Security incident notification email template (end customer)
How to use it: copy and paste, fill in the fields
[IN BRACKETS]and send NOW. Goal: reduce damage (phishing/fraud), not “look good”. Rule: if you are unsure, say so. The worst outcome is sounding certain and having to walk it back.
Email subject line (pick 1)
No selling and no euphemisms. Pick one of these three lines:
Important security notice about your [COMPANY] account
Security notice: possible phishing attempts related to [COMPANY]
Security information: we are investigating an incident
Email preheader (one line)
The preheader is the second thing people read, before they open anything. It should say what the email is for, not decorate it:
We are investigating an incident and we want you to know what to do to protect yourself right now.
Email body
Everything inside the block goes to the customer, as it is. Replace the fields [IN BRACKETS] and delete the lines that do not apply.
Hi,
We are writing to tell you about a security incident we are currently investigating at [COMPANY].
Right now, this is what we know (and what we do not):
What happened
- On [DATE] we detected [SHORT_DESCRIPTION_OF_WHAT_WAS_DETECTED].
- At this point we still cannot confirm [WHAT_WE_CANNOT_CONFIRM: exact scope / origin / whether there was exfiltration].
- What we can tell you is that you may receive phishing or fraud attempts impersonating [COMPANY].
What data could be involved (based on what we know today)
- [DATA_THAT_COULD_BE_INVOLVED: email / name / phone / address / national ID / order history].
- We have seen no indication of exposure of: [DATA_NOT_EXPOSED: cleartext passwords / full payment details]. (If you are not sure, delete this line.)
What we are doing
- We have [ACTIONS_TAKEN: blocked access / forced a password reset / invalidated sessions / tightened detections / notified providers].
- We are working with [TEAM: our internal team / external experts] to determine the scope and close off any access path.
- If we confirm any relevant new information, we will tell you through this same channel.
The important part: how to protect yourself now (2 minutes)
1) Do not do this
- Do not click links in emails or texts saying "your order is on hold", "confirm payment", "update your details", "verify your account".
- Do not download unexpected attachments.
- Do not give out verification codes over the phone.
2) How to spot fake messages
A message is NOT from [COMPANY] if:
- it rushes you ("final notice", "within 30 minutes...", "will be cancelled...")
- it asks for passwords, 2FA codes, bank details or to "confirm your identity" through a link
- it comes from odd domains or URL shorteners
We will NEVER ask you for:
- your password
- verification codes (SMS/Authenticator)
- card details by email or text
- to install an app to "verify" anything
3) What we recommend you do right now
- Change your [COMPANY] password if you reuse it on other sites.
- Turn on 2FA if it is available to you: [2FA_LINK_OR_APP_PATH]
- Check your account for anything odd:
- orders you do not recognise
- address changes
- email or phone changes
4) If you clicked or handed over data
If you interacted with a suspicious message:
- change your password immediately
- check your bank if you gave out payment details
- get in touch with us here: [SUPPORT_CHANNEL]
- if you get calls asking for "verification", hang up and call our support yourself from the official website or app
Official channels and support
To avoid any confusion, these are our official channels:
- Website: [OFFICIAL_URL]
- App: [APP_NAME] (downloaded from [OFFICIAL_STORE])
- Support: [SUPPORT_EMAIL] / [SUPPORT_PHONE] / [TICKET_URL]
- Incident status: [STATUS_OR_POST_URL]
If someone contacts you through any other channel or asks you for sensitive data, do not trust it.
Next update
We will publish an update by [DEADLINE_DATE_TIME] at the latest, even if we do not have everything wrapped up.
If the investigation confirms an impact on personal data, we will tell you explicitly and in detail.
Thanks for your patience.
[FULL_NAME]
[ROLE: Head of Security / Security Team]
[COMPANY]
Internal appendix (DO NOT send to customers)
Quick send checklist (first hour)
Go through this before hitting send, not after:
- Subject line with no selling, no euphemisms, no “peace of mind”
- What is known / what is not known (no spin)
- Practical risk (phishing/fraud) explained in 2 lines
- 3 or 4 concrete actions for the customer
- Explicit “we will never ask you for X”
- Official channels and support
- Commitment to a next update, with a time
Variants by channel
The same notice, cut down. The fields in brackets are the same ones as above.
SMS (300 characters max)
[COMPANY]: Security notice. You may receive fake messages or calls. We never ask for passwords or codes. Only log in through the official app or website. Info and updates: [SHORT_OFFICIAL_URL]
Push
Security notice: possible phishing attempts. Open the app to see our recommendations and updates.
Web/app banner
Security notice: we are investigating an incident. Watch out for fake emails, texts and calls. Recommendations and status here: [STATUS_OR_POST_URL]
How did you end up here?
This template went out to the email list as a response to a security incident.
You can join the email list here: vamosallio.com