Cybersecurity incidents don‘t always announce themselves. They can begin with a suspicious email, unusual account activity, an unexpected authentication request, a lost or stolen device, or an accidental disclosure of sensitive information.
Employees and contractors are often in the best position to recognize these warning signs early.
Prompt reporting allows cybersecurity professionals to investigate suspicious activity, determine the potential impact, and take appropriate steps to protect Postal Service™ information, systems, and operations. Delaying a report, even because you‘re uncertain about what happened, may reduce the time available to contain a potential threat.
If you notice something suspicious, do the following:
n Stop and avoid further interaction. Don‘t click any links, open attachments, respond to suspicious messages, or continue entering information.
n Don’t investigate it yourself. Avoid taking actions that could interfere with a cybersecurity investigation.
n Report it promptly. Don‘t wait until you‘re certain it‘s a cybersecurity incident before speaking up.
n Provide relevant details. Share what happened, when you noticed it, and other useful information that can assist cybersecurity professionals with their investigation.
Reporting suspicious activity doesn‘t require you to determine whether an actual cybersecurity incident has occurred. Cybersecurity professionals will investigate and determine what actions are necessary.
Every employee and contractor has a role in protecting Postal Service information and technology.
For more information about additional security best practices and resources, go to the CyberSafe at USPS® Blue page at blue.usps.gov/cyber/.
— Corporate Information Security Office,
Chief Information Officer, 9-17-26