News

What Should You Do If Someone Clicks a Phishing Link?

A member of staff clicked a phishing link, what now? Disconnect the device, change any passwords entered, switch on MFA, then get sign-in logs and forwarding rules checked properly.

19 August 2026

Red padlock resting on a black computer keyboard, representing email and cybersecurity protection

Short answer: don’t panic, disconnect the device from the network straight away, change any passwords that were entered, and get someone to check whether it’s spread, most damage happens in the hours after the click, not the moment itself.

It happens to good, careful people. Someone’s rushing through their inbox, a message looks like it’s from a supplier or from “IT,” and they click before they think. If that’s just happened in your business, here’s what actually matters, in order.

1. Disconnect First, Ask Questions Later

Pull the device off Wi-Fi or unplug the network cable. If it can’t talk to the rest of your network, it can’t spread anything to the rest of your network. This takes ten seconds and buys you time to think clearly.

2. Change the Passwords That Were Typed In

If the link led to a fake login page and someone typed a password into it, that password is compromised, change it immediately, and change it anywhere else it was reused (please don’t let it be reused anywhere else going forward).

Person looking cautiously at a laptop screen after spotting a suspicious login prompt

3. Turn On Multi-Factor Authentication If It Isn’t Already On

A stolen password is far less useful to an attacker if they still need a code from your phone to get in. If MFA isn’t switched on across your business email and key systems, this is the moment to fix that.

4. Get Someone to Actually Check, Don’t Just Assume It’s Fine

“It looked fine afterwards” is not the same as “it was fine.” A quick check of email forwarding rules, sign-in logs, and the device itself can catch problems before they turn into a real incident.

If you’re not sure whether something odd happening on your systems is serious, that’s exactly the kind of call worth making before it becomes a bigger problem.

ARTICLE FAQ

Common questions about this topic

A few useful answers to common questions related to this article.

Do I need to report it to anyone?
If any customer or financial data may have been exposed, you may have data protection obligations worth taking advice on. When in doubt, ask.
Should I tell the person off for clicking it?
No, modern phishing emails are genuinely convincing, and a team that is afraid to report a mistake is far more dangerous than one that clicked a link and told you immediately.
How do we stop this happening again?
Ongoing staff awareness, spam filtering, and MFA are the three things that make the biggest difference, not one big training session a year.

Related Services

Useful next steps if this issue affects your business

These related DP-Solutions services are often the most relevant follow-on conversations after reading this article.

Need a hand?

Talk to DP-Solutions

If the issue covered in this article is affecting your business or you would like practical advice on what to do next, get in touch with DP-Solutions. We’ll take the time to understand what you need and help make the next step straightforward.