Pause, check, report
A convincing message can still be fraudulent. Use this guide whenever an email, text, QR code or sign-in prompt asks you to act unexpectedly.
Pause before taking action
- Treat unexpected payment changes, password requests and urgent document invitations as a reason to stop and check.
- Do not open an unexpected attachment, scan a QR code or follow a link while you are unsure. Do not reply to ask whether the message is genuine.
- A familiar display name, logo or polished writing is not proof. A real contact account may also have been compromised.
Check through a route you already trust
- Contact the person using a number from your established records, or speak to them in person. Do not use contact details supplied in the message.
- Open the service from your saved bookmark or approved app. Check whether the same request appears there.
- Follow your usual approval process for payments and changes to supplier details, even if the request appears to come from a senior colleague.
Report it so your team can respond
- Use your organisation's reporting button or agreed IT support route. Give the time received, the sender and what made you concerned.
- Do not circulate a live suspicious message to colleagues as a warning. Let IT issue a safe alert if other people may be affected.
- Follow your organisation's process for forwarding suspicious emails to the NCSC at [email protected]. This does not replace internal incident reporting.
Already clicked or replied?
Report it promptly. A quick, accurate account helps your IT team decide what to contain and check. You do not need to diagnose the problem first.
Tell IT what actually happened
- Explain whether you only opened the message, visited a link, downloaded or opened a file, entered a password, approved a sign-in, or sent information.
- Record the approximate time, affected account and device. Keep the message available for investigation and use a trusted channel if your email may be compromised.
- If you entered a password, change it through the genuine service from a trusted device, with IT support where available. Tell IT about any other accounts using that password.
- Follow your incident response instructions. Do not install a suggested clean-up tool, wipe the device or delete potential evidence on your own.
Prepare your report
- Describe any unexpected sign-in prompts, new inbox rules, sent messages or changes you noticed.
- Tell IT if customer, staff or commercial information may have been shared. Describe the type of information without sending another unnecessary copy.
- If money or payment details are involved, tell the person responsible for finance immediately so they can contact the bank through its official route.
What to record
- Time and date noticed
- Account or device affected
- What I clicked, entered or approved
- Reported to / time / reference
The PDF includes space for your notes.
