Employee Clicked a Phishing Link – What Should We Do?
A practical UK business guide to the first actions after a phishing click, stolen Microsoft 365 credentials, an unexpected MFA approval or a suspicious download.

The short answer: if an employee clicked a phishing link, stop interacting with it and establish exactly what happened. If they entered a password, approved MFA, supplied sensitive information or opened a suspicious file, treat it as a possible account or device compromise and respond immediately.
An employee has clicked a phishing link. Perhaps they realised immediately. Perhaps they entered their Microsoft 365 password before noticing something was wrong. Or perhaps they approved an MFA request and only mentioned it afterwards.
First: do not panic, and do not blame the employee. What happens in the next few minutes matters considerably more than who clicked what.
What should a business do immediately after an employee clicks a phishing link?
- 1Stop interacting with the phishing page and report the incident immediately.
- 2If credentials were entered, secure the affected account and change the password.
- 3Revoke existing Microsoft 365 sessions so active authentication is forced again.
- 4Review recent sign-ins and registered MFA methods.
- 5Check the mailbox for suspicious forwarding, inbox rules, sent mail and deleted mail.
- 6Determine whether files, SharePoint, OneDrive, Teams or other company data may have been accessed.
- 7If a suspicious file was downloaded or opened, investigate the affected computer.
- 8Document the incident and decide whether external reporting is required.
For a Microsoft 365 account, changing the password is important, but it should not be the only action. Active sessions, mailbox rules and other account activity also need checking.
An employee clicked a phishing link. Is the business definitely hacked?
No. Clicking a phishing link does not automatically mean the account or computer has been compromised.
There is a substantial difference between clicking a link and immediately closing the page, and clicking a link, entering a Microsoft 365 password and approving an MFA request.
The first useful question is therefore not simply “Did you click it?” It is “What happened after you clicked it?”
Scenario 1: the employee only clicked the phishing link
If the employee clicked the phishing link but did not enter information, download anything or approve an authentication request, the risk is considerably lower.
They should close the page and report what happened. Preserve the original email where possible because the sender, link and message headers may help with the investigation.
Modern browsers and security products provide useful protection against known malicious websites, but no control catches everything. In many cases, clicking alone will turn out to have caused no damage. It is still worth checking rather than guessing.
Scenario 2: the employee entered their Microsoft 365 password into a phishing site
If an employee entered their password into a phishing website, work on the assumption that somebody else may now know that password.
Change the password, secure the account and revoke existing Microsoft 365 sessions. Modern cloud services use authentication tokens so an attacker who has already authenticated may have an active session even after the password has been exposed.
In plain English: change the password and throw everybody out of the account, then allow the genuine employee to sign back in.
What should we check in Microsoft 365 after a phishing attack?
Check recent sign-ins
Review Microsoft Entra sign-in activity for unfamiliar countries, unusual IP addresses, unexpected devices, strange times or patterns of failed attempts followed by a successful sign-in.
Location alone is not proof of compromise. Mobile networks, VPNs and cloud services can make location information look odd. The important thing is the overall pattern.
Check MFA methods
Look for authentication methods the employee does not recognise, such as an unfamiliar authenticator registration or phone number. If the employee approved an MFA request they did not initiate, treat the account particularly seriously.
The employee approved an MFA request – what should we do?
If an employee approved an unexpected Microsoft Authenticator request, entered an MFA code into a phishing website or otherwise completed the second stage of authentication, assume the attacker may have successfully signed in.
Secure the account, change the password, revoke sessions and establish what the attacker may have accessed after authentication. MFA is extremely valuable, but it is not magic if the user is persuaded to hand over both factors.
Check Outlook forwarding and inbox rules
This is one of the most important checks after a Microsoft 365 phishing attack or suspected business email compromise.
Attackers can create rules that forward messages elsewhere, delete selected emails, hide replies or move messages into unusual folders. That can allow them to quietly monitor invoices, payment conversations and other valuable correspondence.
A compromised finance mailbox is particularly dangerous. An attacker may wait inside a genuine supplier conversation and later send “updated bank details”. That is much more convincing than a random phishing message arriving from nowhere.
Check Sent Items and Deleted Items
Look for messages the employee does not recognise, including in Sent Items and Deleted Items. Attackers sometimes delete messages after sending them in an attempt to hide their activity.
If fraudulent messages were sent from the account, you may need to warn recipients, particularly where invoices, payment requests or password links were involved.
What if the employee downloaded a file from the phishing email?
This is a different problem. If an employee downloaded or opened a suspicious attachment, the risk is not limited to the email account. The computer itself may need investigating.
If malware is genuinely suspected, stop normal use of the machine and contact whoever manages your IT. Depending on the circumstances, isolating the device from the network may be appropriate until it has been checked.
Do not continue logging into banking, Microsoft 365, accounting systems or other sensitive services from a computer you believe may be compromised.
What if the employee entered banking or card details?
Contact the relevant bank or payment provider immediately. Do not wait for the IT investigation to finish first.
If money has been transferred or fraud has occurred, the incident may also need reporting through the UK's Report Fraud service. The faster a fraudulent payment is identified, the better the chance of stopping or tracing it.
Should we disconnect the employee's computer from the internet?
Not automatically. If somebody simply opened a phishing webpage and entered a password, the main problem may be the online account rather than the computer.
If they downloaded or executed a suspicious file, the situation is different and the device may need isolating while it is investigated. The response should fit what actually happened.
Should we change everybody's passwords?
Usually, no. If one user entered their password into a phishing website, resetting every employee's password can create considerable disruption without addressing the real problem.
Start with the affected account and investigate. The situation changes if evidence suggests several accounts were compromised, passwords were reused, an administrator account was affected or the attacker gained wider access.
What if the same password was used somewhere else?
Those accounts must also be considered exposed. Password reuse turns one stolen password into several potential compromises.
This is one reason businesses should use unique passwords and a reputable password manager rather than variations of the same password across several services.
Does MFA protect us from phishing?
MFA makes a very significant difference, but it does not make phishing impossible. More sophisticated attacks can attempt to capture authentication sessions or persuade the employee to approve an MFA request.
Good security is layered: MFA, email security, managed devices, endpoint protection, updates, sensible administrator permissions, reliable backup and monitoring all contribute. No single product solves the whole problem.
Should the employee be blamed for clicking the phishing email?
No. That is not simply politeness. It is good security practice.
Employees who fear being blamed may be less likely to report mistakes quickly. You want people to say “I think I've clicked something I shouldn't have” within two minutes rather than two days.
Speed is far more useful than blame.
Does a phishing attack need to be reported to the ICO?
Not every phishing incident is a reportable personal data breach. Clicking a phishing link by itself does not automatically mean you need to contact the Information Commissioner's Office.
You first need to establish whether personal data was compromised and assess the risk to the people affected. Under UK GDPR, certain personal data breaches must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Not every breach reaches the reporting threshold, but the incident and the decision should be documented.
Should we report the phishing email?
Suspicious emails can be forwarded to the UK's National Cyber Security Centre at report@phishing.gov.uk. Suspicious text messages can be forwarded to 7726.
If the business has actually lost money or been affected by fraud or cyber crime, the incident can also be reported through Report Fraud.
How quickly do we need to respond to a phishing incident?
Immediately. That does not mean every incident requires a dramatic emergency response.
It means establishing what happened while the information is fresh and before an attacker has more time to use any stolen access.
- What did the employee click?
- What did they enter?
- Did they approve MFA?
- Did they download or open anything?
- When did it happen?
- Which account and device were involved?
What are the signs that a Microsoft 365 account has been hacked?
Common warning signs can include unusual sign-ins, unfamiliar MFA methods, unexpected password changes, strange Sent Items, missing messages, new forwarding settings, suspicious inbox rules and colleagues receiving messages the genuine user did not send.
One particularly useful warning is a customer or supplier asking, “Did you really send this?” Do not dismiss that message. Investigate it.
Business email account hacked – what should we do?
If you believe a business email account has been hacked, treat it as an incident rather than simply a password problem.
Secure the account first, then establish what happened while the attacker had access. A Microsoft 365 identity may provide access not only to email but potentially OneDrive, SharePoint, Teams and other company services.
The investigation should answer two separate questions: Can the attacker still get in? and What did the attacker do while they could get in?
How can a small business prevent this happening again?
The aim should not be to create a business where nobody ever clicks a suspicious link. That is unrealistic. The better aim is to create a business where one bad click does not become a catastrophe.
That means sensible layers of protection: MFA, email security, endpoint protection, supported and patched devices, backup, limited administrator permissions, monitoring and a clear reporting process.
The technology matters. So does the process around it.
Frequently asked questions about phishing incidents
I clicked a phishing link but didn't enter any information. Am I safe?
The risk is lower if the page was opened but no information was entered, nothing was downloaded and no authentication request was approved. The incident should still be reported so the link and device can be checked.
An employee entered their Microsoft 365 password into a phishing site. What should we do?
Treat the password as compromised. Secure the account, reset the password, revoke existing sessions and investigate sign-ins, MFA methods, inbox rules, forwarding and other account activity.
Is changing the Microsoft 365 password enough after phishing?
Not necessarily. Existing authenticated sessions can remain relevant, so administrators should also consider revoking the affected user sessions and then review the account for signs of compromise.
What if the employee approved an MFA notification?
Treat the account as potentially compromised. Secure it immediately, revoke sessions and investigate whether the attacker successfully signed in and what they may have accessed.
Can a phishing email infect a computer?
Yes. Some phishing attacks attempt to deliver malware through malicious downloads, attachments or websites. If a suspicious file was opened or executed, the device may need isolating and investigating.
Should a phishing incident be reported to the ICO?
Not every phishing incident is reportable. If it resulted in a personal data breach that is likely to present a risk to people, UK GDPR may require notification to the ICO within 72 hours of becoming aware of the breach. The assessment and decision should be documented.
Where can a UK business report a phishing email?
Suspicious emails can be forwarded to report@phishing.gov.uk. Where fraud or cyber crime has actually occurred, the business can also use the UK Report Fraud service.
Sources and further reading
Incident response depends on exactly what happened. The guidance above is aligned with current UK government, NCSC, ICO and Microsoft guidance.
An employee clicked a phishing link right now?
Do not spend the next hour hoping for the best.
Liugo can help establish what happened, secure the affected Microsoft 365 account, check for signs of compromise and explain the next steps in plain English.
Want to know how well your business would handle the next phishing attempt?
Liugo helps small and growing businesses improve Microsoft 365, device security, backup and day-to-day IT without unnecessary complexity.

