What to do if a colleague's account is hacked: an action plan for the team
What to do if a colleague's account is hacked: a calm plan for the team—how to recognize the risk, verify identity, and protect data.
What to do if a colleague's account has been hacked? If you receive a request from a familiar profile to urgently change payment details, open a file, or forward a code, do not act on it automatically. First, stop the risk, then verify the identity, and alert the team.
Signs of a compromise
One strange message does not automatically prove a hack. However, several signs require attention: unusual communication style, sudden urgency, requests for money, passwords, or codes, a new link, an unexpected file, or a message unrelated to work.
Requests to change payment details "right now" or to download a document that hasn't been discussed before are particularly dangerous. Do not blame your colleague: the profile may have been compromised, and the employee might not even know it yet.
Team checklist
- Do not click the link, open the file, or send data.
- Save screenshots, message timestamps, and details about any attachments.
- Warn members of the work chat: "Do not fulfill requests from this profile, the identity is being verified."
- Temporarily pause sensitive discussions and remove payment details, access credentials, and personal data from the chat.
- Contact the colleague using a known phone number or another verified channel, such as a video call.
- Inform your manager or the person responsible for security. Do not delete the correspondence and do not attempt to hack the profile back.
The correct course of action when a breach is suspected: first limit the consequences, then confirm the facts, and only then return to normal work.
How to verify identity
Do not ask for confirmation in the same suspicious dialogue: the attacker may answer convincingly. Call the number from your corporate directory or use a communication channel you have used before. You can clarify a detail known only to that colleague and the team. A legitimate request will withstand a short pause.
Links and files from a compromised account may lead to a password-stealing page, a malicious file, or a fake payment form. It is better to open the necessary service manually. After the incident, the employee should change their password, terminate suspicious sessions, and contact the administrator of the work service.
How PING helps you stay calm
At PING, we focus on clear signals: the user should quickly understand what is happening in the conversation. For the team, this means a simple rule: an unusual request gets an individual verification, and a warning is formulated directly and addressed to all necessary participants. This makes it easier to stop communication if an account is compromised and avoids spreading false accusations.
Additional context on the topic is available in the article Key signs of phishing in work chats: a team checklist.
Read also
Frequently asked questions
A colleague is writing strange things: should I block them immediately?
First, contact the colleague by phone, through another verified channel, or via video call. This way you will verify their identity while preserving the contact.
Do I need to report a possible hack to the work chat?
Yes. Briefly warn the members that the profile may be compromised and ask them not to open links, files, or fulfill requests from that chat.
How do I quickly verify that a real person is writing?
Call them via a known number, use another verified channel, or use a video call. Do not verify the identity in the same suspicious chat.
Was this article useful?
Your feedback helps make PingBook more precise.