Appearance
What to Do When a Coworker's Account Sends a Strange Email
Applies to: Microsoft 365, Outlook, New Outlook for Windows, Outlook on the web, Microsoft Teams
Article Type: Troubleshooting
Last Updated: 2026-08-08
Summary
An email from a coworker's real address is asking something odd — open a document, buy gift cards, handle an urgent payment. Their account may be in someone else's hands, and what you do as the recipient decides how far the attack gets. This article shows you how to verify without alerting the attacker, report it so IT can contain it, and warn others without spreading the message further.
Symptoms
- An email from a colleague's genuine address is out of character — wrong tone, a generic greeting, an unexpected attachment or "view this document" link.
- The message pushes urgency or secrecy: gift cards, a changed bank account for an invoice, "are you at your desk?", a quick favor that must happen right now.
- The same odd email reached several colleagues at once.
- The coworker denies sending it, or their reply to your question sounds off and keeps steering you back to the link.
Before You Start
- None required — every step works from your own mailbox with no admin rights.
- Have a way to reach the coworker that is not email: their phone number, Teams, or a walk to their desk.
Instructions
1. Stop Before You Click, Reply, or Forward
Treat the message as hostile until the sender confirms it by voice or in person — the address can be real while the person behind it is not.
- Do not click any link or open any attachment, even one that looks like a routine SharePoint or OneDrive share. A compromised account sends links that harvest your password next.
- Do not reply to ask "Is this really you?" If the account is compromised, the attacker reads and answers its email — and the answer will be yes. Your reply also tells them their message landed.
- Do not forward the email to warn colleagues. Forwarding hands each of them a live copy of the link; Step 5 shows how to warn people safely.
- Leave the message in your inbox unopened beyond the preview. You will need it intact for the report in Step 4.
2. Check Whether the Address Is Real or a Lookalike
A lookalike address means ordinary phishing, while the coworker's genuine address means an active break-in at your organization — and the response differs.
- Open the message in Outlook and click the sender's name at the top of the reading pane. A contact card opens showing the actual email address behind the display name.
- Compare that address character by character with an older email you know came from the coworker. Lookalikes swap characters (
rnform,0foro), add a word ([email protected]), or use an outside service such as Gmail with the coworker's name on it. - Weigh the request itself as well as the address. Gift cards, secrecy, and urgent payment changes are the signature of business email compromise — a scam that impersonates managers precisely because people obey managers quickly. The ask is the tell, whoever the sender is.
- If the address is a lookalike, the coworker's account is fine and this is standard phishing — report it with Report > Phishing (Step 4) and see How to Identify a Phishing Email for the full checklist.
- If the address is genuinely theirs, continue — the next three steps matter more, not less.
3. Verify with the Coworker by Voice, Not by Reply
Any typed reply — email, chat, a text message — can be answered by the attacker, so verification needs the coworker's voice or face.
- Call them on Teams or their phone, or walk to their desk. Ask one question: "Did you send me an email about [subject] at [time]?"
- If they did not send it, tell them plainly: "Your account has been compromised and is sending phishing. Change your password and sign out of all sessions now." Point them to Understanding What to Do If Your Account Is Hacked — that guide is their side of this incident. Securing the account is their job and IT's; reporting the email is yours, and it happens next.
- If they did send it, you are done — with one exception. When the request involves money, gift cards, or changed payment details, confirm it through their manager or a second person before acting, even after a yes. Business email compromise sometimes runs through a genuinely sent, socially engineered request.
- If you cannot reach them, treat the account as compromised and report it anyway. A false alarm costs IT minutes; a real compromise left unreported costs the organization far more.
4. Report It with Outlook and Tell IT Directly
The Report button and a direct message to IT do different jobs, and a compromised internal account needs both.
- Select the message in your inbox, click Report on the ribbon, and choose Phishing. Outlook asks you to confirm, then submits the message with its full technical headers to Microsoft and your security team.
- Then contact IT through a second channel — ticket, helpdesk chat, or phone — because a report queue is not read with the urgency this needs. Say: "An internal account looks compromised. [Name]'s address sent me a phishing message at [time], and they confirmed by phone that they did not send it."
- Include who else you know received it and whether anyone mentioned clicking. That list shapes how wide IT casts the cleanup.
5. Warn Others Without Forwarding the Email
Forwarding hands the live link to more people, so describe the message instead of passing it on.
- Post in a team channel or tell people directly: "If you got an email from [name] with the subject '[subject]', do not click it — the account is compromised and IT has been told." That sentence protects everyone it reaches and spreads nothing.
- A screenshot is safe to share when someone wants to see the message — an image carries no live link. The email itself is never safe to pass around.
- If you or anyone else already clicked the link or opened the attachment before realizing, follow What to Do If You Clicked a Phishing Link now — it covers passwords, sessions, and what to tell IT — and say so in your report.
6. Know What Happens Next
Reporting can feel like dropping a note into a void, so here is what it actually sets in motion.
- IT blocks sign-in on the coworker's account, ends every active session, and resets the password — cutting the attacker off mid-campaign.
- They check the account's sent items and mailbox rules to find who else was targeted and remove anything the attacker left behind.
- Your reported copy lets them locate the message in every mailbox that received it and remove it centrally — including from people who have not read it yet.
- The coworker gets their account back once it is clean. Compromise is something that happened to them, not something they did; the faster it is reported, the less there is to apologize for.
Troubleshooting
WARNING
A reply from the coworker's address saying "Yes, it's me — it's safe to open" is not verification. While the account is compromised, the attacker answers its email and its chat messages. Only a voice call, a video call, or the person in front of you counts.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| The Report button is missing from the ribbon | Add-in not deployed on this mailbox | Forward the message as an attachment instead: create a new email, drag the suspicious message into it, and send it to your security team. Ask IT to enable the Report Message add-in for you. |
| You already clicked the link or opened the attachment | Acted before the tells registered | Treat it as your own incident as well: follow What to Do If You Clicked a Phishing Link, starting with a password change from a different device, and tell IT you clicked. |
| The coworker insists they sent it, but the request involves money | Social-engineered or coached request | Confirm through their manager or a second person before paying, buying, or changing account details. Business email compromise counts on a single yes being enough. |
| The address turns out to be an external lookalike | Spoofed display name | The coworker's account is fine. Report the message with Report > Phishing and delete it — see How to Identify a Phishing Email for the address tricks to watch for. |
| Strange emails keep coming from the same account after your report | Account not yet contained | Tell IT again with the new timestamps: "The account is still sending phishing after my report — please block sign-in on it now." Repeat reports are signal, not noise. |