Skip to Content

I Received a Suspicious / Phishing Email — What to Do

By OdooBot · Published 02/07/2026 · 3 views

I Received a Suspicious / Phishing Email — What to Do

Category: Cybersecurity · Audience: Customers & Technicians · Est. time: 5 min

Summary

Phishing emails try to trick you into clicking a link, opening an attachment, or handing over your password. When in doubt, don't click — report it. This article shows how to spot and report them safely.

🛑 Never enter your password on a page you reached from an email link, and never approve an MFA prompt you didn't start.

How to spot a phishing email

  • Urgency or threats — "Your account will be closed," "Payment overdue," "Action required now."
  • Unexpected links or attachments, especially invoices, "voicemails," or shared documents you weren't expecting.
  • Sender address doesn't match the display name (hover over it) — lookalike domains (e.g. micros0ft.com).
  • Generic greetings, spelling/grammar errors, or a request to buy gift cards / change bank details.
  • A login page that appears after clicking a link — a classic credential‑harvest trap.

What to do

  1. Don't click links, open attachments, or reply.
  2. Report it. In Outlook, use the Report → Report phishing button (or the Report Message add‑in). This alerts Microsoft and BBN's security tooling. On the web, use ⋯ → Report → Report phishing.
  3. If there's no Report button, forward it to BBN Support as an attachment (don't just forward inline) and delete it.
  4. If you already clicked or entered your password: this is urgent —
  • Change your password immediately at aka.ms/mfasetup or via BBN, from a different, trusted device.
  • Tell BBN Support right away so we can check for suspicious sign‑ins and secure the account.
  • Do not approve any MFA prompts you didn't personally start.

If you're unsure whether it's genuine

  • Verify through a separate channel — phone the sender on a known number, or check with BBN. Never use contact details *from the email itself.*

Prevention

  • Turn on MFA, keep the Report Phishing button handy, and slow down on anything urgent about money or passwords.

Was this article helpful?

Yes No

Didn't find what you were looking for?

Submit a Ticket