Nirmion
HelpLog in Find a tool

Security & Privacy · THE NO-PANIC PLAN

Respond to a suspected phishing incident

Use this guide after receiving a suspicious email, text, or message, or after someone has interacted with it. Stop further interaction, report through a trusted channel, and choose the response branch based on what was exposed. If a work account, managed device, payment, or business email compromise may be involved, notify the responsible security or finance team immediately and follow its incident plan. This guide does not investigate messages or replace provider recovery instructions. Never paste the message, live link, password, code, customer data, or private incident details into a public tool.

MISSION Give an individual or small organization a safe, ordered response when a suspicious message may have exposed credentials, personal information, money, or a device.

Open the official incident-reporting channel

THE REAL-WORLD BIT

What happens outside this browser tab?

Stop interacting with the message and preserve it through an approved route; identify whether anyone clicked, opened, replied, entered credentials, shared personal or financial information, or paid; contain the affected account or device with the service owner; promptly contact the relevant bank or payment provider if money moved; report through the employer/platform and applicable official consumer or law-enforcement channels; then record actions, owners, and unresolved risks without sharing sensitive evidence broadly.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Stop contact and establish what happened

    Do not click another link, open an attachment, reply, call a number in the message, or use its unsubscribe link. Ask the recipient what actions occurred and when: message received, link opened, file opened, information entered, approval granted, payment sent, or nothing beyond viewing. Treat the sender name and visible destination as unverified. If this affects a managed work account or device, notify the organization's established security or IT contact now and follow its incident process. Preserve the original message only through a mail-client reporting control or evidence system approved by that organization; do not forward it broadly or to a personal mailbox.

  2. 02

    Choose the response branch for exposed information

    If a password was entered, use a known-good device and a saved bookmark or official app to reach the real service. Change that account's password promptly, change any reused password on other services, and enable multifactor authentication if offered. If the person cannot sign in, use the provider's official account-recovery instructions. If a one-time code, session approval, or recovery code was shared, tell the provider or organizational security team that specifically; a password change alone may not revoke active sessions. If personal identity, tax, or financial information was exposed, use the relevant official issuer or identity-theft response service. Never reply to the suspicious sender to recover an account.

  3. 03

    Contain a potentially affected device or work account

    If an attachment was opened or software may have run, stop using the device for sensitive sign-ins and contact the organization's IT/security team for managed equipment; do not wipe or investigate it yourself because responders may need evidence. For a personal device, use its built-in security software and the vendor's official support instructions, and get trusted technical help if the device behaves unexpectedly. If a work account was involved, ask the administrator to review sign-in activity, revoke sessions or tokens where appropriate, and secure linked accounts. Record what was done and by whom. A scan, password change, or deletion of the message does not prove that an account or device is clean.

  4. 04

    Act immediately if money or payment details were involved

    If a bank transfer, card payment, wire, payment-app transfer, gift-card value, or business payment may have gone to a scammer, contact the bank, card issuer, payment app, or transfer provider immediately using the number on the card or its official app/site. Ask whether the payment can be stopped, recalled, disputed, or secured, and follow its evidence instructions. For a suspected business email compromise or changed supplier payment details, alert finance and the responsible security owner through a separate known channel; do not rely on reply-to-email confirmation. Preserve transaction references privately. Recovery is not guaranteed, and acting quickly does not replace the provider's formal claim or reporting process.

  5. 05

    Report, track actions, and close only after follow-up

    For an organization's message, use its approved report-phishing control or incident channel and follow internal evidence and retention rules. For a U.S. consumer phishing email or text, the FTC currently directs users to forward email to reportphishing@apwg.org, text SPAM to 7726, and report at ReportFraud.ftc.gov; use the official FTC page to confirm the route. Where a business payment compromise occurred, contact the financial institution promptly and consider an IC3 complaint at the FBI's official site. Other countries and employers may have different channels. Track the case reference, time, action, owner, provider response, and next check in the approved system. The linked Security Incident Timeline Builder can organize a sanitized chronology; enter only synthetic or non-sensitive descriptions, never message contents, active links, credentials, account identifiers, or customer data. Keep the case open until account/device and payment owners confirm their follow-up and document unresolved risks.

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-05