Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays connect@crossrivertechnology.com

IT emergencies

Someone clicked a phishing email: what to do next

How bad it is depends entirely on what happened after the click. Here is the response for each scenario, in order, and how to handle the conversation with the person who clicked.

Written and reviewed by Anthony Omini, Cross River Tech·12 min read·Published

An employee clicked a phishing link, what now?

First find out what actually happened: a click only, a password typed in, an attachment opened, or a login prompt approved. A click alone is usually harmless. A typed password means resetting it and signing that account out everywhere immediately, then checking mailbox rules and sign-in history. Do not scold the person, because the next one needs to report it faster. In Dallas I can check a tenant the same day.

Answered by Anthony Omini, Cross River Tech, Dallas

Hands typing on a backlit laptop keyboard in low light

Key takeaways

  • The click itself is rarely the problem; what matters is whether credentials were typed, a file was opened, or a sign-in prompt was approved.
  • If a password was entered, reset it and sign the account out of every session before doing anything else.
  • Check mailbox rules and recent sign-in activity, because a forwarding rule is how a quiet compromise pays for itself.
  • Look at everyone, not just the person who reported it, since the same message almost always went to several mailboxes.
  • Thank the person who told you. An office where people hide clicks is far more dangerous than one where they report them.

An employee clicked a phishing link, what now?

Establish what happened after the click before you do anything else, because the response is completely different for each case. Someone who clicked and closed the page has done almost nothing. Someone who typed their email password into it has handed over an account. Take two minutes to ask, calmly, and get a truthful answer, which you only get if the person is not afraid of the conversation.

Ask these questions, in this order:

  1. Did you only click, or did a page ask you to sign in?
  2. If it asked, did you type your password? Which password, and is it used anywhere else?
  3. Did your phone show an approval prompt afterwards? Did you tap approve?
  4. Did you download or open a file? What kind of file, and did anything ask permission to run?
  5. Did anything ask you to call a phone number, or to install remote support software?
  6. When did this happen, and roughly what time?
  7. Has anything odd happened since: missing emails, a strange reply, a colleague asking about a message you did not send?

Write the answers down with the time. If the answer to two, three or five is yes, treat it as an account compromise and move immediately to the relevant section below. If it is a click and nothing more, you still check, but you can breathe. Either way, do not spend the first ten minutes trying to work out who sent it; containment first, investigation second.

If the account belongs to someone who can move money, sign documents or reach client data, raise the urgency regardless of how harmless the click sounded, and consider getting help on the phone while you work through the steps.

How serious is clicking a phishing email?

On its own, usually not serious at all, because opening a web page rarely does anything by itself on a patched, protected computer. Seriousness is created by the four things that can happen next, and they escalate sharply.

What happenedHow seriousWhat is at riskResponse time
Clicked, page loaded, closed itLowLittle, if the machine is patched and protectedCheck the same day
Typed email password into the pageHighMailbox, files, everything using that sign-inImmediately
Approved a sign-in prompt on the phoneHighThe account, and the second factor itselfImmediately
Opened an attachment that asked to enable contentHighThe computer, then everything it can reachImmediately, disconnect the machine
Downloaded a file but did not open itLow to mediumNothing yet, but the file must goSame day
Called the number in the emailMedium to highWhatever was said, plus any remote access grantedImmediately
Installed remote support software they were told toVery highThe whole machine, in someone else's handsDisconnect it now
Replied with informationMediumDepends what was sent, often used for the next attackSame day, warn finance

One general rule cuts through most of the panic: attackers want either credentials or money. Almost every message aimed at a small business is trying to get someone to sign in to a fake page, or to change where a payment goes. If neither happened, you are probably fine. If the message was about an invoice or bank details rather than a login, treat it as attempted payment fraud instead, which is covered in a supplier changed their bank details by email.

What if they only clicked the link and nothing else?

Verify the machine is clean, delete the message across the office, and treat it as a near miss worth learning from. There is real work here, just not urgent work, and skipping it is how the second attempt succeeds.

  1. Run a full scan with your managed endpoint protection on that computer and look at the result rather than assuming.
  2. Check the computer is fully up to date, since exploitation through a browser needs something unpatched to exploit.
  3. Search every mailbox for the same message and remove it, because it was almost certainly not sent to just one mailbox.
  4. Block the sender and the linked domain in your email filtering.
  5. Report the message to your filtering vendor so the pattern is recognized next time.
  6. Check the sign-in history for that account anyway. It costs a minute and occasionally surprises you.
  7. Tell the office what the message looked like, in plain language, with no names attached.

Step three is the one people skip. A phishing campaign aimed at a small office typically lands in several mailboxes at once, and the person who reported it is usually the most alert person in the building rather than the only recipient. Somebody quieter may have clicked and said nothing, so search and remove rather than relying on reports.

If the message got through your filtering and looked convincing, that is a signal about the filtering rather than about your staff. Anti-phishing settings, external sender marking and impersonation protection are all included in Microsoft 365 and Google Workspace business plans, and they are frequently left at their defaults. The settings worth reviewing are in Microsoft 365 security for a small business.

What if they typed their password into it?

Treat the account as compromised and act in a fixed order, because minutes matter here and improvising costs you some of them. The attacker's first move after harvesting a password is usually to sign in, create a hidden mailbox rule and start reading, and the rule survives a password change unless you go and remove it.

  1. Reset the password. A new, unique one, not a variation of the old one.
  2. Sign the account out of every session. This is the step people miss. A password change alone does not always end an active session, and the attacker stays signed in until you revoke it.
  3. Check multi-factor authentication is on and untampered. Look for an extra phone number, an extra authenticator or an app password that was added.
  4. Check mailbox rules. Look for anything forwarding, deleting or moving mail to a rarely used folder, and for external forwarding on the mailbox itself.
  5. Review sign-in activity. Look at locations, addresses and devices for the last week, not just today.
  6. Check what else used that password. If it was reused on the bank, the practice software or a vendor portal, change those now too.
  7. Check sent items and deleted items. Attackers send from compromised accounts and then delete the evidence.
  8. Warn anyone who might receive a message from that account, especially clients and anyone who pays invoices.
  9. Look at the other accounts in the office for the same signs, since one harvested password often means several.

Steps two and four are what separate a contained incident from one that quietly continues. I have seen a mailbox rule sit in place for months, silently moving every message containing the word invoice into a folder nobody opens, while the attacker waited for a large payment to be discussed. If you find evidence of that, or of messages sent from the account, you are past a phishing click and into an email compromise, and the full first-hour sequence is in business email hacked: the first hour.

What if they opened an attachment?

Disconnect that computer from the network first and ask questions afterwards, because an attachment that runs something is the one scenario that can spread to the rest of the office. Unplug the network cable and switch off the Wi-Fi. Leave the machine powered on, since powering off can destroy evidence and does not undo anything already done.

  1. Disconnect from the network, leave the power on, and stop using it.
  2. Note exactly what the file was called and what happened when it opened. A prompt to enable content or enable editing is a strong signal that it tried to run something.
  3. Run a full scan from your managed security console rather than from the machine itself where possible.
  4. Check whether the person's account signed in anywhere unexpected, in case credentials were taken from the machine.
  5. Check the file server and shared folders for unusual changes, renamed files or new files that appeared at that time.
  6. Confirm your backups are intact and that the most recent copy predates the incident, and pause any backup job that might overwrite good copies with bad ones.
  7. Decide with your provider whether the machine can be cleaned or should be rebuilt from scratch.

Rebuilding is often the honest answer for anything that genuinely executed, because trusting a cleaned machine means trusting that the cleaning found everything. A rebuild is a few hours of work when the office has proper documentation and a standard build, which is one of the quieter arguments for having both.

If files start becoming unreadable or you see ransom messages, stop following this list and move to the ransomware response, which prioritises isolating the network and protecting backups above everything else. That sequence is in ransomware in a small business. Backup design that survives this kind of event is described on the cybersecurity, backup and disaster recovery page.

What if they approved a multi-factor prompt they did not expect?

Treat this exactly like a stolen password, because it means the attacker already had the password and has now got past the second factor too. This scenario is more common than people realise: someone receives repeated approval prompts, assumes a glitch, and taps approve to make them stop.

  1. Reset the password immediately and revoke every active session.
  2. Remove and re-register the person's authentication methods, so any method the attacker added is destroyed.
  3. Check for newly registered devices, phone numbers, authenticator apps or app passwords on the account.
  4. Check for mailbox rules and forwarding, as with any credential compromise.
  5. Review sign-in history for successful sign-ins from unfamiliar locations.
  6. Check whether the account holds any administrator role, and if so treat every account in the tenant as suspect.
  7. Switch on number matching for approvals, so a prompt cannot be accepted without a code shown on the screen the person is actually looking at.

Step seven prevents this whole category. With number matching, an approval requires typing a two-digit number displayed on the sign-in screen, so a prompt arriving out of nowhere cannot be approved by reflex. It is a setting rather than a purchase, and it is now the default in newer configurations, though plenty of older setups never had it turned on.

Tell staff the rule in one sentence they will remember: if a prompt appears and you were not signing in at that exact moment, deny it and tell somebody. Unexpected prompts are not glitches. They mean somebody has your password.

How do we check for mailbox rules and unfamiliar sign-ins?

Look in three places for every affected account: the rules in the mailbox, the forwarding settings on the mailbox, and the sign-in history for the account. Together they answer whether anyone else has been in there, and they are the same checks whichever email platform you use.

What to checkWhat a normal setup looks likeWarning signs
Inbox rulesA few rules the user recognises and can explainRules with blank or single-character names, rules that delete or move mail to Archive or RSS folders
Rule keywordsProject names, newsletters, sendersWords like invoice, payment, bank, wire, password, security alert
Mailbox forwardingOff, or to a colleague during leaveForwarding to an outside address nobody recognises
Sign-in historyFamiliar cities, familiar devicesSuccessful sign-ins from unexpected places, or many failures then one success
Registered authentication methodsThe user's own phone or appAn extra phone number or an authenticator the user cannot account for
Connected applicationsTools the office actually usesAn unfamiliar application granted access to mail
Sent and deleted itemsWhat the user recognisesMessages they did not send, or an emptied deleted folder

Do these checks for every mailbox in the office if more than one mailbox received the message, not only for the person who spoke up. Where you have the tools, a search across all mailboxes for suspicious rule patterns takes less time than checking three accounts by hand, and it is the sort of routine review that belongs on a monthly rhythm rather than only after an incident. Ongoing administration of these settings sits under Microsoft 365 and Google Workspace support.

Keep a record of what you found, including the nothing-found results, with dates. If a cyber-insurance question or a client asks later how you handled it, that record is the answer, and it is also the evidence trail carriers look for. The related questionnaire items are covered in your cyber-insurance questionnaire came back short.

What do we say to the employee, and to everyone else?

Thank the person, out loud and without qualification, because the speed of the next report depends on how this one is treated. An employee who is embarrassed today is an employee who says nothing next time, and silence is what turns a click into a month-long compromise. The most damaging phishing incidents I have seen were not the cleverest emails; they were the ones nobody mentioned for a week.

A sequence that works:

  1. To the person, immediately: thank them for telling you, say that this is exactly what you want people to do, and explain what happens next.
  2. While fixing it: keep them informed rather than shutting them out, and never discuss it with colleagues as though it were a failing.
  3. To the office, within a day: describe what the message looked like, no names, no blame, and say clearly that reporting is always right.
  4. To finance, specifically: remind them that any change to payment details gets verified by phone on a number already on file.
  5. A week later: a short review of what would have caught it earlier, aimed at systems rather than people.
  6. Regularly after that: short, frequent reminders beat an annual training session nobody remembers.

Say the standing rule out loud so people can act on it: you will never be in trouble for reporting a click, and you will never be asked to judge whether something is serious enough to mention. That is somebody else's job. A small office that treats reports as helpful rather than embarrassing gets its warnings early, which is worth more than most of the software you could buy.

When do we need outside help, and who do we call in Dallas?

Call for help as soon as credentials were entered, a prompt was approved, an attachment ran, or an administrator account is involved, because those cases need somebody who can see the whole tenant rather than one mailbox. A click and nothing else can be handled in-house if you can run the checks above properly.

SituationHandle it yourselfGet help
Click only, machine patched and protectedYes, with the checks aboveIf anything looks unusual afterwards
Password enteredOnly if you can revoke sessions and audit rulesYes, same day
Approval prompt acceptedNoYes, immediately
Attachment opened and ranNoYes, immediately, machine off the network
Administrator account involvedNoYes, treat the whole tenant as suspect
Money already sentNoBank first, then your provider, then the authorities
Client or patient data possibly exposedNoYes, and speak to your attorney about notification duties

What I do in these cases: check sign-in activity and rules across every mailbox, revoke sessions, reset and re-register authentication, remove anything the attacker added, search and purge the message from the office, tighten the filtering that let it through, and give you a written record of what was found and changed. I am Anthony Omini, owner of Cross River Tech and the person you deal with directly, with over 15 years of IT experience across many industries. I support small businesses onsite across Dallas–Fort Worth and remotely anywhere in Texas, and this kind of work is almost entirely remote, which means it can start as soon as we talk.

Hourly help is available at published break/fix rates with no contract and a one-hour minimum. For offices that would rather not be doing this reactively, a month-to-month managed plan puts the filtering, the account reviews, the security software and the training on a routine. If a message got through and somebody clicked it, tell me what happened and when, and I will tell you what to check first.

Questions people ask

How serious is clicking a phishing email?

By itself, usually not serious. Loading a web page rarely does anything on a patched computer with working security software. What makes it serious is what came next: typing a password into the page, approving an unexpected sign-in prompt, opening an attachment that asked to enable content, or installing remote access software. Any one of those means treating the account or the machine as compromised straight away.

What do I do after a phishing attack at work?

Work in order: establish what happened, contain, then investigate. If a password was entered, reset it and revoke every active session. Check mailbox rules, forwarding and sign-in history. Search all mailboxes for the same message and remove it. Scan and, if an attachment ran, isolate the machine. Then write down what you found, tell the office what the message looked like, and thank whoever reported it.

Does changing the password fix it?

Not on its own. An attacker who is already signed in can stay signed in after a password change until the sessions are revoked, and any mailbox rule or forwarding they created keeps working regardless. Reset the password, sign the account out everywhere, remove and re-register the authentication methods, then hunt for rules, forwarding, unfamiliar registered devices and connected applications.

How do I know if anything was actually stolen?

Look at sign-in history for successful sign-ins from unfamiliar locations or devices, check sent and deleted items for messages nobody wrote, and look for mailbox rules or forwarding that hide replies. Also check whether any files were downloaded from your cloud storage around that time. Absence of evidence is not certainty, which is why the safest assumption after credentials are entered is that someone got in.

Should we tell clients about it?

That depends on whether their information was exposed, and it is a legal question as much as a technical one. If an account that holds client or patient records was accessed, or messages were sent to clients from it, speak to your attorney about notification duties before deciding. What is always worth doing is warning anyone who might receive a fraudulent message from the account, particularly people who pay invoices.

How do we stop this happening again?

Layer a few cheap things rather than buying one expensive one. Multi-factor authentication on every account with number matching enabled, anti-phishing and external sender warnings switched on in your email platform, managed endpoint protection everywhere, and short, frequent staff reminders instead of an annual session. Then add the human rule that matters most: reporting a click is always welcome and never punished.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Somebody clicked, and you are not sure how bad it is? Tell me what happened and roughly when. Most of these checks are remote, so I can look at the account rather than guessing with you.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080