πŸ†˜ Emergency Guide Β· 🟑 Medium-High Urgency

Phishing Link Clicked β€” Now What?

Someone on your team clicked a suspicious link, opened an attachment, or entered credentials on a fake login page. The first 15 minutes determine whether this is a close call or a full breach.

⚠️ DON'T PANIC β€” BUT ACT FAST

Create a culture where employees report mistakes immediately β€” without fear of blame. The worst response is silence. A 5-minute delay in reporting can be the difference between a contained incident and a full compromise.

Scenario 1: They Clicked a Link (but Did Not Enter Anything)

The link may have loaded a page that attempted a drive-by download or browser exploit. These are less common than credential harvesting but more dangerous.

  1. 1
    Disconnect the device from the network immediately. WiFi off, Ethernet unplugged. This prevents any malware from communicating with its command server or spreading laterally.
  2. 2
    Do NOT shut down the device. Keep it powered on but disconnected. IT/forensics may need to examine browser history and memory.
  3. 3
    Run a full antivirus scan. Windows Defender (built-in, free) or your EDR tool. Run the deepest scan available, not the quick scan.
  4. 4
    Check for unauthorized software. Look for recently installed programs, new browser extensions, or unfamiliar processes in Task Manager.

Scenario 2: They Entered Credentials on a Fake Login Page

This is the most common phishing outcome. The attacker now has a working username and password. They will use it immediately.

  1. 1
    Change the compromised password IMMEDIATELY β€” from a different, clean device. Do not use the potentially compromised computer to change passwords. Use your phone or another computer.
  2. 2
    Change that password everywhere it was reused. This is why password reuse is dangerous β€” if they used the same password on other services, change those too. Now. Use a password manager to generate unique passwords going forward.
  3. 3
    Check for forwarding rules and filters. Attackers often set up email forwarding rules to silently monitor communications. Check Email Settings β†’ Forwarding and any filter rules.
  4. 4
    Check login history and active sessions. Most services show recent login locations and active sessions. Look for logins from unfamiliar locations or devices. Force-sign-out all sessions.
  5. 5
    Enable MFA on the account. If it was not already enabled, enable it now. MFA would have stopped the attacker even with the stolen password.

Scenario 3: They Opened an Attachment

Attachments can contain malware, ransomware, or macro viruses. Treat this as potentially severe.

  1. 1
    Disconnect immediately. Network off. Do not pass go.
  2. 2
    If it was a macro-enabled Office document (.docm, .xlsm, .pptm) and they enabled macros: Assume the device is compromised. Begin incident response for potential ransomware or data exfiltration.
  3. 3
    Run the deepest antivirus scan available. Consider engaging a professional incident response firm if the attachment contained ransomware or a remote access trojan (RAT).

Phishing Prevention Guide: 7 Red Flags

Teach your team what to check before clicking any link or opening any attachment. Printable one-pager included.

Read Phishing Prevention Guide β†’

After the Incident: Report & Document

  • Document the incident: What was clicked, when, by whom, what happened, what steps were taken. This is required for cyber insurance claims and may be needed for breach notification.
  • Notify your IT provider or security contact. They may need to investigate broader network impact.
  • Forward the phishing email to your email provider's abuse team and to the Anti-Phishing Working Group at reportphishing@apwg.org.
  • Report to the FBI IC3 at ic3.gov if financial information was exposed.
  • Do NOT punish the employee who clicked. Blame creates a culture of hiding mistakes. The employee who reports immediately just saved your business. Thank them publicly and use this as a training opportunity for the whole team.

Prevention for Next Time

  1. 1. MFA on everything. Stolen credentials are useless if MFA is required.
  2. 2. Email security gateway. Block phishing emails before they reach inboxes. See our email security comparison.
  3. 3. Regular phishing simulations. Test your team monthly. Free tools like KnowBe4's free phishing test exist.
  4. 4. Create a "report phishing" button. Make it trivially easy for employees to report suspicious emails β€” one click in their email client.