Safeguard Desk
Response Playbooks

What to Do After an Employee Clicks a Phishing Link

What to Do After an Employee Clicks a Phishing Link
An employee clicking a phishing link requires immediate action within 30–60 minutes: disconnect the device, change passwords from a separate device, enable MFA, check for email forwarding rules in Microsoft 365 or Google Workspace, and scan for malware to contain the breach before attackers can pivot.

An employee clicks a link in a phishing email. They may realize it immediately or only after something looks wrong. Either way, the next 30–60 minutes matter more than most people think.

The goal is not to assign blame. The goal is to limit damage quickly and cleanly. This playbook is written for small teams that do not have a security operations center or an on-call incident responder.

First 5 Minutes: Contain the Immediate Risk

Documentary style photo of an office employee quickly disconnecting internet access on a laptop to contain risk.
  1. Stay calm and tell the right person
    The employee should immediately message or call whoever handles IT or operations (owner, office manager, or designated lead). Do not wait until the end of the day.

  2. Disconnect if anything seems active
    If the browser is behaving strangely, new windows keep opening, or the system feels slow or locked, turn off Wi-Fi or unplug the network cable. If necessary, shut the laptop down. The priority is stopping further communication with the attacker’s server.

  3. Do not enter any more credentials

    If the page is asking for a password, MFA code, or payment information, close it. Do not try to “log in again to check.”

Next 15–30 Minutes: Secure the Accounts

Documentary style photo of colleagues securing accounts and resetting passwords from a separate device.
  1. Change the password on the affected account from a different device
    Use a phone or another computer that was not involved. If the phishing page targeted email or Microsoft 365 / Google Workspace, reset that password first. Make the new password unique and store it in the company password manager.

  2. Enable or verify multi-factor authentication
    Confirm MFA is turned on. If the attacker may have added their own MFA method, remove unknown devices or authenticator entries.

  3. Check for forwarding rules and suspicious inbox rules
    In email, look for rules that automatically forward messages or move them to hidden folders. Attackers often set these so they continue to receive mail after the password is changed. Delete any rules that were not created by the team.

  4. Review recent account activity
    Check sign-in logs or recent activity for unfamiliar locations, devices, or times. Most major platforms (Microsoft 365, Google, common banking and SaaS tools) provide this information under security or account settings.

  5. Sign out other sessions
    Use the “sign out of all other devices” or equivalent option where available.

Next 30–60 Minutes: Assess Broader Exposure

  1. Determine what was entered
    Ask the employee exactly what they typed or clicked. Did they only click the link? Did they enter a password? An MFA code? Banking details? The answer changes the severity.

  2. Scan the device
    Run a full scan with your company antivirus or endpoint protection tool. If the device shows signs of infection or you lack confidence in the scan, treat the machine as compromised and plan to wipe and rebuild it.

  3. Check related accounts
    If the same password was reused elsewhere (a common problem), change those passwords too. This is why unique passwords and a password manager matter.

  4. Notify your bank or payment processors if financial data was involved
    Call them directly using a trusted number, not a number from the suspicious email. Ask them to flag the account and watch for unusual activity.

Communication and Documentation

  1. Tell only the people who need to know
    Keep the circle small at first: the affected employee, the operations/IT lead, and ownership if the risk is significant. Avoid company-wide panic emails until you understand the scope.

  2. Write down what happened while it is fresh
    Note the time of the click, the approximate sender and subject line, what was entered, which accounts were reset, and what actions were taken. A short internal note is enough. This record helps if further investigation or insurance questions arise later.

  3. Preserve the email if possible
    Do not delete the original phishing message yet. Move it to a safe folder or take screenshots. It may be useful for understanding the attack or reporting it.

After the Immediate Response

  1. Decide whether the device needs to be wiped
    If credentials were entered and the device showed any odd behavior, the safest path is usually to back up clean personal files, wipe the machine, and set it up again using your standard new-employee checklist.

  2. Review how the email got through
    Was it a new domain that looked similar to a real vendor? Did it come from a compromised customer or partner account? Use the answer to tighten basic filters or remind the team of specific red flags.

  3. Update the team with a short, factual note
    Once the situation is contained, send a brief message: what happened at a high level, what staff should watch for, and a reminder not to enter credentials from unexpected emails. Keep the tone practical, not alarming.

What Not to Do

  • Do not ignore it because “nothing obvious happened.”

  • Do not have the employee keep using the same computer without checking it.

  • Do not reset passwords from the potentially compromised device.

  • Do not pay any ransom or follow instructions from the attacker.

  • Do not wait days to act because everyone is busy.

Prevention Link

Every phishing incident is also feedback. After the dust settles, ask:

  • Did the employee have MFA turned on before the incident?

  • Was the password unique or reused?

  • Is our new-employee setup checklist consistently applied?

  • Do we have a simple way for people to report suspicious emails quickly?

Fixing those gaps reduces the chance of a repeat.

Final Note

Clicking a phishing link is common. The difference between a minor event and a serious incident is usually the speed and clarity of the response. A short, practiced sequence—contain, reset, check, document—keeps most events manageable for small teams.

Secure enough includes knowing exactly what to do in the first hour.

Updated · 2026-09-05 11:42
Feedback

No feedback yet — submit the first.

Submit feedback
© 2026 Safeguard Desk. All rights reserved. data-driven, published weekly