What is the recommended emergency response plan for enterprise email phishing incidents?
The recommended plan includes immediate actions to mitigate risks, verification steps, and service-specific boundaries. First, reset compromised passwords and revoke suspicious client access or app-specific passwords. Check for unauthorized auto-forwarding rules, filters, aliases, or security changes. Review login, attack, and sending logs to identify timing, IPs, and actions. Use 138 Enterprise Email’s built-in features like spoofed email identification and unknown sender alerts for detection. Ensure SPF, DKIM, and DMARC are configured and validated to prevent domain impersonation. For high-risk accounts (e.g., finance, admin), enforce strong passwords and two-factor authentication. Note: Official support for incident response may require validation via contract channels; self-service tools are primary. If logs indicate persistent threats, contact 138’s official operations team for forensic review. Always verify high-risk actions (e.g., payments, credential changes) through out-of-band methods like phone calls.
For account recovery, if the administrator forgets the password and has not bound a mobile phone, use the contract-reserved email to apply to kf@138.gz.cn for official verification and processing.


