If you clicked a phishing link: disconnect the device from the network, tell IT or your manager immediately, change your password for any account you typed into (starting with your email), revoke active sessions and check for forwarding rules. A click without data entered is usually recoverable in minutes; a password you typed on a fake login page starts a clock measured in minutes too, which is why speed matters more than embarrassment.
TL;DR
- The first hour decides the damage: report before you troubleshoot.
- Change the password of any account whose credentials you entered, and revoke active sessions.
- Check mailbox rules and app access — attackers set forwarding to intercept future mail.
- MFA on the account does not make the click harmless; reset and revoke anyway.
- Australia's average small-business cybercrime incident costs $56,571 (ASD 2024-25) — most of that cost follows a slow response.
What to do if you clicked a phishing link
Work through these steps in order, whether you clicked, entered a password, opened an attachment or sent money:
- Report first. Use your report-phishing button or contact IT now, and say exactly what happened: "I clicked and entered my password at 10:14." Nobody credible will fire you for speed; late silence is what turns an incident into a breach.
- Disconnect if something was downloaded. If an attachment opened or a file downloaded, turn off Wi-Fi or unplug the network cable and leave the machine on for IT to inspect.
- Change the password — from a different device. If you entered credentials anywhere, change that account's password on a device the attacker has not touched, then revoke active sessions in the account's security settings. Start with email: whoever controls your mailbox can reset everything else.
- Check for forwarding rules and new app access. Open the mailbox rules settings and delete any rule you did not create — attackers use forwarding to keep reading your mail after you change the password. Review connected applications and remove the unfamiliar ones.
- Contact your bank if money moved. Payment sent to the wrong account: call the bank immediately, preserve the transaction details, and report it. Speed is the only thing that recalls a transfer.
- Report the scam externally. Scam attempts go to the Scamwatch reporting form; suspected cybercrime goes to Australia's ReportCyber service. Neither replaces your internal containment steps — do those in parallel, not after.
Why the first hour matters
Roughly 60% of data breaches involve a human element — an error, a clicked link or a manipulated employee (Verizon, 2025 DBIR). What separates a near-miss from a reportable breach is almost always time: a password changed within minutes closes the door the attacker was still walking through, while one changed tomorrow arrives after the mailbox rules, the email to your customers and the supplier invoice fraud are already done.
In Australia the average self-reported cost of cybercrime to a small business is $56,571 per incident, up 14% year on year (ASD, Annual Cyber Threat Report 2024-25). Most of that cost is downstream cleanup that a fast report prevents.
What changes by what you did
| What you did | What matters most |
|---|---|
| Clicked only | Report it; watch the device for odd behaviour; no password change needed unless you typed something |
| Entered a password | Password change from another device, revoke sessions, check mailbox rules |
| Opened an attachment | Disconnect the device, leave it on, let IT investigate |
| Approved an MFA prompt | Deny further prompts, change the password, revoke sessions — approval means the attacker is in |
| Sent money | Bank immediately, then everything above |
How training turns this reflex into a habit
The response above works only if people follow it under pressure, and people follow it under pressure only when they have practised. Teams that run regular phishing simulations treat a click as a drill they have rehearsed: the report goes out in the first minutes, and the remediation list is muscle memory. Before any training, 33.2% of employees are likely to engage with a malicious email; twelve months of continuous security awareness training and simulation cuts that to 4.2% (KnowBe4, 2026). The click you just made is exactly the event that training is built to shrink — reporting it makes you part of that metric instead of the exception.
FAQ
I clicked a phishing link but entered nothing. Am I safe? Almost certainly. Change nothing urgent, but report it so IT can watch the device and warn colleagues who received the same email.
I entered my password on a fake login page. What now? Change the password from a different device, revoke active sessions, check mailbox forwarding rules and connected apps, and report it. Do this within minutes, not tomorrow.
I have MFA on that account. Does that make it safe? No. Attackers relay MFA in real time or wear you down with prompts until you approve. Change the password and revoke sessions anyway.
Should I delete the email? No. Keep it for IT — the headers and links help them block the sender and find other recipients.
Do I have to tell my manager if nothing bad happened? Yes. Reports without consequences build the reporting habit the whole programme depends on; silence is the behaviour that costs $56,571.
Who do I report to outside the company? Scamwatch for scam attempts, ReportCyber for cybercrime or a security incident — both links above.
One last thing
The most valuable sentence in this article is the one you say out loud: "I clicked and entered my password at 10:14." Say it fast and the incident ends as a training anecdote. Say it tomorrow and it ends as a breach report.