The essentials
- Clicking alone is rarely a compromise; entering credentials or running a download usually is. Be precise about which happened.
- Change the exposed password now, from a different device, and revoke active sessions — attackers use stolen credentials within minutes, not days.
- Report it to IT or security immediately. Speed is the single biggest factor in how small this stays.
- Multi-factor authentication helps but does not make you safe: real-time phishing kits relay codes as you type them.
- Write down exactly what you saw, clicked, and entered — that detail directs the whole response.
Phishing works on everyone eventually — practiced professionals click well-crafted lures every day. The difference between a non-event and an incident is almost never the click itself. It is what happens in the minutes after.
Work out which of three things happened: you only clicked, you entered credentials, or you ran something that downloaded. Each has its own path below.
Do this now
- Establish what actually happened. Only clicked and closed it? Low risk, still report it. Entered a password? Treat that credential as stolen. Ran a file or enabled a macro? Treat the device as compromised and disconnect it.
- Change the password from another device. If you typed credentials, change them now — from a device you trust, not the one that clicked. Then sign out of all sessions for that account.
- Check and strengthen MFA. Verify no new MFA devices or app passwords were added to the account, and approve nothing you did not initiate.
- Report it with the details. Tell IT or security exactly what you clicked, when, and what you entered. The timestamp and the URL are worth more than an apology.
- Watch the follow-on. Password-reset emails, MFA prompts you didn't trigger, or 'security team' phone calls in the next hours are the attacker using what they got.
- Let the device be checked. If anything downloaded or ran, hand the machine to security for scanning rather than cleaning it yourself.
What not to do
- Do not stay quiet out of embarrassment — silence converts a five-minute fix into a breach.
- Do not forward the phishing email around the office to warn people; report it and let security notify.
- Do not click "unsubscribe" on the message — it confirms your address is live.
- Do not trust follow-up calls from a "security team" you didn't contact.
- Do not delete the email; it is the sample the investigation starts from.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- The phishing email itself, exported as a file with headers, not forwarded.
- The URL you landed on — copied, not revisited.
- The exact time of the click and of anything you entered.
- Screenshots of the fake page if it is still open.
- Any follow-on prompts, resets, or calls you receive afterward.
Keep a clear head
The flush of shame after clicking is universal — and it is the attacker's best defense, because embarrassed people delay reporting. Every security team would rather hear about ten false alarms than miss one real click by an hour.
You are the witness, not the culprit. The lure was built by professionals to beat exactly the checks you normally run.
Questions victims ask
I only clicked the link and closed the page — am I safe?
Usually, yes. Modern browsers make drive-by infection from a mere click rare. Report it anyway: the URL helps security block it for everyone else, and they may want to check the device.
I have MFA on the account — does the stolen password matter?
Yes. Phishing kits increasingly proxy the real login page and capture your MFA code or session token live. Change the password and revoke sessions even with MFA enabled.
Will I get in trouble at work for this?
In a healthy organization, no — fast reporting is exactly what security teams ask of you. The person who reports in five minutes is the good story; the one who hides it for a week is the incident.