An unexpected message about mynordstrom, payroll, or benefits should be verified through a channel you already trust before you follow its instructions. A familiar company name does not establish who sent the message or where its link leads.
This article explains how to assess a request. It does not report a specific active Nordstrom scam or imply that every unusual message is fraudulent.
Examine the action being requested
Begin with the consequence of complying. Is the message asking you to sign in, disclose information, approve a verification request, install software, or change where money is sent?
The more consequential the action, the more important it is to verify the request independently. A message can refer to a plausible workplace event while directing you to an unrelated destination.
For a hypothetical example, “Your benefits selection is incomplete” might describe a real administrative issue. That possibility does not prove that the attached sign-in link is genuine. You can investigate the underlying issue through the known employer resource without using the message.
Use an independent route
Open the employer resource from established instructions or contact the employer through a verified channel. Ask whether the request exists and where the action should be completed.
The FTC advises using a known website or phone number to check a suspicious message, rather than the contact details supplied inside it. It also warns that phishing messages may impersonate trusted organizations. See the FTC’s phishing guidance.
Do not use a reply from the original sender as your only verification. It keeps the conversation inside the same unverified channel.
Treat downloads and access approvals carefully
A search result or message offering an unofficial “MyNordstrom app” or browser extension is not employer confirmation that the software should be installed. Obtain software instructions through the employer’s established process.
Similarly, an unexpected verification prompt should not be approved just to make it stop. Confirm whether it corresponds to a sign-in you initiated.
If you are simply having trouble accessing a known resource, use the access problems guide. Technical frustration can make an apparently convenient shortcut more tempting.
If you already interacted, identify what happened
Separate these situations when reporting the incident:
| What happened | Information to give the official support team |
|---|---|
| You opened the message only | Sender, time, subject, and suspicious request |
| You followed a link | Destination observed and whether you entered anything |
| You entered a password | Account involved and approximate time |
| You approved a verification request | Whether you initiated the related sign-in |
| You supplied personal or financial data | Categories of information disclosed |
| You downloaded or installed something | File or application name and device involved |
This helps support assess the exposure. It is not a substitute for its incident-response instructions.
Stop interacting with the questionable channel and notify the employer’s designated security or support service promptly. If credentials were disclosed, use the legitimate recovery process and ask whether additional account protection steps are needed.
Preserve useful evidence without spreading secrets
Keep the message, timing, and relevant screenshots for the approved reporting process. Do not circulate passwords, codes, or full identity documents while trying to warn others.
If the message claimed a payroll change, ask payroll to check the relevant record through its verified process. The paycheck guide can help you describe the payment question separately from the security concern.
The goal is to verify the request and address the actual exposure, rather than to decide authenticity from a logo, a spelling mistake, or the urgency of the message alone.