Blog

That 'Reset Your Password' Email Might Not Be from IT

Written by 3Value | August 13 2026

John had a busy Tuesday. Back-to-back meetings, a deadline and three cups of coffee that barely helped. Around 2 PM, an email landed in his inbox with the subject line: "Action Required: Reset Your Password Now."

It looked official. The logo matched. The colors were right. The email said his account would be locked in 24 hours if he didn't act. There was a blue button. Reset My Password. John was tired and clicked it.

The page asked for his current password first, then his new one. He typed both and hit submit. Nothing happened. The page just refreshed. He figured it was a tech glitch and moved on.

It wasn't a glitch. John had just handed his password to someone who had no business having it.

What Happened

The email was not from IT. It was a phishing email designed to look like a real password reset notice. The link took John to a fake login page that collected his credentials. The attackers now had his username and password.

Your work account connects to your email, files, shared drives and possibly payroll or HR systems. One stolen password can open all of it. Fake password reset emails are one of the most common ways attackers get in, and they work because they create a sense of urgency. Urgency makes people skip the pause.

Remember the Framework

Simple Steps to Protect Yourself

  • Don't click password reset links you didn't request. If you didn't ask to reset your password, treat that email as suspicious. Full stop.

  • Go directly to the source. Instead of clicking the link, open your browser and go to the login page manually. If something is really wrong with your account, you'll see it there.

  • Check the sender address carefully. The display name might say "IT Support," but the actual email address will often reveal the truth. Look for odd domains or slight misspellings.

  • Watch for urgency. Phrases like "your account will be locked," "act within 24 hours" or "immediate action required" are pressure tactics. Slow down when you see them.

  • Apply the same habit to personal accounts. Fake reset emails target bank accounts, social media and shopping sites too. The trick is identical.

Do This Today

Find one recent email in your inbox that mentions a password, account alert or login. Check the actual sender address, not just the display name. If anything looks off, report it to IT and delete it.

Quick Checklist

  • I did not request this password reset

  • The sender address matches the real company domain

  • I am not clicking the link. I am going to the site directly

  • I am not entering my current password on a reset page

  •  I have reported anything suspicious to IT.

Zero Trust Human Habit of the Week

Never enter your current password on a password reset page. Legitimate reset flows ask you to create a new one. They do not need your old one.