How to Spot and Report Phishing

How to Spot and Report Phishing

Applies to: All supported users
Time required: 3-minute read — could save your company a very bad week

Why this matters to your business

Phishing is a fake email (or text) designed to trick you into clicking a bad link, opening an infected attachment, giving up your password, or sending money. Small and mid-sized businesses are favorite targets — criminals know companies like yours move real money to vendors, suppliers, and payroll every week, and they impersonate exactly those people.

You don't need to be a computer expert to stop phishing. You just need to slow down for five seconds and know what to look for.

The red flags

  • Urgency and pressure. "Do this in the next hour." "I'm in a meeting, can't talk, need this now." Rushing you is the whole trick — urgency switches off careful thinking.
  • Money or account changes you weren't expecting. A vendor "updating" their bank account for payments. An employee asking payroll to change their direct deposit. An invoice you don't recognize. These are the most expensive scams targeting businesses today.
  • The sender's address doesn't quite match. The display name might say a coworker or vendor you know, but the actual email address is off by a letter or uses a strange domain (e.g., billing@acme-supplies-inc.net instead of billing@acmesupplies.com). On a phone, tap the sender's name to see the real address.
  • Links that don't go where they claim. On a computer, hover over a link without clicking — the real destination appears in the corner of the window. If a "Microsoft" link goes somewhere that isn't a microsoft.com address, it's fake.
  • Unexpected attachments — especially invoices, "shared documents," voicemails, or anything asking you to "enable content" or sign in to open it.
  • Requests to keep it quiet or move off email. "Don't mention this to anyone yet" or "text me your personal cell" are classic impersonation moves.
  • Gift cards. No manager, owner, or executive will ever ask you to buy gift cards and send the codes. Ever. This one is always a scam.
  • QR codes in emails asking you to scan to "verify your account" or "view a document." Treat these like suspicious links.
  • Generic greetings, odd wording, or a tone that doesn't sound like the person. Trust your gut — if an email from someone you know feels "off," it probably is.

⚠️ The golden rule for money: any request to send money, pay an invoice, or change bank/payroll details gets verified by phone, using a number you already have — never a number or link from the email itself. A two-minute phone call beats a five-figure wire to a criminal.

If an email looks suspicious

  1. Don't click links, don't open attachments, don't reply.
  2. Don't forward it to coworkers to ask "is this real?" — that just spreads the bait.
  3. Report it (see below). When in doubt, report — we would much rather check ten harmless emails than miss one real attack.

How to report it

Best way: use the Report button in Outlook.

  • Outlook on your computer or in a browser: select the email, then click ReportReport phishing on the toolbar (in some views it's under the three-dot menu).
  • Outlook on your phone: open the email, tap the three-dot menu, and choose ReportReport phishing.

The Report button sends the message — with all its hidden technical details intact — to our security tools and removes it from your inbox. That's why it beats forwarding.

If you can't find the Report button, or you got a suspicious text message or phone call instead of an email, submit a ticket through this help center or email your organization's designated service desk address and describe what you received. Don't forward the suspicious email itself unless we ask.

If you already clicked — or typed in your password

Tell us immediately — submit a ticket or email your service desk address. Minutes matter, and nobody is in trouble for reporting fast. The only way to make a phishing incident worse is to keep it to yourself.

While you wait to hear from us: stay off the suspicious site, and if you entered your work password anywhere, don't use that password to log in to anything else.

One more thing: surprise sign-in prompts

If your Microsoft Authenticator app asks you to approve a sign-in you didn't start, tap Deny / "No, it's not me" and report it. That prompt means someone may already have your password and is trying to get past your MFA. Never approve a prompt just to make it stop.

Quick recap

  • Slow down. Urgency is the weapon.
  • Money and bank-change requests get verified by phone, on a known number.
  • Report with the Outlook Report phishing button — even if you're not sure.
  • Clicked something? Tell us right away. Fast reporting fixes things; silence doesn't.

Need help?

  • Support portal: use the Submit a Ticket option in this help center
  • Email: your organization's designated service desk address (provided during onboarding)
  • Hours: Monday–Friday, 9:00 a.m.–5:00 p.m. Central

    • Related Articles

    • How to Setup Microsoft Authenticator

      Applies to: All users with a company Microsoft 365 account Time required: About 5 minutes What you'll need: Your smartphone and a computer Why you're being asked to do this Multi-factor authentication (MFA) adds a second step when you sign in — a ...