Knowledge base

Phishing – what to do if you clicked

First 15 minutes matter most. Do this, in this order.

If you clicked a phishing link or typed your password into a fake page, act now – the first 15 minutes decide how bad this gets. Do these steps in this exact order.

The first 15 minutes

  1. Disconnect the machine. Turn off Wi-Fi or unplug the network cable. Don’t power it off – just take it off the network.
  2. From a different device (your phone on mobile data is perfect), change your Microsoft 365 password. Email first, always – it’s the master key to everything else.
  3. Sign out everywhere. At myaccount.microsoft.com, go to Sign-ins and sign out of all sessions. This kicks the attacker out of anything they’ve already opened.
  4. Tell us straight away – message the helpdesk on WhatsApp (open 24/7) or raise a ticket from the clean device. We’ll review the sign-in logs, check for mail-forwarding rules a phisher may have planted, and audit any app permissions they granted themselves.
  5. Don’t delete the suspicious email. We need it – the headers and the link tell us what we’re dealing with and who else may have received it.

Once the dust settles

If you reused that password anywhere else, change it there too – attackers try stolen credentials on every big site within hours. Then make sure MFA is on (Adding MFA to your account); with MFA, a stolen password alone gets an attacker nowhere. If you’re seeing signs they got further – strange sent mail, rules you didn’t create – go straight to Think you have been hacked? Do this first.

And for next time: the ten-second habit that catches nearly every fake is in Spot a phishing email before you click.

Was this helpful?
Still stuck? Log a ticket Browse more guides

Still stuck?

Raise a ticket and we’ll pick it up. Clear updates until it’s resolved.