GUIDE · 10 September 2026
What to do in the first hour after a phishing email is clicked
Someone in your organisation clicked the link and typed their password. The next sixty minutes decide whether this is a bad afternoon or a very bad month. A practical, ordered checklist for small organisations.
It's a Tuesday afternoon. Someone on your team has just come to you, or messaged you, and said the sentence every organisation dreads: "I think I clicked on something I shouldn't have." They followed a link in an email that looked like a shared file, or an invoice, or a message from the boss, and they typed their password into a page that wasn't yours.
Take a breath. This happens to good people at careful organisations every day, and the outcome depends far less on the click than on what you do in the next hour. Here is that hour, in the order that matters. It assumes Microsoft 365, because that's what most small organisations run, but the principles hold everywhere.
First: thank them, and don't wait
The single most damaging thing a person can do after clicking is stay quiet for a day because they're embarrassed. Your colleague told you; that is the best possible outcome of a bad situation. Say so. Then act immediately, because the attacker is already inside the account and is typically working fast: setting up forwarding rules, reading email for payment details, and sending the same phishing message to everyone in the contact list, from a trusted address.
Minute 0 to 10: reset the password and kill the sessions
Resetting the password alone is not enough. The attacker's browser may still be logged in with a valid session token, and a password change does not always end it. Do both:
- Reset the user's password from the admin centre (not by having them do it on the possibly compromised device).
- In Microsoft Entra (the identity part of Microsoft 365), open the user and choose Revoke sessions. This signs them out everywhere, including the attacker.
- If multi-factor authentication isn't on for this account, turn it on now. If it is, check the registered methods and remove any phone number or authenticator you don't recognise: attackers add their own so they can get back in after the reset.
Minute 10 to 25: look for what the attacker left behind
A compromised mailbox is rarely just read. Check, in this order, and remove anything you didn't create:
- Inbox rules. Attackers create rules that move replies to RSS Feeds or Deleted Items, or delete anything containing "invoice", "password" or "suspicious", so the victim never sees the warnings. Look in the user's Outlook rules and in the admin centre.
- Forwarding. A forward to an external address means every future email is being copied out. Check both the mailbox forwarding setting and rules that forward.
- Sent items. Has the account sent messages the user doesn't recognise? Those recipients are your next victims, and your next phone calls.
- OAuth app consents. Some phishing tricks the user into granting an app permanent access to their mailbox, which survives password resets. Review enterprise applications and revoke anything unfamiliar.
- Sign-in logs. Where has this account signed in from in the last 48 hours? A login from a country you don't operate in tells you when the compromise started, which matters for the next step.
Minute 25 to 40: contain the spread
If the account sent phishing to others, warn them now, by a channel that isn't email if you can (a call, Teams, a text): "If you received a file share from me today, don't open it." Ask anyone who did click to tell you, without blame. Repeat the first two sections for each of them. If the attacker reached a shared mailbox or a distribution list, treat those the same way.
Check whether the compromised account had access to anything that matters beyond email: finance systems, the CRM, cloud storage with client data, admin rights. If it did, assume the attacker looked, and involve whoever owns those systems.
Minute 40 to 60: the money question, and reporting
The most common real-world consequence of a compromised mailbox is invoice fraud: the attacker reads a conversation about a payment, then sends a "we've changed our bank details" email that looks entirely legitimate. Call, don't email, any supplier or client the account was corresponding with about money. Confirm nothing has been changed. Tell your bank if any payment might be in flight.
Then report. In the UK, report to Action Fraud, and if personal data may have been accessed, you may have an obligation to notify the ICO within 72 hours; make a note now of what you know and when you knew it. If you hold Cyber Essentials or have cyber insurance, check your notification requirements, as most policies expect to hear within a fixed window. Forward the original phishing email to the NCSC's Suspicious Email Reporting Service (report@phishing.gov.uk) so it can be taken down for everyone else.
After the hour: the things that stop it happening twice
Once the immediate danger is contained, the useful questions are structural. Was MFA enforced for everyone, or just recommended? Are there conditional access rules that block sign-ins from countries you don't work in? Is external forwarding blocked at the tenant level (it should be)? Is there any monitoring that would have flagged the new inbox rule the moment it was created, rather than an hour later when a human noticed? Do staff get short, regular, non-patronising training with real examples?
These are the controls that turn a compromised password from a crisis into a non-event: the attacker has the password and still gets nowhere. They are also, not coincidentally, most of what Cyber Essentials asks for. If you'd like to know where you stand, our free Cyber Essentials readiness check takes a few minutes.
The one-page version
- Thank the person. Act now.
- Reset the password from the admin centre. Revoke all sessions. Check and clean MFA methods.
- Remove unknown inbox rules, forwarding and app consents. Read sent items and sign-in logs.
- Warn anyone the account emailed. Repeat for anyone who clicked.
- Phone every counterparty in a money conversation. Tell the bank if needed.
- Report: Action Fraud, ICO if personal data is involved, insurer, NCSC.
- Then fix the controls so the next click doesn't matter.
If you're reading this because it's happening right now and you'd like a second pair of hands, get in touch; we've done this many times and can work through it with you the same day.