Skip to main content

IT Support

Someone clicked a phishing link — what to do in the next 10 minutes

A teammate clicked a bad link and maybe entered their password. Don't panic — the next few minutes matter far more than how it happened. Here's the calm checklist.

· 9 min read

It happens to careful, sensible people: an email looked legitimate, someone clicked, and a login page asked for their Microsoft password — and they typed it in before the penny dropped. If that's where you are right now, take a breath. What matters most isn't how it happened; it's what you do in the next few minutes. Work through this in order.

1. Change that password — from a different device

Right away, change the password for the account whose details were entered. If you can, do it from a phone or another computer, not the one that clicked — and if the same password is used anywhere else (it shouldn't be, but often is), change it there too. This alone slams the most important door.

2. Turn on two-factor authentication

If the account doesn't already have two-factor (also called MFA) switched on, turn it on now. Even if an attacker has the password, two-factor stops them getting in without the second code on your phone. If it's already on, that's genuinely good news — it may have blocked them already.

3. Sign out everywhere

Changing the password doesn't always kick out someone who's already signed in. There's an option to sign out of all sessions on all devices — use it, so any active intruder is booted immediately.

4. Check for sneaky inbox rules

This is the step people miss. A common attacker trick is to quietly add a rule that forwards or hides certain emails — so they can keep reading replies, or hide their own scam messages from you. Have someone check the mailbox's rules and forwarding settings for anything you didn't set up, and remove it.

How to tell if they actually got in

Often nobody's sure whether the password was really captured, or whether it even mattered. A few signs point to a genuine break-in, and they're worth checking calmly:

  • A sign-in from a city, country, or device the person never uses
  • Emails vanishing from the inbox, or being marked read on their own
  • Colleagues or customers receiving messages the person never sent
  • A new mailbox rule that forwards or deletes certain emails
  • Password-reset or security-code messages nobody asked for

See any of those, and treat the account as compromised and work through the steps above. See none, and you've still lost nothing by changing the password and turning on two-factor — that's the cheap insurance.

5. Tell your IT person — and your team

Loop in whoever looks after your technology so they can confirm the account is clean and watch for anything odd. And give the team a quick heads-up: a compromised account is often used to email colleagues and contacts, so a 'if you get a strange message from me, ignore it' note prevents the problem spreading.

One thing not to do: don't power off the computer in a panic. It won't help, and the steps above — which lock down the account itself — are what actually matter.

The traps worth knowing

The 'approve this sign-in?' prompt you didn't start

If someone already has a password, they'll sometimes trigger a stream of two-factor prompts to your phone, hoping you'll tap 'approve' out of habit or annoyance — a trick known as MFA fatigue. The rule is simple: if a sign-in prompt appears that you didn't start, never approve it, and change that password. An unexpected prompt is itself a sign someone has the password and is knocking on the door.

The attachment that isn't what it looks like

Plenty of scams skip the link and lean on a file instead: an .htm attachment that opens a fake login page from your own computer, a 'voicemail' or 'fax' that won't play normally, or a note about CAD drawings or an invoice you simply must download. If a file needs you to log in after opening it, or nags you to enable something, stop — that's the tell. When in doubt, don't open it; forward it to whoever handles your IT and let them look.

How to spot the next one

The habit that prevents most break-ins is a half-second of 'was I expecting this?' These are the red flags worth teaching the whole team:

Red flagWhy it's usedWhat to do
Urgency or a threat ('act now, account closing')Panic makes people skip the checkSlow down; verify through a known channel
A login link in the email itselfSends you to a lookalike pageGo to the site directly, never via the link
A slightly-wrong sender address or domainImpersonates a brand or colleagueCheck the full address, not just the name
An unexpected attachment or 'voicemail'Hides a fake login or malwareDon't open it; forward to IT
A request to change payment detailsRedirects your money to the scammerConfirm by phone using a known number

The five-minute habits that prevent most of this

You can't buy your way out of phishing with a single gadget, but a few cheap habits stop the large majority of it before it ever starts. None of these is technical or expensive:

  • Turn on two-factor for every account that offers it — it's the single biggest win, and it's free
  • Use a password manager so no password is ever reused across sites
  • Give the team a two-second 'was I expecting this?' rule for links and attachments
  • Agree that any change to payment or bank details is confirmed by phone, never by email alone
  • Keep a known contact for whoever handles your IT, so a worried person can ask straight away

Together, these turn 'someone clicked a link' from a genuine crisis into a two-minute reset. The goal isn't to make anyone feel foolish for clicking — it's to build a calm reflex so the occasional slip does no real harm.

What happens after you call us

When a client hits this, we confirm the account is genuinely clean rather than just hoping — reviewing recent sign-ins, hunting for hidden forwarding rules, making sure two-factor is on properly, and checking nobody else was reached. If it did spread, we help contain it. It's usually a short job, and knowing it's actually closed, not just probably fine, is the whole point.

Frequently asked questions

I already entered my password on a fake page — what now?
Change that password immediately, ideally from a different device, then turn on two-factor authentication, sign out of all sessions, and check the mailbox for any forwarding rules you didn't create. Then tell your IT contact so they can confirm the account is clean.
How do I know if the account was actually broken into?
The clearest signs are a sign-in from a place or device the person didn't use, emails disappearing on their own, or contacts receiving messages nobody sent. If you see any of those — or someone entered their password after a suspicious click — treat it as compromised and work through the steps.
Should I turn off the computer?
No — powering off doesn't help, because the risk is to the online account, not the machine. Focus on changing the password, enabling two-factor, and signing out all sessions.
I got a two-factor prompt I didn't ask for — what does that mean?
It usually means someone already has the password and is trying to get past two-factor by hoping you'll approve. Never approve a sign-in you didn't start, and change that password right away — the unexpected prompt is the warning sign.
Is it safe to open a suspicious attachment just to check it?
No. Files like .htm attachments or fake 'voicemails' can open a convincing login page or run something unwanted. If a file wants you to log in or enable content after opening it, don't — forward it to whoever handles your IT and let them look safely.
Should we tell our customers if an account was compromised?
Often yes, briefly — a compromised account is frequently used to message contacts, so a quick 'if you get an odd message from us, please ignore it and call' heads off any follow-on scams. Your IT contact can help judge what's proportionate.

Keep reading

Book a consult

Let's talk about what's not working

The first conversation is free and pressure-free. You talk, we listen, and by the end you'll have at least one concrete thing you can act on — whether you work with us or not.

30 minutes, via phone or video

We come prepared if you share your brief first

Flexible scheduling, including evenings and weekends

What to expect

0–5 min

Context

We learn about your business and what's not working

5–20 min

Diagnosis

We ask specific questions and share our initial read

20–30 min

Next steps

You leave with at least one concrete recommendation

“James created something that I have no doubt is the reason my practice has been at capacity for years.”

— Donovan Bigelow, LMHC