It happens to careful, sensible people: an email looked legitimate, someone clicked, and a login page asked for their Microsoft password — and they typed it in before the penny dropped. If that's where you are right now, take a breath. What matters most isn't how it happened; it's what you do in the next few minutes. Work through this in order.
1. Change that password — from a different device
Right away, change the password for the account whose details were entered. If you can, do it from a phone or another computer, not the one that clicked — and if the same password is used anywhere else (it shouldn't be, but often is), change it there too. This alone slams the most important door.
2. Turn on two-factor authentication
If the account doesn't already have two-factor (also called MFA) switched on, turn it on now. Even if an attacker has the password, two-factor stops them getting in without the second code on your phone. If it's already on, that's genuinely good news — it may have blocked them already.
3. Sign out everywhere
Changing the password doesn't always kick out someone who's already signed in. There's an option to sign out of all sessions on all devices — use it, so any active intruder is booted immediately.
4. Check for sneaky inbox rules
This is the step people miss. A common attacker trick is to quietly add a rule that forwards or hides certain emails — so they can keep reading replies, or hide their own scam messages from you. Have someone check the mailbox's rules and forwarding settings for anything you didn't set up, and remove it.
How to tell if they actually got in
Often nobody's sure whether the password was really captured, or whether it even mattered. A few signs point to a genuine break-in, and they're worth checking calmly:
- A sign-in from a city, country, or device the person never uses
- Emails vanishing from the inbox, or being marked read on their own
- Colleagues or customers receiving messages the person never sent
- A new mailbox rule that forwards or deletes certain emails
- Password-reset or security-code messages nobody asked for
See any of those, and treat the account as compromised and work through the steps above. See none, and you've still lost nothing by changing the password and turning on two-factor — that's the cheap insurance.
5. Tell your IT person — and your team
Loop in whoever looks after your technology so they can confirm the account is clean and watch for anything odd. And give the team a quick heads-up: a compromised account is often used to email colleagues and contacts, so a 'if you get a strange message from me, ignore it' note prevents the problem spreading.
One thing not to do: don't power off the computer in a panic. It won't help, and the steps above — which lock down the account itself — are what actually matter.
The traps worth knowing
The 'approve this sign-in?' prompt you didn't start
If someone already has a password, they'll sometimes trigger a stream of two-factor prompts to your phone, hoping you'll tap 'approve' out of habit or annoyance — a trick known as MFA fatigue. The rule is simple: if a sign-in prompt appears that you didn't start, never approve it, and change that password. An unexpected prompt is itself a sign someone has the password and is knocking on the door.
The attachment that isn't what it looks like
Plenty of scams skip the link and lean on a file instead: an .htm attachment that opens a fake login page from your own computer, a 'voicemail' or 'fax' that won't play normally, or a note about CAD drawings or an invoice you simply must download. If a file needs you to log in after opening it, or nags you to enable something, stop — that's the tell. When in doubt, don't open it; forward it to whoever handles your IT and let them look.
How to spot the next one
The habit that prevents most break-ins is a half-second of 'was I expecting this?' These are the red flags worth teaching the whole team:
| Red flag | Why it's used | What to do |
|---|---|---|
| Urgency or a threat ('act now, account closing') | Panic makes people skip the check | Slow down; verify through a known channel |
| A login link in the email itself | Sends you to a lookalike page | Go to the site directly, never via the link |
| A slightly-wrong sender address or domain | Impersonates a brand or colleague | Check the full address, not just the name |
| An unexpected attachment or 'voicemail' | Hides a fake login or malware | Don't open it; forward to IT |
| A request to change payment details | Redirects your money to the scammer | Confirm by phone using a known number |
The five-minute habits that prevent most of this
You can't buy your way out of phishing with a single gadget, but a few cheap habits stop the large majority of it before it ever starts. None of these is technical or expensive:
- Turn on two-factor for every account that offers it — it's the single biggest win, and it's free
- Use a password manager so no password is ever reused across sites
- Give the team a two-second 'was I expecting this?' rule for links and attachments
- Agree that any change to payment or bank details is confirmed by phone, never by email alone
- Keep a known contact for whoever handles your IT, so a worried person can ask straight away
Together, these turn 'someone clicked a link' from a genuine crisis into a two-minute reset. The goal isn't to make anyone feel foolish for clicking — it's to build a calm reflex so the occasional slip does no real harm.
What happens after you call us
When a client hits this, we confirm the account is genuinely clean rather than just hoping — reviewing recent sign-ins, hunting for hidden forwarding rules, making sure two-factor is on properly, and checking nobody else was reached. If it did spread, we help contain it. It's usually a short job, and knowing it's actually closed, not just probably fine, is the whole point.