Errant sign-in alerts & how to report phishing
Two different security notices land in ALTA inboxes. This SOP explains the difference: the routine, system-generated errant sign-in notice (no action needed) versus a genuine phishing email (report it).
"Errant sign-in attempt" notices — reassure
You may receive a "[ALTA Hub Security] Errant sign-in attempt (non-ALTA account)" notice. The sign-in attempt was blocked by ALTA's security controls; your account was not accessed. No action is needed — unless you recognize the attempt as your own and were blocked, in which case reply so IT can verify.
If you receive an unexpected MFA prompt you did not initiate, do not approve it and report it.
Suspected phishing — how to report
If an email looks like phishing, reporting it is exactly the right call.
- Do not click any links, open attachments, or reply.
- Use the report-phishing button (or forward to IT), then delete the message.
- If you already clicked, contact IT immediately so your session can be secured.
See the Phish Alert SOP for how to use ALTA's Phish Alert Report button in the Outlook desktop app.
Source: OmniDesk canned responses "Errant sign-in attempt — reassure & verify" and "Suspected phishing — thank & advise" (ALTA-authored). · Owner: IT / Security.