PanicStation.org
us Work & employment crises

What to do if…
you notice emails or messages being sent from your work account that you did not send

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat this as a possible account compromise. Stop using the account and contact your IT or security team through a trusted method so they can lock access, sign out sessions, reset credentials, and check for suspicious rules, forwarding, apps, and sign-ins.

Do not do these things

  • Do not delete sent messages, alerts, rules, or logs unless IT or security tells you to.
  • Do not keep using the compromised account to investigate or warn people.
  • Do not click links or open attachments connected to the incident.
  • Do not remove forwarding rules, inbox rules, apps, or delegates on your own unless IT or security says to.
  • Do not send a mass apology or warning unless your organization tells you what to send and from where.
  • Do not use personal email, personal cloud storage, or unapproved messaging apps to share screenshots or logs.

What to do now

  1. Stop sending from the account. Leave the suspicious messages, alerts, and settings in place so your security team can review them.

  2. Contact IT or security through a trusted route. Use a known helpdesk number, an approved internal incident channel, or an in-person contact. Do not rely on a phone number, link, or instruction inside the suspicious message.

  3. Say clearly what you noticed. Use plain facts: messages were sent from your work account that you did not send, when you noticed them, and whether they involved links, attachments, invoice changes, bank details, gift cards, or wire instructions.

  4. Ask for immediate containment. Ask IT or security to consider locking or disabling sign-in, forcing sign-out of active sessions, resetting your password, checking multi-factor authentication, and reviewing recent sign-ins.

  5. Ask them to check common hiding places. This may include mailbox forwarding, inbox rules, auto-replies, delegated access, connected apps, app passwords, and chat access logs.

  6. Capture only basic evidence if it is safe and allowed. Note timestamps, recipients, subject lines, chat names, and alert wording. Share screenshots only through your organization’s approved incident channel.

  7. Tell your manager using a trusted channel. Keep it brief: your work account may have been used without permission, and IT or security has been contacted or needs to be contacted.

  8. Escalate payment-related messages immediately. If any message mentioned invoices, bank details, gift cards, payroll, vendor payment changes, or wire instructions, contact finance, accounts payable, or your manager through a trusted route so payments can be paused or verified.

  9. Secure related work access with IT guidance. If you reused the same password on other work systems, tell IT or security so they can decide what else needs resetting or reviewing.

  10. Let the organization handle outside reporting. If this looks like business email compromise, especially if payment instructions or money movement were involved, your organization may report it to the FBI Internet Crime Complaint Center and contact financial institutions.

What can wait

  • You do not need to prove how it happened right now.
  • You do not need to decide whether it was malware, phishing, a stolen token, or a mistake.
  • You do not need to write to clients, vendors, or everyone who received a message unless your organization directs you.
  • You do not need to argue about blame or discipline in the moment.
  • You do not need to clean up the mailbox before security has looked at it.

Important reassurance

This is a known pattern of attack, and quick reporting can reduce harm. Preserving what you see and switching to a trusted contact route is more useful than trying to fix everything alone.

Scope note

These are first steps only. Later decisions about investigation, client or vendor notifications, finance recovery, employment process, legal duties, or regulatory issues may need help from your employer’s security, legal, HR, finance, or compliance teams.

Important note

This is general information, not legal, cybersecurity, financial, employment, or professional advice. Follow your organization’s security policies and incident-response instructions.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us