What to do when an employee clicks a real phishing link

A step-by-step first-hour response plan for when an employee clicks a real phishing link: contain, reset, check for damage, report, and turn the mistake into training.

An employee clicks a link in a phishing email, realises halfway down the fake login page that something is wrong, and walks over to tell you. What happens in the next hour decides whether that click costs you an afternoon or a quarter. The good news: most clicked links do not become breaches. The response — not the click itself — is what separates the two outcomes. This guide gives you the sequence, in order, with the reasoning behind each step so you can act without waiting for an IT background you do not need.

What to do when an employee clicks a real phishing link: the first hour

Work through these in order. Skipping step one is the most common mistake, and it is not a technical one.

1. Thank the person who told you — before anything else. The fastest way to make your next incident invisible is to punish the messenger. If the first response to a report is blame, the next person who clicks tells no one, and a quietly infected machine becomes a week-long cleanup instead of a ten-minute reset. Say plainly: reporting this was the right thing to do. You can review the mistake later, calmly, as a training topic rather than a disciplinary one.

2. Establish what actually happened. Ask three questions and write the answers down: Did you type your username or password into the page? Did you open or download any attachment? Did you reply, forward, or act on any instructions (especially payment or bank-detail instructions)? The click itself is rarely the damage — what followed the click is. A click with nothing entered and nothing opened is a very different incident from a captured password.

3. Disconnect the device — do not power it off. Unplug the network cable or switch off Wi-Fi. Pulling the network stops an active connection to an attacker's server; shutting the computer down can destroy evidence and interrupt something you want to see. If files suddenly start renaming themselves or the screen shows a ransom note, stop touching it and call your IT support immediately.

4. Reset the credentials — from a different device. If anything was typed into a phishing page, treat that password as stolen. Reset it from a phone or another computer, not the affected machine, and reset it everywhere the same password was reused (people reuse passwords; assume this one was reused). Revoke active sessions so the attacker is logged out of anything already signed in. If multi-factor codes were read out or approved, treat the account as compromised even after the password reset, and repeat the reset through your IT provider.

5. Check the mailbox for attacker persistence. Attackers who steal email credentials often leave a parting gift: a hidden forwarding or inbox rule that quietly copies your mail to them, or buries security alerts in a folder. In the affected mailbox, check Settings for forwarding rules and inbox rules the user did not create, and scan Sent Items for mail the user did not send. Delete any rule you find, then reset again.

6. Warn the rest of the staff the same day. A short note with a screenshot: this email is going around, it looks like this, do not click it, report it if you received it. Phishing campaigns usually hit many people at once, and the second and third victim often click hours after the first.

7. Report it externally where relevant. In Australia, report scams and incidents to Scamwatch, which feeds the National Anti-Scam Centre's pattern data. If customer personal information may have been taken, your privacy obligations under the Notifiable Data Breaches scheme may also apply — check with your advisor. If you carry cyber insurance, notify your insurer within the window your policy requires.

Quick reference: what happened, and what it demands

What happenedImmediate actionUrgency
Clicked the link, closed the page, entered nothingConfirm nothing was downloaded; monitor the device for a few daysLow
Typed credentials into a fake login pageReset password from another device, revoke sessions, check mail rulesImmediate
Opened an attachment or ran a fileDisconnect the device, IT support scan before it rejoins the networkImmediate
Approved an unexpected MFA promptTreat the account as compromised: reset, revoke, check rulesImmediate
Made a payment or changed bank detailsCall your bank's fraud line straight away; recovery odds drop by the hourCritical

What actually happens after a click, in plain English

Four things typically sit behind a phishing link, and knowing which one you faced tells you how worried to be.

How to tell whether the click caused real damage

In the days after the incident, watch for these signals and escalate the moment one appears:

None of these alone is proof of a breach, but each one moves the incident up a level. Silence is the good outcome.

Should the employee be in trouble? No.

This is worth its own section because the instinct is strong and it is wrong. The phishing email that fooled your employee was written by a professional whose full-time job is deception, and increasingly the spoofed brand (a bank, the ATO, your own managing director) is one your staff hear from every week. Punishing clickers teaches staff that reporting a click is more dangerous than hiding one — and hidden clicks are where breaches live. The metric that protects you is how fast a clicked email gets reported, and that number is built on trust, not fear. The productive version of accountability is the next section.

Making the next click less likely

A single click tells you where your training needs to go — which makes the response to a real click the same as the response to a simulated one:

FAQ

Should I shut the computer down?

No. Disconnect it from the network and leave it running. Powering off can destroy evidence, and you want your IT support to see the machine in the state the click left it.

The link was fake and asked for nothing. Do we still need to act?

Confirm nothing was downloaded, then monitor for the signals above for a week. An unentered click is usually a low-urgency incident — but it is still a training moment worth capturing while it is fresh.

How do we know if credentials were actually stolen?

Assume yes until proven otherwise. Resetting a password costs five minutes; discovering a compromised mailbox a month later does not. Check mail rules and sent items while you are in there.

Do we need to tell anyone outside the business?

Report scams to Scamwatch. If personal information of customers or employees may have been exposed, ask your advisor about Notifiable Data Breaches obligations. Insurers usually have notification windows — check your policy.

How do we stop this happening again?

You cannot eliminate clicks — attackers only need one lucky day. What you can build is a workforce that reports fast and clicks less every month: monthly phishing simulations, immediate remediation training after every click, and reporting that is one button, not a procedure.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.