Insights

Clicked a Phishing Link? Do This Now

A step-by-step response plan for the first hour after a phishing click — password resets, session revocation, inbox rules, and when to call for help.

Someone on your team clicked a link they shouldn't have — or worse, typed their password into a page that looked exactly like Microsoft 365. What you do in the next hour matters more than what the attacker did. Here's the playbook.

First: no blame, fast reporting

The most dangerous phishing click is the one nobody reports. If your culture punishes the person who clicked, the next incident stays hidden until it's a breach. Make it loudly known: reporting fast is the win condition.

The first hour

  • Change the password immediately — from a different, known-clean device. If that password is reused anywhere else, change it there too.
  • Sign out all sessions: Attackers often keep an active session even after a password change. Microsoft 365 and Google Workspace both support forced sign-out everywhere.
  • Check inbox rules: Attackers commonly plant mail-forwarding or auto-delete rules to hide their activity. Delete anything unfamiliar.
  • Watch for MFA prompts: Unexpected authentication requests mean the attacker is actively trying the stolen credentials. Deny and report.
  • Tell your IT provider or team now, not after lunch. Containment tools — session revocation, device isolation, sign-in log review — work best in the first hour.

What your IT team should be doing

Beyond the immediate cleanup: reviewing sign-in logs for unfamiliar locations and devices, checking whether anything was forwarded or downloaded, confirming no new app permissions or account delegations were granted, and screening for the same message across every other inbox in the organization — phishing rarely targets just one person.

Making the next click a non-event

Layered defenses turn this from a crisis into a logged incident: email security that stops most malicious messages before delivery, endpoint detection that catches what runs after a bad click, a 24/7 response team watching identity sign-ins, dark web monitoring for credentials that leak anyway, and ongoing phishing training so fewer messages get clicked in the first place.

If you're reading this mid-incident and don't have a response team, call us at (844) 247-5227 — the emergency line is answered.

Have questions about your situation?

Talk to our team — we'll give you a straight answer, even if the answer isn't AIS.