Skip to main content
Articles

An Employee Clicked a Phishing Link. Do These Things in This Order.

Someone on your team just came to you, embarrassed, and said the sentence every business owner dreads: "I think I clicked something I shouldn't have."

First, before anything else: they did the right thing by telling you, and how you react right now determines whether the next person speaks up or hides it. Phishing that gets reported in five minutes is an incident. Phishing that gets hidden for three days is a disaster. Say thank you, mean it, and get to work.

Here's the order of operations.

1. Figure out what "clicked" means

The word covers four different situations with four different severities. Ask calmly:

  • Clicked a link but entered nothing. Lowest severity. The page may have tried to run something in the browser, but most of the time a click alone means little. Don't relax yet, but don't panic.
  • Clicked and typed in a password. This is credential theft, and it's now a race. Assume the attacker is trying that password within minutes.
  • Clicked and downloaded or opened a file. Possible malware on the machine. The computer is now suspect.
  • Clicked and approved a sign-in prompt or MFA request. The attacker may have a live session right now. Treat it like a stolen password, urgently.

2. If a password went in: change it, then kill the sessions

Change the password on the affected account immediately. Then, and people skip this, sign out all active sessions for that account, because changing a password doesn't always evict someone who's already logged in. If that same password is reused anywhere else, and be honest, it usually is, change it there too. Turn on multi-factor authentication if it wasn't already on.

Then check the mailbox rules on that account. Attackers who get into email almost immediately create forwarding or auto-delete rules so they can watch quietly. A rule the user didn't create is confirmation you had a visitor.

3. If a file was opened: get the machine off the network

Disconnect it from Wi-Fi or unplug the cable. Don't power it off, just isolate it, since powering off can destroy the evidence of what ran. If you have endpoint detection on the machine, this is its moment: check what it flagged. If your antivirus is whatever came free with the computer, assume you don't actually know what's on the machine, because you don't.

4. Look at what the account could reach

An email account is rarely the target. It's the doorway. Think about what flowed through that mailbox: invoices, wire instructions, payroll changes, customer data, password resets for other systems. If the account touched money conversations, call, don't email, the other parties in any recent payment thread and confirm nothing changed. Invoice fraud from a watched mailbox is how small businesses lose five and six figures, and the window to catch a fraudulent wire is measured in hours.

5. Write down what happened

Date, time, who, what was clicked, what was done about it. Twenty minutes of notes while it's fresh. If this turns out to be bigger than it looked, that record is what your insurer, your bank, and any regulator will ask for first. If your business handles regulated data, patient records, tax files, client financials, an incident record isn't optional paperwork. It's the difference between "we responded properly" and taking their word for it.

6. Afterward: fix the system, not the person

One more time, because it matters: the employee is not the problem. Phishing works on smart, careful people, and the businesses that punish clicks just train their staff to stop reporting. The useful questions afterward are system questions. Why did the email get through? Would MFA have stopped this? Would anything on the computer have caught the download? Does anyone watch for suspicious sign-ins, or did you only find out because a human confessed?

That last question is the uncomfortable one. Everything in this checklist assumes you found out. The incidents that do real damage are the ones nobody reports because nobody noticed.

If you worked through this list for a real incident today and step 3 revealed you have no way to know what ran on that machine, or step 6 left you without good answers, that's what we do for small businesses: monitored detection on every computer, MFA done properly, and someone to call before you need this checklist again. Book a 15-minute review and we'll go through where you stand.


Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.