Skip to content.
A woman with curly hair, wearing a teal blouse, stands and leans over a laptop on a desk in a bright modern office with large windows and scattered papers and sticky notes.

How to address hoax reports to your hotline

Anonymous reporting channels are essential to a strong speak-up culture. They help organizations identify concerns early, protect employees and respond to potential misconduct. But when a report appears suspicious, compliance, legal, IT and investigation teams need to balance thoughtful follow-up with the right security precautions.  

Recently, some customers have told us they received anonymous reports through their internal reporting systems that appear to be hoaxes or phishing attempts.  

The reports used similar language and appeared designed to obtain direct contact information for an organization’s general counsel. One example stated:  

“I have identified a massive company wide data breach. Please take the following steps. 

  • Inform the General Counsel 
  • Provide me with the GC’s email address via Ethics Point. 
  • Inform the GC that I will have a New York Times reporter email them using the subject line “Fully Aligned”. 

Thank you”  

Reports like these can create added IT security risk, whether they arrive by email or through an online reporting and case management system. They can also be difficult to assess at first, particularly for teams focused on responding quickly, consistently and appropriately to every concern raised. 

A prior example shows why organizations should take suspected hoax reports seriously. In 2021, a researcher submitted fabricated reports through multiple company hotlines as part of an academic experiment, without the knowledge or consent of the organizations involved. The exercise consumed investigative time and resources, including outside counsel costs for several companies, and created reputational risk. We are also aware of at least one additional academic research project before 2020 that used fraudulent claims submitted through company reporting systems to assess corporate responses. 

Whatever the source, a suspicious report should be handled carefully and escalated through the organization’s established channels before any sensitive information is shared. 

Customers often ask whether it is safe to exchange follow-up messages with a reporter through NAVEX EthicsPoint or WhistleB when a report looks suspicious. The answer is a qualified yes. Follow-up communication through EthicsPoint and WhistleB is designed to support secure case handling, but organizations should avoid sharing additional information with the reporter until the submission has been assessed and its legitimacy is better understood. 

If you decide to respond, do so within the case management system rather than through corporate email. Keeping the exchange inside the reporting platform helps maintain separation between your organization’s systems and any potential threat actor. As part of NAVEX security protocols, attachments uploaded into EthicsPoint and WhistleB are scanned for known malware.

Building AI you can trust

Even when a secure reporting platform is in place, any response to a suspicious reporter should be limited, sanitized and reviewed with care. If there is uncertainty, consult legal counsel, IT and audit stakeholders before replying. The following steps can help teams respond appropriately while reducing unnecessary risk.  

  1. Respond through the reporting platform, not corporate email 
  2. Share only the minimum information needed for follow-up 
  3. If suspicious submissions increase, consider temporarily disabling online search functionality 
  4. Remove reports after they have been confirmed as hoaxes 

Stay secure, always respond through the reporting platform 

NAVEX hotline and case management systems are designed to support secure communication between investigators and anonymous reporters. Still, teams should be cautious when copying, pasting or acting on information provided in a suspicious submission. Treat links with particular care. Attachments submitted through the system are scanned, but links or copied text opened in a browser or corporate email environment may still introduce risk.  

Suspicious reports should be treated seriously, but they should not weaken an organization’s commitment to trusted speak-up channels. Employees need confidence that they can raise concerns safely, and organizations need processes that help teams distinguish genuine reports from potential threats. By keeping reporting channels open, responding through secure systems and applying additional diligence when something looks unusual, organizations can protect both their people and the integrity of their ethics and compliance program.