Blog/Phishing

"Your Mailbox Is Full" and Other IT Phishing Emails

Mailbox full, password expiring, account deactivation and security update emails are among the most common phishing lures. How they work and how real IT departments communicate.

CyberWatch AI1 October 2026 · 2 min read
A woman in glasses typing at a desk in an office

Emails that look like they come from your IT department or email provider are among the most effective phishing lures. They sound technical, routine and a little urgent, and they lead straight to a fake login page that captures your password.

Common IT lures

  • "Your mailbox is full. Emails will stop arriving."
  • "Your password expires today. Keep your current password."
  • "Unusual sign-in activity. Verify your account."
  • "Your account will be deactivated. Confirm you are still using it."
  • "New security policy. Re-validate your account."
  • "You have 5 held messages in quarantine. Release them."
Illustrative example · Email
From: IT Service Desk Subject: Password Expiry Notice Your network password expires in 4 hours. To keep using your current password, validate it here: hxxps://portal-password-keep[.]com Failure to act will result in loss of email access.
Red flags:
  • "Keep your current password" is a common trick; real expiry makes you set a new one.
  • A link to an outside domain and a short deadline.

How real IT communicates

  • Password changes happen through the normal system prompt or the company's known portal.
  • Storage warnings appear inside your email app, not only as emails with links.
  • Important changes are announced through several channels, such as the intranet or team messages.
  • IT will not ask for your password.

What to do

  1. Do not click; check through the app or your company's known portal.
  2. Report the email with your report button. See phish report buttons.
  3. If you entered your password, act now. See entered your password on a phishing page.

Got an IT email you are unsure about? Paste it into CyberWatch AI Scan for a free check.

For more, see how to recognise phishing in our complete guide.

Frequently asked questions

Does my IT team send password expiry emails?

Some do, but genuine ones usually ask you to change your password through the normal system, not by clicking a link to a sign-in page.

What should I do with a 'mailbox full' email?

Check your storage in your email settings or ask IT through the usual channel. Do not sign in through the link.

What if I already entered my password?

Change it immediately, report to IT, and follow their instructions. See our guide on entering your password on a phishing page.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
  3. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.