PanicStation.org
uk Work & employment crises

What to do if…
you get repeated password reset emails for work accounts you did not request

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Do not click anything in the emails. Contact your organisation’s IT or security helpdesk now using a trusted route so they can check and protect your account.

Do not do these things

  • Do not click “reset password”, “verify”, or “unsubscribe” links in the emails.
  • Do not reply to the email or call any phone number shown in it.
  • Do not approve sign-in or MFA prompts, or read out one-time codes, unless you started that login yourself.
  • Do not forward the emails outside your organisation unless your organisation’s policy, IT team, or security team asks you to.
  • Do not leave it unreported until IT or security has checked it.

What to do now

  1. Pause and treat the emails as suspicious.
    Repeated password reset emails you did not request can mean someone is trying to reset your password, test your account, or lure you to a fake sign-in page.

  2. Report it to IT or security using a trusted route.
    Use your company intranet, known helpdesk number, normal ticketing tool, or usual security-reporting button. Do not use contact details inside the email. Tell them:

    • you are receiving repeated password reset emails you did not request
    • when it started and how often it is happening
    • which work accounts or services the emails mention, such as email, VPN, HR, payroll, finance, or a supplier portal
    • whether you clicked anything, entered a password, approved a prompt, or shared a code
  3. Ask IT or security to check the account activity.
    Ask them to review:

    • sign-in attempts and password reset events for the affected account
    • whether any sessions should be signed out and any session tokens revoked
    • suspicious mailbox changes, including forwarding, inbox rules, delegated access, or hidden deletion rules
    • unfamiliar connected apps, add-ins, or consented permissions
    • whether other staff are receiving the same kind of emails
  4. Change the password only through the official route.
    If IT or security says you should change it now, use your normal work sign-in page or password portal, not a link from the email. Use a trusted device, ideally your work device. If your organisation requires IT-led password resets or asks you to wait while they investigate, follow that process.

  5. Check visible email settings only if you can do so safely.
    If you can access your mail settings normally, look for anything you did not set up:

    • automatic forwarding to an external address
    • inbox rules that hide, move, or delete messages
    • rules affecting messages from finance, HR, suppliers, your manager, or IT
    • unfamiliar connected apps or add-ins with permission to read mail
      If you cannot see these settings, ask IT or security to check them for you.
  6. If you clicked a link or entered details, say that clearly.
    Tell IT or security: “I clicked the link,” “I entered my password,” “I approved a prompt,” or “I shared a code.” They may need to reset your password, sign out sessions, reset MFA, check your device, or verify that no mailbox rules were added.

  7. Protect payment, payroll, HR, and supplier processes today.
    If your role involves payments, payroll, HR changes, contracts, or supplier messages, tell your manager that your account may be under attack and IT or security is checking it. Ask them to verify any urgent request that appears to come from you by a separate trusted route.

  8. Keep the emails available for IT or security.
    Do not delete them yet. Your organisation may need the message headers or security logs. If your organisation’s policy allows it, IT or security may ask you to forward suspicious emails to report@phishing.gov.uk or may report them for you.

What can wait

  • You do not need to work out who is doing it right now.
  • You do not need to report externally unless there is confirmed fraud, money loss, data loss, or your organisation’s IT or security process tells you to.
  • If external fraud reporting is needed, Report Fraud is the usual route for England, Wales and Northern Ireland. In Scotland, Police Scotland says fraud and financial crime should be reported via 101.
  • You do not need to redesign all your security today. Focus on the affected work accounts and follow your organisation’s incident process.

Important reassurance

Repeated reset emails do not automatically mean someone is already inside your account. They are still worth acting on quickly, because early reporting gives IT or security a better chance to check logs, block misuse, and prevent knock-on harm.

Scope note

These are first steps only. Later decisions about investigation, reporting, data protection, employment process, or customer and supplier communications may need your organisation’s security, legal, HR, data protection, or specialist support.

Important note

This is general information, not legal, technical, cyber-security, employment, financial, or professional advice. Follow your organisation’s IT, security, and incident-response instructions.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us