An unexpected message about your myExperience login should be verified before you follow its link or enter account information. Open the employer’s known website independently or use an established employer contact route to check the request.
The FTC explains that phishing messages can imitate familiar organizations and claim an account problem to encourage action. Its advice is to verify through a phone number or website you know is genuine, rather than using the contact information supplied in the suspicious message. Source: FTC phishing guidance.
This article explains a checking process. It does not establish that a particular message you received is fraudulent.
Separate the claimed problem from the requested action
Read the message as two parts: what it says happened, and what it wants you to do.
A message might claim that access will expire and ask you to enter credentials elsewhere. Another might claim to be helping with an account problem and ask for a verification code. The claimed problem and the requested action both need to be checked.
A recognizable logo, a familiar subject, or an urgent deadline is not enough to establish the sender’s authority. The useful question is whether the organization confirms that the action is required through a route you already trust.
For a known Northwell starting point, use the employee resource linked in the main login guide.
Verify without continuing the same conversation
If the message may be suspicious, replying to it keeps the verification inside the same potentially untrusted channel. Use a separate route instead.
For an onboarding question, contact the employer representative through an established channel. For an account issue, use the organization’s recognized support process.
Describe the claim without supplying the requested secret. You can say, “I received a message claiming my employee access needs reactivation. Can you confirm whether any action is required?” Include the time and subject through the approved reporting route.
Do not send a password or authentication code to an editorial website to have the message checked.
Preserve useful details without spreading sensitive material
Before reporting, identify the sender address or number, the time received, the subject, and the action requested. Note whether the message included a link or attachment.
Follow the employer’s instructions for submitting the original message. Avoid forwarding it to coworkers as a way to test whether it is safe.
If a screenshot is requested, inspect it for private information. A message can contain an employee identifier, a personalized link, or a code even when the main text appears harmless.
The goal is to help the authorized team inspect the event while limiting unnecessary distribution of the material.
If you already interacted, describe exactly what happened
Different actions provide different information for the response. Distinguish between opening a message, following a link, entering credentials, approving a verification request, and downloading or opening a file.
Do not minimize the event, but do not add actions that did not happen. “I opened the link but did not type anything” is a different report from “I entered my password and approved a request.”
For an employer-managed account or device, contact the appropriate employer security or IT channel promptly and follow its instructions. Account and device remediation may require actions that an employee cannot complete independently.
If you disclosed personal information such as a Social Security number or banking details, the FTC points readers toward IdentityTheft.gov for steps tailored to the information involved. Source: FTC guidance on responding to phishing.
Check the original task separately
A suspicious message may refer to a real task, such as onboarding, without being an authorized way to complete it. Verify whether the task exists through the genuine employer route.
If you are awaiting initial instructions, use the first-access guide to check what is missing. If the verified destination then has a loading problem, use the browser troubleshooting guide.
Keeping the message check separate from the legitimate task helps you resolve both questions: whether the communication should be trusted, and what you actually need to do next.