I Clicked a Phishing Email – What Now?

Table of Contents

Quick summary 

  • Disconnect the device from the network immediately. Don’t power it off; that can destroy evidence of what actually ran. 
  • Don’t delete the email. It’s the most useful evidence anyone investigating this will have. 
  • If you typed a password anywhere, change it now from a different device, and change it anywhere you reused it. 
  • Tell IT or your security team immediately, even if you’re not sure it was phishing. Use the Report Phishing option in Outlook or Gmail if you have it. 
  • Verizon’s own breach research puts the median time from opening a phishing email to entering data on the fake page at under a minute, so speed matters more than certainty. 
  • Reporting a false alarm costs about ninety seconds. A phishing click reported three days late costs a lot more than that. 

You clicked. You have realized. Your stomach has dropped. 

Here is the part worth knowing before anything else: clicking is not the failure. People click. The links are designed by people whose full-time job is making them clickable, and they are good at it. What actually determines how bad this gets is what happens in the next few minutes. And the most common reason those minutes get wasted is that the person who clicked spends them deciding whether to admit it. 

Don’t do that. Read the next section and act on it. 

Phishing Email Response Steps: Do These 5 Things in the Next 10 Minutes 

  1. Disconnect the device from the network. Unplug the ethernet cable or turn off Wi-Fi. Do not shut the machine down. If something did execute, shutting down can destroy evidence that helps work out what happened. Disconnecting stops it talking to anything; powering off just makes it harder to investigate. 
  1. Do not delete the email. It is the single most useful artifact anyone investigating this will have: the sender address, the headers, the exact link. Deleting it out of embarrassment removes the evidence and doesn’t remove the problem. 
  1. If you entered credentials anywhere, change that password now, from a different device. Use your phone, or a colleague’s machine. Changing it on a device that may be compromised can hand the new password over too. Change it anywhere you reused it as well, which is the part people skip. 
  1. Tell your IT team or provider. Now, not later. Say what you clicked, roughly when, and whether you typed anything in. You do not need to have worked out whether it was really phishing, that is their job, and they would far rather look at ten false alarms than miss one real one. If your organization uses Outlook or Microsoft 365, look for a Report button in the toolbar and choose Report Phishing. In Gmail, open the three-dot menu on the message and select Report phishing. Either one takes under ten seconds and sends the message, headers included, straight to whoever is watching for this. If you don’t see either option, or you’re not sure it’s set up, forwarding the email to IT with a one-line note works just as well. 
  1. Watch for the follow-up. Phishing frequently comes in pairs: the first message harvests something, the second uses it. A colleague suddenly emailing you an unexpected invoice, a “helpdesk” calling about the very issue you just reported: treat all of it as suspect for the next few days. 

What If I Entered My Password on the Phishing Site? 

Then treat the account as compromised until someone confirms otherwise, and do three things in this order: 

  1. Change the password from a clean device, as above, and change it anywhere you reused it. 
  1. Sign out all active sessions. Most business platforms have this in security settings, and it matters because changing a password does not always evict someone already logged in. 
  1. Check for changes the attacker may have made:  
  • Mail forwarding rules 
  • New recovery email addresses or phone numbers 
  • New app passwords 
  • Any device or app newly authorized on the account 

That last one is the step almost everybody misses. A mail-forwarding rule quietly copying your inbox to an external address survives a password change perfectly well, and it is one of the first things a competent attacker sets up. If you have multi-factor authentication enabled, you are in a considerably better position, but MFA is not absolute, and it does not undo a forwarding rule. 

Definition:

Credential harvesting. A phishing page that imitates a real login screen in order to capture the username and password you type into it. The page usually then forwards you to the genuine site, so the login appears to have simply failed the first time, which is why many people never realize anything happened. 

What If I Opened an Attachment or Enabled Content? 

Stay disconnected from the network, and say so explicitly when you report it. “I opened the attachment” is a materially different situation from “I clicked a link,” and it changes what the response has to check for. 

If a document asked you to enable editing, enable content, or enable macros, and you did, say that too. That prompt exists because the file wants to run something, and legitimate business documents essentially never need it. 

I Clicked the Link But Didn’t Enter a Password, Now What? 

Report it anyway, but you are probably in reasonable shape. 

If you clicked, a page opened, and you closed it without typing anything or downloading anything, the most likely outcome is that the sender now knows the address is live and monitored. That is worth something to them and is why the follow-up attempt often arrives. It is not nothing, but it is a long way from a credential compromise. 

Two things are still worth checking: whether anything downloaded automatically (look in your downloads folder for anything you didn’t ask for), and whether the page prompted you to install or update something. “Your browser is out of date, click to update” is a delivery mechanism, not a browser message. 

Should I Report It If I’m Not Sure It Was Phishing? 

Yes. Every time. This is the single most useful habit an organization can build, and it is worth being blunt about why. 

The people who investigate this would rather assess twenty harmless emails than find out three days late about the one that mattered, because at three days, the question is no longer “did someone get in” but “what have they had access to since Tuesday.” The cost of a false report is about ninety seconds of someone’s attention. The cost of a delayed real one compounds hourly. 

Verizon’s own breach research backs up why speed matters more than certainty here: the median time between opening a phishing email and clicking the link is 21 seconds, and entering data on the resulting page takes about another 28 seconds, under a minute, start to finish. There usually isn’t time to be sure before it matters, which is exactly why reporting doesn’t require certainty. 

If your organization makes people feel stupid for reporting, that is a security problem in its own right, and a more serious one than any individual click. The reporting delay is the attack surface. CISA’s guidance on recognizing and reporting phishing makes the same point about speed. 

What Actually Happens After You Report It 

Most articles about phishing stop at “contact your IT team,” which is unhelpful if you have never seen what that actually sets in motion. Here is the shape of it, from the side that receives the report. 

The first five minutes 

A competent monitored environment does not begin by working out what happened. It begins by containing it, because those are different jobs and only one of them is urgent. The failure type is already mapped, so the triage doesn’t wait on a human diagnosing it from scratch. In our Security as a Service work, an alert is acknowledged and triaged automatically, and where a playbook exists for that situation, the response runs without waiting for someone to pick up a ticket. In practice, containment usually means: 

  • Isolate the device 
  • Force a password reset and terminate active sessions on the affected account 
  • Check whether that account has done anything unusual since the click 
  • Look for the same message in other people’s mailboxes, because you were almost certainly not the only recipient 

The next few hours 

Then the slower questions: 

  • Did anything execute on the device 
  • Were credentials actually submitted, or just requested 
  • Has anything changed on the account: forwarding rules, recovery details, authorized apps 
  • Did the same campaign reach anyone else, and did anyone else click 
  • Whether anything needs reporting externally, which for a healthcare or financial organization is a regulatory question and not only a technical one. See HHS guidance on the HIPAA Security Rule if you handle protected health information; we’ve worked through exactly this kind of compliance pressure with a Texas healthcare network client. 

None of that is glamorous, and most of it is invisible to the person who clicked. That is rather the point: the experience you want after reporting a phishing click is a short conversation, a forced password reset, and someone telling you a day later that it was contained. 

How to Tell It Was Phishing, After the Fact 

Once you are out of the immediate window, it is worth going back and looking at what actually gave it away, mostly because it makes the next one easier to spot. 

  • The sender domain rarely survives inspection. Not the display name, which is trivially faked, but the actual address. Look for a character swapped, a hyphen added, or a real company name sitting in front of an unrelated domain. 
  • Urgency doing a lot of work. Account suspension, a payment failing, a document expiring today. Urgency exists to stop you checking. 
  • The link destination doesn’t match the text. Hovering shows where it really goes. 
  • A login page you arrived at rather than navigated to. This is the big one. If an email took you to a login screen, treat it as hostile by default. Open a new tab, type the address yourself, and log in there instead, every time, regardless of how legitimate the page looks. It costs ten seconds and defeats the entire category. 

The FTC’s guidance on phishing covers the consumer-facing versions of these patterns. 

Why This Keeps Happening, and What Actually Reduces It 

Awareness training helps, and it is not sufficient. The organizations that handle this well are not the ones whose staff never click. They are the ones where the gap between clicking and reporting is measured in minutes, and where the estate is in a state that limits what one compromised account can reach. 

Concretely, that means: 

  • Continuous monitoring across endpoints, network and email, so the report isn’t the only way anyone finds out 
  • Access that gets removed when people leave, automatically rather than eventually 
  • A patching cadence you could show an auditor 
  • Multi-factor authentication on everything that supports it 

That last cluster is worth dwelling on, because it is the unglamorous part that determines blast radius. In the first week of a new environment, the pattern we see is remarkably consistent: unsupported operating systems still in production, firmware years out of date, credentials still active for people who left, and backup jobs that have been failing quietly for long enough that nobody remembers the last successful restore. None of that causes a phishing click. All of it decides how much one costs you.

FAQs 

1 How long do I have before a phishing click becomes serious?  

Assume minutes, not hours. Automated credential-stuffing can begin using a harvested password almost immediately, and mail-forwarding rules take seconds to set up. This is why reporting immediately matters more than reporting accurately. Containment is time-sensitive in a way that diagnosis is not. 

2 Will changing my password fix it?  

It is necessary, and on its own it is often not sufficient. Changing a password does not always terminate sessions that are already logged in, and it does nothing about changes an attacker may have already made: forwarding rules, recovery addresses, authorized apps. Change the password, sign out all sessions, then check those three things. 

3 Does multi-factor authentication mean I’m safe?  

It puts you in a much better position and defeats most credential-harvesting outright. It is not absolute. Some phishing kits are built specifically to relay MFA prompts in real time, and it does nothing about changes made to an account that was already accessed. Treat MFA as substantially reducing the risk, not eliminating it. 

4 I clicked but didn’t enter anything. Do I still need to report it?  

Yes. The report costs about ninety seconds and it tells whoever monitors your environment that a campaign reached your organization, which matters, because you were almost certainly not the only recipient. It also means that if something did happen quietly, the timeline already exists. 

5 Can you tell whether anything was actually stolen? 

 Sometimes definitively, sometimes only by inference. It depends on what logging exists in the environment and how long it is retained. This is one of the practical arguments for continuous log assessment: the question “what did they access” is answerable only if something was recording at the time. 

Share this article with a friend

Create an account to access this functionality.
Discover the advantages