PanicStation.org
us Work & employment crises

What to do if…
you are asked to share your work login details or approve an unexpected multi-factor prompt

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not share your login details, verification code, or recovery information. Do not approve a multi-factor prompt you did not initiate; report the request promptly through a trusted company IT or security channel.

Do not do these things

  • Do not share your password, verification code, backup code, recovery information, or multi-factor approval.
  • Do not approve an unexpected multi-factor prompt to make it disappear.
  • Do not click links, open attachments, or install software sent by the person making the request.
  • Do not use contact details, callback numbers, or ticket links inside a suspicious message to verify the request.
  • Do not delete the message or wipe a device unless your company IT or security team tells you to.
  • Do not blame yourself if you already responded. Report what happened promptly.

What to do now

  1. Stop the interaction. If an unexpected multi-factor prompt is still visible and your sign-in system offers a deny or reject option, use that option. Otherwise, do not approve it.

  2. Report the request through a trusted company channel. Use a help desk number, internal portal, security-reporting process, or corporate directory entry that you already know is genuine. Do not use contact information from the suspicious message.

  3. Say clearly whether you shared or approved anything. Tell IT or security what was requested, when it happened, how you were contacted, and whether you entered a password, shared a code, clicked a link, opened an attachment, installed software, or approved a prompt.

  4. Preserve what is readily available. Keep the message and take a screenshot of the prompt or request if you can do so without clicking links, opening attachments, or continuing the conversation.

  5. Follow your company’s account instructions. If IT or security tells you to change your password, use your normal company sign-in page or app. If you think a device may be affected, stop using it for work and ask IT or security what to do next.

What can wait

  • You do not need to prove that the request was malicious before reporting it.
  • You do not need to contact everyone yourself.
  • You do not need to decide whether this becomes an HR, legal, or compliance matter.
  • You do not need to change every password at once. Follow the account-containment steps your company gives you.
  • Optional external reports can wait until the immediate workplace report is complete. A suspected phishing email may be forwarded to reportphishing@apwg.org, a suspicious text message may be forwarded to 7726 (SPAM), and a scam may be reported to the FTC.
  • An IC3 report can also wait until the immediate workplace report is complete. It may be appropriate for suspected cyber-enabled fraud or cybercrime, including cases involving account misuse or financial loss.

Important reassurance

Reporting an unexpected login request or multi-factor prompt is appropriate, even when you are not certain what happened. A prompt you deny and report may be a false alarm, and reporting it is still the right first step.

Scope note

These are first steps only. Later decisions may need help from your organization’s IT, security, HR, compliance, or other specialist teams.

Important note

This guide is general information, not legal, medical, financial, therapeutic, or professional advice. Follow your employer’s policies and the instructions of your organization’s IT or security team.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us