RESOURCES · SECURITY & EMAIL

What to do if you
clicked a phishing link

Clicked a link in a suspicious email, or typed your password into a page that now looks wrong? Don't panic — but do move quickly. Here's exactly what to do in the first few minutes to limit the damage.

Applies to: Any account / device Time: act now Level: Everyone should read this
Quick answer

Change the password on that account from a different, trusted device, tell your IT/security team immediately, and confirm MFA is on. If you downloaded or ran anything, disconnect the device. If bank or card details were involved, phone your bank now.

WHY IT MATTERS

Speed decides how bad this gets.

A single click can lead to stolen credentials, malware on your device, or a business email compromise where an attacker sits inside your mailbox. The good news: the faster you respond, the less an attacker can actually do with what they got. The steps below are ordered so you deal with the most urgent risks first.

WHAT TO DO NOW

Work through these straight away.

  1. Stop — don't enter anything elseClose the page and type nothing more into it. If you downloaded or opened a file, disconnect the device from Wi-Fi and the network right away to stop anything spreading or "phoning home".
  2. Change the password — from a different deviceUsing a separate, trusted device, change the password on that account, and on anything that shares the same password. Don't reuse the compromised device until IT has checked it.
  3. Tell your IT/security team straight awayReport it immediately (and let your manager know). Reporting fast is the single biggest thing that limits the damage — it lets IT revoke sessions and lock things down before the attacker moves.
  4. Turn on or confirm MFAMake sure multi-factor authentication is enabled on the account, so a stolen password alone can't get anyone in. If it was already on, that's your safety net working.
  5. Have IT check for hidden changesAsk IT to check the mailbox for sneaky forwarding rules or new app sign-ins, and to review recent sign-in activity for logins from unexpected locations or devices.
  6. Run a full malware scanIf anything was downloaded or opened, run a full malware scan (or have IT do it) before the device goes back on the network. Don't assume "it looked like it didn't do anything".
  7. Money involved? Phone your bank nowIf bank details, card numbers or a payment were involved, phone your bank immediately and report it to ReportCyber at cyber.gov.au. Fast contact can stop or reverse transactions.
  8. Warn colleagues and watch for follow-upsIf the email appeared to come from a known contact, warn colleagues so they don't click it too. Then stay alert for follow-up scams — attackers often try a second approach while your guard is down.
There's no shame in reporting fast. IT would much rather hear "I think I clicked something" within two minutes than discover a breach two weeks later. Trying to hide it is what turns a click into a crisis. Owning up quickly is exactly what a good security culture looks like — and it's often the difference between a non-event and a genuine incident.
BEFORE THE NEXT ONE LANDS

The best time to prepare is before someone clicks.

Everyone gets caught out eventually — what matters is whether your defences catch it. Our free IT Health Check reviews your email filtering, MFA, sign-in security and staff awareness, and shows you exactly where a single click could still do damage, and how to close those gaps.

KEEP READING

Related resources