Maria was making coffee when her phone buzzed. A security alert from her email provider. Sign-in from a city she had never visited, at 2:14 in the morning. She stared at the screen. She had not traveled. She had not logged in at 2 AM. Her stomach dropped.
Her first instinct was to tell her coworker Sandra. Her second instinct was to start changing every password she could think of, starting with her bank. She did neither. Instead, she took a breath and did the one thing that actually helped. She called IT.
Maria's account showed a login from an unfamiliar location. Someone may have had her credentials. The risk was real, but her response made the difference. She did not panic, forward suspicious emails to coworkers, or start clicking through security links on her own. She contacted IT immediately.
A compromised account is not just an email problem. Attackers use one account to reach others. They reset passwords, access shared files, impersonate you to coworkers, or move deeper into company systems. The faster you report it, the less damage they can do.
If you get an unexpected security alert, do not ignore it. Take it seriously even if it turns out to be nothing.
Do not try to investigate on your own by clicking links inside the alert email. Go directly to the app or website instead.
Contact IT right away. Do not wait to see if anything else happens.
Change your password only after IT advises you to. Changing it at the wrong moment can complicate the investigation.
Check your recent account activity. Most email and Microsoft 365 accounts show recent sign-ins and locations in your security settings.
• At home, use the same approach. If your personal email sends you an unusual sign-in alert, take it seriously and change your password from a trusted device.
Open your Microsoft 365 account and review your recent sign-in activity. Go to myaccount.microsoft.com, select Security, then Sign-in activity. Look for anything unfamiliar. If you see something, report it to IT today.
I know how to reach IT quickly if I suspect my account is compromised.
I check security alerts instead of dismissing them.
I do not click links inside security alert emails.
I know where to review recent sign-in activity in my work account.
I would report a suspicious sign-in immediately, not wait and watch.
When in doubt, report it. A false alarm is always better than a real breach that went unreported.