β οΈ DON'T PANIC β BUT ACT FAST
Create a culture where employees report mistakes immediately β without fear of blame. The worst response is silence. A 5-minute delay in reporting can be the difference between a contained incident and a full compromise.
Scenario 1: They Clicked a Link (but Did Not Enter Anything)
The link may have loaded a page that attempted a drive-by download or browser exploit. These are less common than credential harvesting but more dangerous.
- 1Disconnect the device from the network immediately. WiFi off, Ethernet unplugged. This prevents any malware from communicating with its command server or spreading laterally.
- 2Do NOT shut down the device. Keep it powered on but disconnected. IT/forensics may need to examine browser history and memory.
- 3Run a full antivirus scan. Windows Defender (built-in, free) or your EDR tool. Run the deepest scan available, not the quick scan.
- 4Check for unauthorized software. Look for recently installed programs, new browser extensions, or unfamiliar processes in Task Manager.
Scenario 2: They Entered Credentials on a Fake Login Page
This is the most common phishing outcome. The attacker now has a working username and password. They will use it immediately.
- 1Change the compromised password IMMEDIATELY β from a different, clean device. Do not use the potentially compromised computer to change passwords. Use your phone or another computer.
- 2Change that password everywhere it was reused. This is why password reuse is dangerous β if they used the same password on other services, change those too. Now. Use a password manager to generate unique passwords going forward.
- 3Check for forwarding rules and filters. Attackers often set up email forwarding rules to silently monitor communications. Check Email Settings β Forwarding and any filter rules.
- 4Check login history and active sessions. Most services show recent login locations and active sessions. Look for logins from unfamiliar locations or devices. Force-sign-out all sessions.
- 5Enable MFA on the account. If it was not already enabled, enable it now. MFA would have stopped the attacker even with the stolen password.
Scenario 3: They Opened an Attachment
Attachments can contain malware, ransomware, or macro viruses. Treat this as potentially severe.
- 1Disconnect immediately. Network off. Do not pass go.
- 2If it was a macro-enabled Office document (.docm, .xlsm, .pptm) and they enabled macros: Assume the device is compromised. Begin incident response for potential ransomware or data exfiltration.
- 3Run the deepest antivirus scan available. Consider engaging a professional incident response firm if the attachment contained ransomware or a remote access trojan (RAT).
Phishing Prevention Guide: 7 Red Flags
Teach your team what to check before clicking any link or opening any attachment. Printable one-pager included.
Read Phishing Prevention Guide βAfter the Incident: Report & Document
- Document the incident: What was clicked, when, by whom, what happened, what steps were taken. This is required for cyber insurance claims and may be needed for breach notification.
- Notify your IT provider or security contact. They may need to investigate broader network impact.
- Forward the phishing email to your email provider's abuse team and to the Anti-Phishing Working Group at reportphishing@apwg.org.
- Report to the FBI IC3 at ic3.gov if financial information was exposed.
- Do NOT punish the employee who clicked. Blame creates a culture of hiding mistakes. The employee who reports immediately just saved your business. Thank them publicly and use this as a training opportunity for the whole team.
Prevention for Next Time
- 1. MFA on everything. Stolen credentials are useless if MFA is required.
- 2. Email security gateway. Block phishing emails before they reach inboxes. See our email security comparison.
- 3. Regular phishing simulations. Test your team monthly. Free tools like KnowBe4's free phishing test exist.
- 4. Create a "report phishing" button. Make it trivially easy for employees to report suspicious emails β one click in their email client.