Stop immediately and report it to OurTechnology Department. Do not keep clicking, replying, forwarding, or trying to “fix it” yourself. Report the email as phishing and contact IT right away so they can check your account, device, and whether others received the same message. CISA recommends recognizing and reporting phishing quickly because links and attachments can steal information or infect devices. Reporting it can be done via your Phish Notify Icon in your Gmail Inbox on your side panel:
Tell IT exactly what happened. Share whether you clicked a link, opened an attachment, entered your username/password, approved an MFA prompt, downloaded a file, or replied with information. The more specific you are, the faster IT can contain the issue.
Change your password immediately if you entered credentials. Use a different device if possible, go directly to the official login page, and do not reuse the old password anywhere else. NIST and CISA both advise changing exposed passwords right away.
Do not approve unexpected MFA prompts. If you receive login approval requests you did not initiate, deny them and notify IT. MFA helps protect accounts even when a password is compromised, but only when users avoid approving suspicious prompts.