What to do if…
you receive unexpected account verification or welcome emails at your work address
Short answer
Treat it as a possible security incident. Do not click links or open attachments in the messages, and report it promptly through your employer’s official IT or security process.
Do not do these things
- Do not click verification, unsubscribe, or password-reset links in the unexpected messages.
- Do not open unexpected attachments.
- Do not reply to the messages or enter your work password on a site reached through them.
- Do not forward the messages to your personal email account or store them in a personal cloud drive.
- Do not delete the messages before reporting them. After reporting, follow your employer’s instructions on whether to keep or delete them.
- Do not try repeated password resets or trial-and-error logins for accounts you do not recognize.
What to do now
-
Report the messages through your employer’s official channel.
Use a known helpdesk route, security hotline, or report-phishing workflow. Say that your work email address is receiving account-creation, verification, or password-reset messages for services you do not recognize. -
Use your employer’s approved reporting method.
Use the report-phishing button or other official process your employer provides. Do not click links or open attachments in the messages. Keep the messages until reporting is complete, then follow your employer’s instructions on whether to retain or delete them. -
Tell IT or security about any other signs you have noticed.
Mention unfamiliar sign-in alerts, messages you did not send, changed inbox rules or filters, unexpected forwarding, unfamiliar delegated access, or unknown connected apps. Ask whether they need to review those items in your work account. -
Secure the work account through your employer’s process.
Follow official instructions if you are asked to change your password, sign out of other sessions, review devices, or confirm that multi-factor authentication is enabled and working. Do not bypass your employer’s process or change settings in a way that makes the investigation harder to audit. -
Make a brief list of the unknown services if it is easy to do.
After reporting the issue, list the service names and message times for the unexpected account emails you can readily identify. Do not open links or spend a long time trying to catalog every message. -
Escalate internally if impersonation or company-data exposure may be involved.
Tell your manager and the appropriate security, privacy, or compliance contact if coworkers or clients received messages that appeared to come from you, or if a message suggests company information may have been entered into an unknown service. -
Use the official identity-theft route if personal identity misuse may also be involved.
If the messages suggest that your Social Security number, bank-account details, credit-card details, or other sensitive personal information may have been used, go directly to IdentityTheft.gov for a guided recovery plan. You may also consider a credit freeze or fraud alert using official FTC guidance.
What can wait
- You do not need to contact every website or try to close unknown accounts one by one right now.
- You do not need to work out the cause before reporting the messages.
- You do not need to notify clients or customers yourself unless your employer’s security team asks you to do so.
- You do not need to make broader decisions about identity-protection steps unless personal information may also have been misused.
Important reassurance
There are several possible explanations, including a mistyped address, automated misuse, phishing, or account compromise. You do not need to determine the cause alone. Your immediate job is to avoid risky clicks, keep the messages available until reporting is complete, and involve your employer’s security team.
Scope note
These are first steps only. Later decisions about specific accounts, communications, workplace procedures, identity-protection measures, or legal steps may need help from your employer’s security team or another appropriate specialist.
Important note
This is general information, not legal, financial, cybersecurity, or other professional advice. Follow your employer’s policies and incident-response instructions. Use official recovery resources if personal identity misuse may also be involved.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.