How to report a phishing email or security concern
What to do (and what not to do) if something looks wrong
Report early. You won't be in trouble. The sooner we know, the smaller the problem. Most incidents we deal with could have been contained in minutes if they'd been reported straight away.
Signs an email might be phishing
- Urgency or pressure: "Your account will be closed today", "Pay this invoice now".
- A sender address that doesn't quite match, such as
micros0ft-support.co. - Requests for passwords, MFA codes, gift cards or changes to bank details.
- Unexpected attachments or "shared document" links.
- Links whose real address, shown when you hover over them, goes somewhere unrelated.
If you receive a suspicious email
- Don't click links, open attachments or reply.
- Use your email's Report phishing button if you have one, or forward the email to support as an attachment.
- Delete it.
If you've already clicked or entered details
- Don't panic, and don't try to fix it yourself.
- If you entered a password, change it now from a different, trusted device.
- Disconnect from Wi-Fi or unplug the network cable if you opened an attachment.
- Raise an urgent support ticket or phone us. Tell us what you clicked, when, and what you entered.
If your antivirus shows a warning
Report it even if it says the threat was removed. We check whether anything else was affected.
Bank detail change requests: always confirm by phone using a number you already have, never one from the email. Invoice fraud is one of the most expensive scams affecting UK businesses.
Personal data involved?
If customer or staff personal data could have been exposed, tell us and your Data Protection Officer straight away. Under UK GDPR, some breaches have to be reported to the ICO within 72 hours.