If an employee clicked a phishing link, the first three things to do are: disconnect the device from the network, change the employee's password from a different device, and sign the account out of every session so the attacker loses any access they already gained. Then check the mailbox for forwarding rules the attacker may have added, scan the device, and report the incident internally. Do all of this calmly and without blame, because the employee who reports a click within minutes has just saved you from a much worse week.
Employee clicked a phishing link: the first ten minutes
Speed matters more than perfection. Most damage from a phishing compromise happens in the hours after the click, when the attacker uses the stolen password to read email, set up persistence, and start fraud. Here is the order of operations we use with Treasure Coast clients.
1. Find out what happened, briefly
Ask three questions, without judgment: What did you click? Did you enter a username and password, or a code from your phone? Did anything download or open? The answers determine how much of the rest applies. A click that opened a page and was closed is lower risk than a click that led to a login form that was filled in.
2. Disconnect the device
Unplug the network cable or turn off Wi-Fi. If the device is managed by endpoint detection and response, isolate it from the console instead, which keeps it reachable for investigation while cutting it off from everything else. Do not power it off; that destroys evidence in memory that may be needed.
3. Reset the password from a different device
If credentials were entered, change the password immediately, and do it from a machine that is known to be clean, not the one that was just clicked on. Change it anywhere else the same password was used, which is more places than people admit.
4. Revoke every active session
Changing a password does not always end sessions the attacker already has. In Microsoft 365, an administrator should sign the user out of all sessions and revoke refresh tokens so every device and app must authenticate again. Do the same in Google Workspace or any other cloud service the credentials unlocked.
5. Check MFA
Confirm multi-factor authentication is still enabled and that no new authentication methods, phone numbers, or devices were added to the account. Attackers who get in often register their own authenticator so they can survive a password change.
What should you check in the mailbox?
A compromised mailbox is the attacker's favorite tool, and they set it up to keep working quietly.
- Inbox rules. Look for rules that forward mail externally, move messages to obscure folders, or delete anything containing words like invoice, payment, or password. These hide the attacker's activity from the real user.
- Forwarding settings. Check account-level forwarding, not just rules.
- Sent items and deleted items. Look for messages the user did not send, especially to coworkers, clients, or vendors, and for replies to payment threads.
- OAuth application consents. Attackers sometimes grant a malicious app permanent access to the mailbox. Review and remove unfamiliar apps.
- Sign-in logs. Identify logins from unfamiliar locations or devices to establish when the compromise started and whether it is ongoing.
If the account sent phishing to others, notify them promptly so the spread stops. This is embarrassing and necessary.
How do you clean the device?
If the link only led to a credential-harvesting page, the device is often uninfected, but assume nothing. Run a full scan with your endpoint protection. If the click downloaded or opened a file, treat the machine as compromised: capture what EDR recorded, then reimage the device rather than trying to clean it by hand. Reimaging a workstation takes an hour or two; trusting a partially cleaned one can cost weeks.
While the device is out of service, the employee can work from a known-good machine with the new password. Do not let the urgency of getting them back to work shortcut the cleanup.
Who needs to know, and when?
Report internally the same day: the owner or manager, your IT provider, and whoever handles compliance. Keep a simple written timeline: when the email arrived, when it was clicked, what was entered, what was done and when. That record matters for three reasons.
- Your cyber insurance policy almost certainly requires prompt notice of a potential incident, and late notice can affect coverage.
- If the account contained patient, client, or financial data, breach-notification obligations under HIPAA or state law may apply, and the analysis of whether they do depends on knowing what the attacker could have accessed.
- If a wire or payment was diverted, contacting your bank within hours gives the best chance of recovering funds.
When there is any sign the attacker actually got in, moved money, or touched regulated data, escalate to a formal incident response engagement rather than handling it ad hoc.
How do you handle the employee?
This part determines whether your next incident is reported in five minutes or hidden for five days. The person who clicked is not the problem; the attacker is. Phishing is designed by professionals to fool careful people, and the widely reported reality is that everyone clicks eventually.
Thank the employee for reporting. Say it out loud in front of others. Make the after-action review about the process, not the person: how did the email get through, what tell did it hide, what could the team learn. Reserve discipline for repeated carelessness after training, never for a first report. In offices where reporting is safe, we consistently see faster detection and smaller incidents.
What should you fix afterward?
Every click is a free penetration test. Use it.
- Confirm MFA is enforced for every user, with no exceptions for executives or shared mailboxes.
- Turn on alerts for new inbox rules, external forwarding, and impossible-travel sign-ins in Microsoft 365, so the next compromise announces itself.
- Review email filtering and whether the message could have been caught.
- Add the tell from this email to your next staff refresher.
- Verify that endpoint detection and response is on every device and that someone is watching it.
- Add a phone-verification rule for any payment or banking change request, regardless of how legitimate it looks.
Most of those are configuration changes inside tools you already own, and a managed security program keeps them in place.
A one-page version for the wall
Clicked something suspicious? Do not panic and do not hide it. Disconnect the device. Tell IT or the help desk right now, and say whether you entered a password. Change your password from another device. Do not use the machine until IT clears it. You will not be in trouble for reporting.
MainSail Data provides 24x7x365 incident response and managed security for businesses across Vero Beach, Fort Pierce, Port St. Lucie, and Stuart. If you are dealing with a click right now, call (772) 794-1194. If you want to be ready before the next one, the same number gets you a free security assessment.

