Outlook Shared Mailbox Phishing- What to Check Before Clicking or Replying

 

Outlook Shared Mailbox Phishing|What to Check Before Clicking or Replying

Shared mailboxes are useful for addresses such as:

But they can also create a phishing problem: several people may read the same message, and one person may assume someone else already verified it.

Microsoft 365 shared mailboxes are designed so authorized members can access and manage messages, and users may also be given permission to send as the shared mailbox. That makes a clear verification routine especially important when an unexpected payment request, document, login alert, or urgent customer message arrives.

The safest rule is simple:

Do not trust a message just because it arrived in a familiar shared mailbox. Check the sender, request, link, and internal context before anyone acts on it.



1. Check the actual sender, not just the display name

A message may show a familiar name such as:

  • Microsoft Support
  • Accounts Payable
  • Company Director
  • Existing Customer
  • Trusted Vendor

But the visible name is not enough.

Check the full sender address and look for:

  • A misspelled company domain
  • An unrelated external domain
  • A free email address where a business address would normally be used
  • Small character changes designed to imitate a real domain
  • A sender address that does not match the person or organization named in the message

Microsoft specifically lists mismatched or subtly misspelled email domains as common phishing warning signs.

2. Ask whether the request matches the purpose of the shared mailbox

Context matters.

A message sent to support@ may reasonably contain a customer question.

But a message sent to the same mailbox asking an employee to:

  • Reset a Microsoft 365 password
  • Approve a bank account change
  • Buy gift cards
  • Open an unexpected invoice
  • Sign in to view a secure message
  • Download unfamiliar software

should receive extra scrutiny.

The message may still be legitimate, but the request should make sense for the mailbox and the normal workflow of the team.

3. Do not assume another team member already checked it

This is one of the easiest mistakes to make with a shared inbox.

Someone may see that the message has already been opened and assume:

“Another person must have checked it.”

But “read” does not mean “verified.”

Before clicking a link, downloading an attachment, sending money, or providing information, make sure the request has actually been checked.

A simple internal note can help:

“Has anyone verified this sender?”

That takes only a few seconds and can prevent multiple employees from acting on the same phishing message.

4. Check links before clicking

Hover over links and buttons before opening them.

Be cautious when the destination:

  • Does not match the organization named in the email
  • Uses a strange or misspelled domain
  • Redirects through an unfamiliar website
  • Leads to an unexpected sign-in page
  • Downloads a file instead of opening the expected page

Microsoft recommends avoiding links and attachments in suspicious messages and checking the actual destination before clicking.

When possible, open the service directly through a trusted bookmark, company portal, or known website instead of using the email button.

5. Treat unexpected attachments as unverified

Shared mailboxes often receive real documents, so attachments can feel routine.

That is exactly why employees should slow down when an unexpected file arrives.

Check:

  • Were you expecting the file?
  • Does the filename match the conversation?
  • Does the sender normally send this type of document?
  • Is the file type unusual?
  • Is the message pressuring you to open it immediately?

Microsoft recommends opening attachments only when they come from people you trust and when the message is expected.

6. Verify sensitive requests outside the email thread

Do not use the suspicious message itself as your only verification method.

For example, if a vendor requests a bank account change, confirm it using:

  • A known phone number
  • An existing verified contact
  • A previous trusted email thread
  • Your company’s internal supplier process

If a manager appears to request an urgent action, confirm through Teams, phone, or another known channel.

Microsoft recommends contacting a known sender through another communication method when a suspicious message appears to come from someone familiar.

7. Be careful with messages that appear to come from inside the company

An internal-looking sender is not automatic proof that a message is safe.

A message may be spoofed, or a real account may have been compromised.

Pay attention when an internal message suddenly asks for:

  • An unusual login
  • A payment
  • Sensitive files
  • Passwords or verification codes
  • An urgent change to a normal process

The request itself should still be verified.

A 30-second shared mailbox checklist

Before anyone clicks, replies, pays, or downloads, check:

Do we recognize the full sender address?
Does the request match the purpose of this mailbox?
Has anyone actually verified the message?
Does the link go where it claims to go?
Were we expecting the attachment?
Can we confirm sensitive requests through another channel?

If the answer to one of these questions is unclear, pause before acting.

How to report phishing from a shared mailbox

In supported versions of Outlook, Microsoft’s built-in Report button can also support reporting messages from shared mailboxes or other mailboxes accessed by a delegate.

Microsoft notes that reporting behavior can depend on mailbox permissions. In particular, a delegate may need Send As permission for the report to be submitted from the shared mailbox as intended; without it, the message may only be removed from the folder rather than sent to the configured reporting destination.

For ordinary Outlook phishing reports, Microsoft instructs users to select the suspicious message and choose:

Report → Report phishing

Your organization may also have its own security reporting process, so follow internal IT guidance when available.

What if someone already clicked or entered a password?

If a team member only opened the message but did not enter information, download a file, or approve a sign-in request, close the suspicious page and report the message.

If someone entered credentials or believes an account may have been compromised:

  • Notify the IT or security team immediately
  • Change the affected credentials through a trusted route
  • Review suspicious account activity
  • Investigate mailbox access and related activity
  • Revoke active sessions when appropriate

Microsoft’s guidance for compromised Microsoft 365 accounts includes securing the affected account, resetting credentials, investigating suspicious activity, and revoking active sessions as part of the response process.

Final takeaway

A shared mailbox is not safer just because several people can see it.

In fact, shared responsibility can make it easier for everyone to assume that someone else already checked the message.

Before acting on an unusual email, verify four things:

Who sent it, whether the request makes sense, where the link goes, and whether someone has actually confirmed it.

For a shared inbox, one clear verification step is better than five people assuming the message is safe.

신고하기

이 블로그 검색

오른쪽박스

왼쪽 광고