Skip to content

Society Toolkit

When a Suspicious Email Reaches a Society

A volunteer treasurer or booking contact will eventually click a bad link. The first moves that limit the damage, drawn from plain security guidance.

The editorial team of The Repertory NotebookSociety Toolkit

Laptop on a kitchen table showing an email inbox beside a notebook and a phone in evening light
Laptop on a kitchen table showing an email inbox beside a notebook and a phone in evening light. Illustration produced for this entry.

A volunteer society's first steps after a suspicious email are the same as anyone's: stop, do not reply, and check the account that email touched before anything else. Because a society's mailboxes hold booking confirmations, license correspondence and the bank details of a small budget, the hour after a bad click matters more than the click itself.

The committee is a target for the ordinary reason that it is a small organization with a public address and shared passwords passed between volunteers. Nothing about the attack needs to be clever; it only needs to arrive on a busy night.

What should a volunteer do in the first hour after a bad click?

In the first hour after a bad click the volunteer should disconnect nothing and change the password of the affected account from a different device, then check for forwarding rules and active sessions they did not create. Those two quiet actions, password changed elsewhere and hidden forwarding removed, close most of the damage a phishing click opens.

Plain step by step guidance exists for exactly this situation. Security, Applied is a reference guide written for people and small teams without a specialist, covering the first steps after a phishing click, a hacked account, a lost phone and the first moves against ransomware, with pages on comparing multifactor options and keeping a one page response plan. Its account recovery pages walk through sessions, reused passwords and hidden forwarding rules in the order a volunteer needs them.

A written incident note helps here too. Recording the time of the click, the account affected and the actions taken gives the committee a record for the bank or the provider if the incident grows, and it turns a frightening evening into a dated sequence of completed steps.

The treasurer's mailbox deserves priority because it touches the bank. A society that keeps its bookkeeping under one email address should treat any suspicious click on that account as a financial event, not a technical one, and tell the committee the same evening.

Which accounts does a small society need to protect first?

A small society protects three accounts first: the mailbox that receives booking and banking mail, the cloud folder that holds the program files and accounts, and the social account that speaks to the audience. Each is a single point of failure, and each is recoverable if the response is quick and written down.

The recovery note belongs in the same folder as the rest of the handover. A society that already writes down who holds which role across the committee year adds one more line: where the passwords live, who resets them, and which address the bank knows. When the volunteer who set up the accounts leaves, the next officer should not have to guess which email controls the domain.

Sessions deserve their own check because a stolen login often persists through a password change. The account's security page lists devices and active sessions, and signing out everything the committee does not recognize closes the door the intruder left open. The same screen usually reveals the quiet damage, a new forwarding address or an added recovery phone, which should be removed and noted with the date.

How does the prevention side look for a small group?

Prevention for a small group is a short list rather than a program: a password manager so the shared accounts stop traveling by email, a second factor on the treasurer's and coordinator's mailboxes, and a named habit of checking sender addresses before paying anything new. The one page response plan that the security guide describes is the right size for a society, one sheet taped inside the accounts folder saying what to do and in what order.

New volunteers join mid season and inherit habits, not manuals, so the induction email should say two things: never pay a new invoice without a voice check, and report a suspicious click the same day without embarrassment. A society where reporting is safe catches the incident in the first hour instead of the third month.

The same care applies to the society's own website and domain account, because losing the registrar login can cost the season page itself. Two volunteers should know where those credentials live, and the renewal notices should reach an address that is read, not one that left with the last coordinator.

The Federal Trade Commission publishes a consumer guide on recognizing and avoiding phishing scams, covering what the messages look like, what the click leads to and how to report one. It is the standard plain language reference in the United States and a reasonable printout to keep with the society's accounts folder.