.
Do not do these things
- Do not click reset links or open attachments in the emails.
- Do not reply to the emails.
- Do not use phone numbers, chat links, QR codes, or “helpdesk” contacts shown in the email.
- Do not approve unexpected MFA prompts, and do not share verification codes with anyone.
- Do not forward potentially sensitive work emails to a personal or external address unless your company policy explicitly allows it.
- Do not delete the emails before reporting them, unless your IT or security team tells you to.
What to do now
-
Stop using the reset emails.
Treat repeated reset emails as a possible sign that someone is testing access to your work account or trying to push you toward a fake login page. -
Report it to IT or security using a known-good method.
Use your normal helpdesk number, internal portal, company phishing-report button, or a company chat channel you already trust. Do not use contact details inside the reset emails. Include:- the affected account or accounts
- when the emails started and how often they arrive
- the sender address shown and subject lines
- whether you clicked anything, entered a password, opened an attachment, or approved a prompt
-
Ask IT or security to check for account access and persistence.
Ask them to review sign-in logs and password reset events; force sign-out and revoke active sessions or tokens if available; confirm MFA methods; remove unknown MFA methods; check mailbox forwarding, inbox rules, delegated access, and connected apps; and check whether other employees are seeing the same reset emails. -
Only change your password through an official company route.
Use a saved bookmark, your company intranet, or a typed official sign-in address, not a link from the reset emails. If your organization requires IT-administered resets or asks you to pause while they investigate, follow that direction. -
Check visible account settings if you can do so safely.
Without clicking anything in the reset emails, look for unfamiliar auto-forwarding, inbox rules that hide or delete messages, unknown recovery details, unfamiliar MFA methods, or connected apps with mail or account access. Report anything suspicious rather than trying to fix it alone. -
Escalate immediately if you interacted with the email.
If you clicked a link, entered your password, opened an attachment, shared a code, or approved an MFA prompt, tell IT or security plainly. Follow their steps for password reset, MFA reset, device checks, and session revocation. -
Warn the right person if your role can trigger payments or data changes.
If you handle payments, purchasing, payroll, HR changes, customer data, vendor details, or approvals, tell your manager that you have reported a possible account-security incident. Ask that urgent requests appearing to come from you are verified through a separate trusted channel today. -
Preserve evidence without spreading it.
Keep the emails and note timestamps. Let IT or security collect headers or copies through your company’s approved process.
What can wait
- You do not need to decide by yourself whether the emails are real, fake, or harmless.
- You do not need to decide external reporting now; if money was sent, payroll or vendor details were changed, or sensitive data may have been exposed, your company incident process can guide reporting to banks, insurers, regulators, or IC3.
- You do not need to overhaul your device or accounts unless IT or security finds signs that this is needed.
Important reassurance
Repeated reset emails do not automatically mean someone is inside your account. The safest move is to avoid the email links and get your IT or security team to check access, reset events, MFA methods, forwarding, and connected apps.
Scope note
These are first steps to stabilize the situation. Later decisions, including investigation, customer notification, legal duties, insurance, or law enforcement reporting, may need specialist help from your employer’s security, legal, HR, compliance, or management teams.
Important note
This is general information, not legal, medical, financial, therapeutic, cybersecurity consulting, employment, or other professional advice. Follow your organization’s IT, security, and incident-reporting instructions.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.