Detect phishing by pausing on requests involving credentials, money, sensitive data, unusual files, or changed procedure, then verifying through a trusted channel you already know. Do not use contact details supplied in the suspicious message. Report quickly through the approved process, even after a click, so responders can contain risk without blaming the reporter.
Who this is for: Employees, managers, and support teams who handle workplace email, messages, files, sign-in prompts, and payment requests.
- Judge the requested action and context, not only spelling, logos, or whether a message looks professional.
- Verify identity and process through a separate trusted channel before sharing data, approving payment, or signing in.
- Report suspected messages and accidental interaction immediately, then follow the response team's instructions.
Focus on action and context
Warning signs include unexpected urgency, secrecy, changed payment details, unusual document sharing, requests to bypass normal approval, and sign-in prompts that arrive without an action you initiated. A familiar display name or polished writing does not establish identity. Attackers can imitate ordinary business language and continue real conversation threads.
Compare the request with normal process. Ask whether this person usually makes the request, whether the channel is expected, whether the timing makes sense, and whether the action would expose credentials, private data, money, or administrative access. Treat an unusual process change as a reason to verify, not proof that a colleague is malicious.
Inspect safely without interacting
Check the full sender address and message context using the mail client's normal details view. Read link destinations through supported preview features without opening them, but remember that a plausible address can still be deceptive. Do not open unexpected attachments or enable active content merely to determine whether a message is suspicious.
Avoid replying to the message for verification. Contact the person through a known directory entry, saved number, established internal chat, or official service portal. For financial or account changes, follow the organization's independent approval process. Employees should not investigate infrastructure, trace senders, or test links on personal or company devices.
Report through a prepared channel
Use the organization's report button, security mailbox, help desk, or emergency contact. Include the original message through the approved method so headers and attachments remain available to responders. Add what action you took, whether credentials were entered, whether a file opened, and the time. Do not forward suspicious content broadly.
A no-blame reporting culture improves response time. Managers should thank employees for reporting uncertainty and avoid demanding certainty before escalation. Security teams can then assess related recipients, block known indicators, protect accounts, preserve evidence, and communicate safe next steps within their authorized systems.
Respond after interaction
If you entered credentials, approved a prompt, sent sensitive data, or opened an unexpected file, report immediately and state exactly what occurred. Follow responder instructions for account reset, session revocation, device isolation, payment hold, or evidence preservation. Do not erase messages or independently install cleanup software because that can remove useful evidence or add risk.
Organizations should practice realistic reporting scenarios without collecting real passwords or shaming participants. Measure reporting speed and process clarity rather than click rate alone. Review contacts, payment procedures, identity protections, backup communications, and current CISA guidance quarterly, and update training after real incidents or major channel changes.
Handle a changed bank-details request
An employee receives a polished message in an existing vendor thread asking that the next invoice use a new bank account before today's deadline.
- Pause the payment change and do not reply, open linked forms, or call a number introduced in the message.
- Compare the request with the established vendor-change and dual-approval procedure.
- Contact the vendor through the saved account record and notify the internal finance owner through a known channel.
- Report the original message with its timing and thread context through the approved security route.
- Follow responder instructions, preserve evidence, and document the verified outcome without accusing an individual.
Pause, verify, report card
Use this short playbook for any unusual workplace request.
- Pause: Do not sign in, open files, approve prompts, send data, or change payment details.
- Assess: Identify the requested action, consequence, urgency, process change, and sensitive information involved.
- Verify: Use an established directory, saved contact, official portal, or known internal channel.
- Report: Send the original through the approved route and state any interaction plus its time.
- Follow: Preserve evidence, obey containment guidance, use recovery procedures, and escalate urgent financial or account risk.
Common mistakes
- Trusting a message because its grammar, logo, and display name look professional.
- Verifying through the phone number or reply address supplied in the suspicious request.
- Hiding an accidental click or credential entry out of embarrassment and delaying containment.
Try one
A coworker sends an unexpected shared-document link and asks you to sign in before a meeting. What should you do?
A strong answer pauses and avoids the link, checks whether the request fits current work, and contacts the coworker through an established channel. It reports the original message if identity or context remains uncertain. If sign-in already occurred, it immediately tells responders what was entered and follows session, password, device, and evidence guidance rather than investigating or deleting the message alone.
Sources
- CISA phishing guidanceCISA guidance for reducing successful phishing and responding to reports.
- OWASP Multifactor Authentication Cheat SheetOWASP design and recovery guidance for multifactor authentication.