
An invoice from a familiar supplier. A meeting request that appears to come from your CEO. A Microsoft 365 alert that arrives during a packed workday. Phishing works because it borrows the language, urgency, and tools of ordinary professional life. Knowing how to report phishing attacks is not an admin task to postpone - it is one of the fastest ways to protect your team, your customers, and your reputation.
For people working across startups, scaleups, agencies, and large organizations, a single report can reveal a campaign before it reaches the rest of the company. That matters especially in connected European tech teams, where partners, freelancers, investors, and colleagues may all sit outside the same security environment.
First, recognize what deserves a report
Phishing is any message designed to pressure you into giving away information, money, or access. It can arrive by email, text message, social media direct message, a collaboration platform, or a spoofed video call. The familiar version asks you to reset a password. More targeted attempts may impersonate a founder, finance lead, recruiter, customer, or a known vendor.
Report a message when something feels inconsistent, even if you cannot prove it is malicious. Common signals include a sender address that is slightly off, an unexpected attachment, a login page with an unfamiliar web address, a request to bypass normal payment approval, or artificial urgency such as "pay within the hour."
A message does not need to be clumsy to be phishing. Business email compromise attacks are often short, polished, and written after attackers have studied an organization’s leadership, suppliers, or public posts. The absence of spelling mistakes is not evidence that a request is safe.
How to report phishing attacks without losing evidence
Your first move is simple: do not click, reply, download, or forward the suspicious message to colleagues. Forwarding can spread a harmful link or attachment. Instead, use the phishing-report function in your email or messaging platform when one is available. This usually sends the message to the provider and, in well-configured workplace systems, to your internal security team.
Then report it through your organization’s designated channel. Depending on the company, that may be an IT service desk, security email address, Slack or Teams incident channel, or a managed security provider. Follow the process even if you think someone else has probably reported it. Security teams can compare recipients, timestamps, sender details, and message variants to understand the scope.
Include the original message whenever your reporting process supports it. Technical details such as full email headers can help analysts trace the route a message took and identify spoofing. If you cannot attach the original safely, provide the sender’s displayed name and email address, the subject line, the time you received it, and a screenshot of the content. Do not crop out the address bar if the report involves a website.
For a suspicious text or social message, capture the account name or phone number, the exact wording, and the destination link without opening it. A screenshot is useful, but report the profile in the platform as well. Impersonators often target people in visible roles, including founders, community leads, and women who share their expertise publicly.
If you clicked the link or entered information
Report immediately. Do not let embarrassment turn a manageable incident into a larger one. Security teams would rather receive an early, incomplete report than a perfect one hours later.
Disconnect from the network if your company’s incident guidance tells you to do so, particularly after downloading a file or installing software. Contact IT or security through a known, separate channel - not by replying to the suspicious message. Tell them exactly what happened: whether you opened a link, entered a password, approved a multi-factor prompt, shared a file, or sent payment information.
Change the affected password from a known-clean device, not from a device you suspect may be compromised. If you reused that password elsewhere, change those accounts too. Review multi-factor authentication methods, active sessions, mailbox forwarding rules, and recent account activity. Attackers who obtain an email login may set hidden forwarding rules to monitor conversations long after the initial phishing message disappears.
If money, payroll information, customer data, or bank credentials were involved, contact your finance team and financial institution right away. Payment recall options can be time-sensitive. Your legal, privacy, and security teams may also need to assess notification obligations, particularly when personal data is involved.
Report beyond your workplace when the risk calls for it
Internal reporting protects your organization. External reporting can help remove malicious infrastructure and build a wider picture of fraud. The right destination depends on where you are and what happened.
Report an impersonation account, message, or ad directly to the platform where you found it. Report malicious websites through the browser or email provider’s abuse and phishing tools. If a scam imitates a legitimate supplier, notify that supplier using contact details from a trusted source, not details contained in the suspicious message. This gives them a chance to warn other customers and secure a compromised account if necessary.
For financial fraud or identity theft, make a report to the appropriate national fraud or law-enforcement body. In the United States, that can include the Federal Trade Commission’s fraud reporting service and the FBI’s Internet Crime Complaint Center, especially when funds or sensitive information have been stolen. For European teams, national cyber security centers, CERTs, fraud-reporting bodies, and local police are often the relevant routes. Your security team or insurer may have a required escalation path, so check before assuming one external report covers everything.
Keep a record of what you reported and when. Save case numbers, screenshots, and relevant messages in accordance with company policy. Do not keep copies of sensitive data in personal folders or send them through unapproved channels just to document the incident.
Give security teams details they can act on
A useful phishing report answers a few practical questions: Who appeared to send it? Who received it? What did it ask for? Did anyone interact with it? What systems, accounts, files, or payments may be affected?
Context matters. A fake invoice sent to one employee may be a nuisance; the same email sent to every person in finance may signal a targeted campaign. A fake recruiter message sent through LinkedIn may be trying to collect resumes, personal data, or credentials from job seekers. Mention why the message seemed plausible, such as an ongoing vendor relationship or a real event you recently attended.
Avoid diagnosing the attack yourself. Calling something "definitely malware" can send a report in the wrong direction, while vague descriptions such as "weird email" may slow triage. State observable facts and let the security team investigate. For example: "Received at 10:14 a.m. from a lookalike vendor domain. It requested a password reset and linked to a page that resembled our Microsoft sign-in screen. I did not open the link."
Make reporting part of team culture
Phishing reporting succeeds when people feel safe speaking up. A culture that shames someone for clicking will encourage silence, and silence gives attackers time. Leaders can change that dynamic by treating reports as useful intelligence rather than personal failure.
This is also an inclusion issue. People who are new to a company, junior in their role, working in a second language, or outside the headquarters time zone may hesitate to question an apparently senior request. Clear reporting routes, regular examples, and permission to verify unusual requests level the playing field. No one should need to choose between seeming "difficult" and protecting the business.
Teams should test their process before a real incident. Can employees find the report button? Do they know whom to call after hours? Does finance verify changes to bank details through a second channel? Are executives willing to normalize a pause before urgent payments? Technology filters help, but human escalation remains essential.
The best phishing report is rarely the most technical one. It is the one sent quickly, through the right channel, with enough context for someone else to act. That small pause before clicking can protect far more than one inbox - it can protect the trust your work depends on.




