Hoplon InfoSec Logo

Hoplon Infosec · Threat Intelligence

Clicked on a Phishing Link? What to Do Now

BySharfunnahar Radia
Published16 Aug, 2026
Clicked on a Phishing Link? What to Do Now
Sharfunnahar Radia16 Aug, 2026

Clicked on a Phishing Link? Here’s What to Do Now

If you clicked on a phishing link, stop interacting with the page first. Do not enter a password, payment information, authentication code, or personal data. Do not approve a login request or install anything the page asks you to install.

Then work out what actually happened. A link opening in your browser does not by itself prove that your account or device was compromised. The response should depend on whether you entered information, downloaded or ran something, approved access, or noticed signs of malicious activity.

If malware may have been downloaded, update your security software and run a scan. If you exposed a password, change it on the legitimate service and secure the account. If the incident involved a work or school account, notify your IT or security team promptly.

Phishing Link Response Decision Tree
Phishing Link Response Decision Tree


First, Work Out What Happened

Not every phishing incident has the same level of exposure.

What happened?

Main concern

What to do first

You opened the link but entered nothing

Malicious page or possible download

Close the page, check downloads, update security software, scan if appropriate

You entered a password

Account takeover

Change the password on the real service, review activity, secure sessions, enable MFA

You reused that password elsewhere

Multiple accounts may be exposed

Replace the reused password everywhere it was used

You entered or approved an MFA request

Authenticated access may have been granted

Contact the account provider or IT team, revoke sessions and review sign-ins

You downloaded or ran a file

Malware or remote access

Isolate the device when compromise is suspected and begin security investigation

You gave bank/card information

Financial fraud

Contact the financial institution and monitor the account

You provided sensitive identity information

Identity theft

Follow the recovery steps at IdentityTheft.gov

It happened on a work device/account

Organizational compromise

Report it to IT/security immediately and preserve relevant evidence

FTC advises people who believe malicious software may have been downloaded to update their security software, run a scan, and remove anything identified as a problem. Microsoft separately recommends changing affected passwords, enabling MFA, and notifying IT when a work or school account is involved.

If You Only Clicked the Link

A click is not the same as giving an attacker your password.

Some phishing links simply open a fake login page. Others try to trigger downloads, redirect you, collect browser information, or exploit a vulnerability. That means the risk depends partly on what happened after the page loaded.

Close the suspicious page. Check whether your browser downloaded anything. Do not open an unfamiliar file just to see what it contains.

Make sure your operating system, browser, and security software are current. If you believe the link may have delivered harmful software, run the appropriate security scan. FTC specifically recommends this after a suspected malicious download.

You do not need to assume automatically that every account you own is compromised simply because a page opened.

If You Entered Your Password

Treat the affected account as potentially compromised.

Open a new browser window or, when device compromise is also suspected, use another trusted device. Navigate to the real service yourself rather than using the phishing message.

Change the exposed password. If the same password was used anywhere else, replace it on those accounts too. Microsoft specifically recommends changing passwords on affected accounts and anywhere the same password was reused.

Then review recent account activity and unfamiliar devices. Major platforms provide security pages where users can inspect or remove devices and sessions. Google, for example, provides controls for reviewing devices with account access, while Microsoft provides account-activity and sign-out controls.

Turn on MFA if it is not already enabled. MFA adds another barrier when a password has been stolen.

If You Entered an MFA Code or Approved a Sign-In

This deserves more attention than a simple password reset.

Modern phishing can target authenticated sessions as well as passwords. Microsoft documents token-theft attacks in which stolen tokens are replayed after the user has already satisfied MFA.

For an ordinary consumer account, use the provider's security tools to review active devices, suspicious logins, recovery details, and sessions.

For a business account, the security or identity team may need to revoke sessions, inspect authentication logs, check recently registered authentication methods, and investigate activity after the suspected compromise. These steps are especially important for SSO, administrator, cloud, email, or other privileged accounts. Microsoft and Google both document response mechanisms for suspected token or session compromise in their environments.

If a File Downloaded or You Installed Something

A downloaded file is not automatically malware, but do not run an unfamiliar file simply to investigate it yourself.

If you already opened or executed something suspicious, or if the computer starts behaving abnormally, treat the situation more seriously.

For a personal device, use trusted security software and follow the operating system or security vendor's malware-removal process. FTC recommends keeping security software updated and scanning when harmful software may have been downloaded.

For a company device, contact the security team before deleting files or clearing evidence. KnowBe4 specifically advises employees not to manipulate potentially malicious files and instead to follow their organization's investigation process.

When malware or an active compromise is genuinely suspected, isolating the endpoint from the network can help limit further communication or spread while responders investigate. This is different from claiming that every accidental click requires immediate network isolation.

If You Shared Banking, Credit-Card, or Identity Information

Account security steps are not enough when financial or identity information has been exposed.

Contact the relevant bank or card issuer using a trusted phone number or official application. Do not use contact details from the phishing message.

FTC directs people who believe a scammer obtained Social Security, credit-card, or bank-account information to IdentityTheft.gov, where recovery actions can be tailored to the information exposed.

If fraudulent transactions or cyber-enabled crime occurred, the FBI's Internet Crime Complaint Center accepts reports. IC3 describes itself as the central hub for reporting cyber-enabled crime and says people can file even when they are unsure whether the complaint qualifies.

If You Clicked the Link at Work

Report it quickly rather than trying to hide or privately fix the issue.

The security team may need information such as:

  • the original email or message;
  • the URL;
  • when you clicked it;
  • which device you used;
  • whether you entered credentials;
  • whether you approved MFA;
  • whether a file downloaded;
  • what happened afterward.

Microsoft recommends recording details while they are fresh and notifying IT when a work or school account may have been phished. KnowBe4 similarly advises contacting the security team and following its investigation process.

A security team may then inspect email telemetry, endpoint activity, identity logs, active sessions, cloud activity, or other evidence according to the systems involved.

Phishing Response and Recovery Guide
Phishing Response and Recovery Guide


Why Business Phishing Incidents Can Become More Serious

For businesses, the immediate issue may be larger than one employee's browser.

Stolen credentials can expose business email, SaaS platforms, internal systems, or cloud resources. Session theft can create additional risk because some authentication tokens can be replayed even after MFA has already occurred.

Depending on the account, an attacker may also attempt business email compromise, payment fraud, data access, further phishing, or privilege escalation. The actual risk depends on what the compromised identity can access. Google Workspace documentation describes phishing as a common method of stealing credentials used to compromise organizational accounts.

This is why an administrator account, finance mailbox, executive account, developer identity, or SSO account should usually receive more scrutiny than a low-privilege account.

Five Questions to Assess the Incident Yourself

Ask:

  1. Did I enter a password or personal information?
  2. Did I download, open, install, or run anything?
  3. Did I approve an MFA request or enter a verification code?
  4. Was this a business, administrator, SSO, financial, or other sensitive account?
  5. Have I seen unfamiliar logins, new devices, changed settings, suspicious email activity, or unexpected transactions?

The more of these questions you answer “yes” to, the more appropriate formal investigation becomes.

Common Mistakes After Clicking a Phishing Link

Continuing to interact with the page

Do not keep clicking buttons to test whether the site is malicious.

Using the link again to change your password

Navigate independently to the legitimate service.

Changing only one reused password

If the exposed password was reused, other accounts may also be vulnerable. Microsoft recommends replacing reused passwords on affected accounts.

Assuming MFA ends the investigation

MFA is valuable, but token or session theft can require session-level remediation as well.

Deleting evidence on a work system

The original message, suspicious URL, downloaded file, and device logs may help investigators establish what occurred.

Calling the number shown in the suspicious page

FTC recommends contacting companies through a phone number or website you already know is genuine instead of using information provided in the suspicious message.

When Professional Incident Response May Be Appropriate

Professional help becomes more relevant when:

  • a business or privileged account may be compromised;
  • multiple employees received or interacted with the same campaign;
  • suspicious authentication continues after account recovery;
  • malware or remote access is suspected;
  • sensitive business data may have been accessed;
  • the incident affects several systems;
  • internal staff cannot establish what the attacker did;
  • forensic preservation is important;
  • the company needs a structured containment and recovery process.

NIST's current SP 800-61 Rev. 3 treats incident response as part of broader cybersecurity risk management and emphasizes preparation, detection, response, and recovery capabilities across an organization.

Legal, regulatory, contractual, insurance, and notification obligations depend on the facts and jurisdiction. Organizations should obtain appropriate legal or compliance advice rather than assuming every phishing event creates the same reporting obligation.

What a Good Incident-Response Provider Should Do

For a meaningful phishing-related compromise, professional support should be able to:

  • establish what happened;
  • identify affected identities and endpoints;
  • contain active access;
  • preserve important evidence;
  • review relevant security and authentication logs;
  • investigate suspicious activity;
  • remove malicious persistence where present;
  • recover affected systems or accounts;
  • document findings;
  • identify security gaps that contributed to the incident;
  • recommend practical remediation.

These activities align with the broader goals of structured incident response described in NIST's current incident-response guidance.

How Hoplon Infosec Can Help

If a phishing click has developed into a suspected business compromise, Hoplon Infosec currently lists Incident Readiness & Response Recovery among its services. The published service scope includes incident-response planning, technical readiness assessment, containment and investigation support, and recovery and remediation.

Incident response and recovery services

For incidents where the organization needs to determine what occurred and preserve electronic evidence, Hoplon also publishes a Digital Forensics & Incident Investigation service.

Digital forensics and incident investigation

Organizations that are not dealing with an active compromise but want to identify weaknesses in endpoints, networks, identity, cloud, policy, and people can also review Hoplon's cybersecurity assessment offering.

Cybersecurity assessment

If the incident involves a company device, business email account, SSO identity, administrator account, malware, or sensitive organizational data, document what happened and contact your internal security team first. If additional incident-response expertise is required, Hoplon's verified incident-response service is a relevant next step.

Related Articles:

 

Frequently asked questions

Frequently Asked Questions

Was this useful?

React, leave a note, or share it forward.

Leave a note

Share this article

Share this :

03Latest posts

Free · Weekly · No noise

Get the threats that matter, before they reach you.

One short email a week with the breaches, zero-days, and fixes worth your attention — written in plain English, no fear-mongering.