Quick answer
Change the password on that account from a different, trusted device, tell your IT/security team immediately, and confirm MFA is on. If you downloaded or ran anything, disconnect the device. If bank or card details were involved, phone your bank now.
WHY IT MATTERS
Speed decides how bad this gets.
A single click can lead to stolen credentials, malware on your device, or a business email compromise where an attacker sits inside your mailbox. The good news: the faster you respond, the less an attacker can actually do with what they got. The steps below are ordered so you deal with the most urgent risks first.
WHAT TO DO NOW
Work through these straight away.
- Stop — don't enter anything elseClose the page and type nothing more into it. If you downloaded or opened a file, disconnect the device from Wi-Fi and the network right away to stop anything spreading or "phoning home".
- Change the password — from a different deviceUsing a separate, trusted device, change the password on that account, and on anything that shares the same password. Don't reuse the compromised device until IT has checked it.
- Tell your IT/security team straight awayReport it immediately (and let your manager know). Reporting fast is the single biggest thing that limits the damage — it lets IT revoke sessions and lock things down before the attacker moves.
- Turn on or confirm MFAMake sure multi-factor authentication is enabled on the account, so a stolen password alone can't get anyone in. If it was already on, that's your safety net working.
- Have IT check for hidden changesAsk IT to check the mailbox for sneaky forwarding rules or new app sign-ins, and to review recent sign-in activity for logins from unexpected locations or devices.
- Run a full malware scanIf anything was downloaded or opened, run a full malware scan (or have IT do it) before the device goes back on the network. Don't assume "it looked like it didn't do anything".
- Money involved? Phone your bank nowIf bank details, card numbers or a payment were involved, phone your bank immediately and report it to ReportCyber at cyber.gov.au. Fast contact can stop or reverse transactions.
- Warn colleagues and watch for follow-upsIf the email appeared to come from a known contact, warn colleagues so they don't click it too. Then stay alert for follow-up scams — attackers often try a second approach while your guard is down.
There's no shame in reporting fast. IT would much rather hear "I think I clicked something" within two minutes than discover a breach two weeks later. Trying to hide it is what turns a click into a crisis. Owning up quickly is exactly what a good security culture looks like — and it's often the difference between a non-event and a genuine incident.