An employee clicks a link in a phishing email, realises halfway down the fake login page that something is wrong, and walks over to tell you. What happens in the next hour decides whether that click costs you an afternoon or a quarter. The good news: most clicked links do not become breaches. The response — not the click itself — is what separates the two outcomes. This guide gives you the sequence, in order, with the reasoning behind each step so you can act without waiting for an IT background you do not need.
What to do when an employee clicks a real phishing link: the first hour
Work through these in order. Skipping step one is the most common mistake, and it is not a technical one.
1. Thank the person who told you — before anything else. The fastest way to make your next incident invisible is to punish the messenger. If the first response to a report is blame, the next person who clicks tells no one, and a quietly infected machine becomes a week-long cleanup instead of a ten-minute reset. Say plainly: reporting this was the right thing to do. You can review the mistake later, calmly, as a training topic rather than a disciplinary one.
2. Establish what actually happened. Ask three questions and write the answers down: Did you type your username or password into the page? Did you open or download any attachment? Did you reply, forward, or act on any instructions (especially payment or bank-detail instructions)? The click itself is rarely the damage — what followed the click is. A click with nothing entered and nothing opened is a very different incident from a captured password.
3. Disconnect the device — do not power it off. Unplug the network cable or switch off Wi-Fi. Pulling the network stops an active connection to an attacker's server; shutting the computer down can destroy evidence and interrupt something you want to see. If files suddenly start renaming themselves or the screen shows a ransom note, stop touching it and call your IT support immediately.
4. Reset the credentials — from a different device. If anything was typed into a phishing page, treat that password as stolen. Reset it from a phone or another computer, not the affected machine, and reset it everywhere the same password was reused (people reuse passwords; assume this one was reused). Revoke active sessions so the attacker is logged out of anything already signed in. If multi-factor codes were read out or approved, treat the account as compromised even after the password reset, and repeat the reset through your IT provider.
5. Check the mailbox for attacker persistence. Attackers who steal email credentials often leave a parting gift: a hidden forwarding or inbox rule that quietly copies your mail to them, or buries security alerts in a folder. In the affected mailbox, check Settings for forwarding rules and inbox rules the user did not create, and scan Sent Items for mail the user did not send. Delete any rule you find, then reset again.
6. Warn the rest of the staff the same day. A short note with a screenshot: this email is going around, it looks like this, do not click it, report it if you received it. Phishing campaigns usually hit many people at once, and the second and third victim often click hours after the first.
7. Report it externally where relevant. In Australia, report scams and incidents to Scamwatch, which feeds the National Anti-Scam Centre's pattern data. If customer personal information may have been taken, your privacy obligations under the Notifiable Data Breaches scheme may also apply — check with your advisor. If you carry cyber insurance, notify your insurer within the window your policy requires.
Quick reference: what happened, and what it demands
| What happened | Immediate action | Urgency |
|---|---|---|
| Clicked the link, closed the page, entered nothing | Confirm nothing was downloaded; monitor the device for a few days | Low |
| Typed credentials into a fake login page | Reset password from another device, revoke sessions, check mail rules | Immediate |
| Opened an attachment or ran a file | Disconnect the device, IT support scan before it rejoins the network | Immediate |
| Approved an unexpected MFA prompt | Treat the account as compromised: reset, revoke, check rules | Immediate |
| Made a payment or changed bank details | Call your bank's fraud line straight away; recovery odds drop by the hour | Critical |
What actually happens after a click, in plain English
Four things typically sit behind a phishing link, and knowing which one you faced tells you how worried to be.
- A credential capture page. A clone of your Microsoft 365, Google or bank login. Whatever is typed is sent to the attacker, and the page often then forwards you to the real site so you notice nothing. This is the most common outcome of a clicked link.
- Malware. An attachment or download that installs software the attacker controls — anything from a password stealer to ransomware. Well-configured endpoint protection and email filtering catch most of it, which is exactly why the ones that land are the crafted ones.
- An app approval request. Instead of stealing a password, the page asks the employee to approve an app that wants access to their email or files. There is no password to reset because none was stolen — the access persists until the grant is revoked, which makes this variant easy to miss.
- Payment redirection. No malware at all. The email impersonates a supplier changing bank details, or a manager authorising an urgent payment. The damage is financial and starts the moment the transfer clears.
How to tell whether the click caused real damage
In the days after the incident, watch for these signals and escalate the moment one appears:
- Multi-factor prompts arriving when nobody is logging in
- Password reset emails nobody requested
- Colleagues receiving messages that appear to come from the affected account
- Inbox or forwarding rules the user did not create
- Unexpected transactions, new payees, or changed bank details
- An account locking out, or login alerts from unfamiliar locations
None of these alone is proof of a breach, but each one moves the incident up a level. Silence is the good outcome.
Should the employee be in trouble? No.
This is worth its own section because the instinct is strong and it is wrong. The phishing email that fooled your employee was written by a professional whose full-time job is deception, and increasingly the spoofed brand (a bank, the ATO, your own managing director) is one your staff hear from every week. Punishing clickers teaches staff that reporting a click is more dangerous than hiding one — and hidden clicks are where breaches live. The metric that protects you is how fast a clicked email gets reported, and that number is built on trust, not fear. The productive version of accountability is the next section.
Making the next click less likely
A single click tells you where your training needs to go — which makes the response to a real click the same as the response to a simulated one:
- Run phishing simulations monthly, with templates modelled on the scams actually circulating, so staff learn to recognise the tactic rather than one fake email. Cyber Aware's benchmark for monthly programmes is an average 80% reduction in clicked links by month eight.
- Auto-enrol anyone who clicks into a short remediation course the same week — five to ten minutes on the exact tactic that caught them, not an annual refresher. Cyber Aware's phishing simulations do this automatically after every campaign.
- Track report rate, not just click rate. A rising report rate is the earliest evidence the culture is working; human risk reporting shows the trend per person per month.
- Celebrate reporters. The employee who reports a real phishing email has just protected every colleague behind them on the recipient list. Treat that as the win it is.
FAQ
Should I shut the computer down?
No. Disconnect it from the network and leave it running. Powering off can destroy evidence, and you want your IT support to see the machine in the state the click left it.
The link was fake and asked for nothing. Do we still need to act?
Confirm nothing was downloaded, then monitor for the signals above for a week. An unentered click is usually a low-urgency incident — but it is still a training moment worth capturing while it is fresh.
How do we know if credentials were actually stolen?
Assume yes until proven otherwise. Resetting a password costs five minutes; discovering a compromised mailbox a month later does not. Check mail rules and sent items while you are in there.
Do we need to tell anyone outside the business?
Report scams to Scamwatch. If personal information of customers or employees may have been exposed, ask your advisor about Notifiable Data Breaches obligations. Insurers usually have notification windows — check your policy.
How do we stop this happening again?
You cannot eliminate clicks — attackers only need one lucky day. What you can build is a workforce that reports fast and clicks less every month: monthly phishing simulations, immediate remediation training after every click, and reporting that is one button, not a procedure.