An Employee Clicked a Phishing Link. What Should You Do Next?
September 6, 2026
A phishing click does not automatically mean a breach, but the first response matters. Here is a practical containment and investigation sequence for businesses.

An employee clicking a phishing link does not automatically mean the company has been breached. The risk depends on what happened next: whether credentials were entered, a file was downloaded, an MFA prompt was approved, or malicious code executed.
The most useful response is fast, calm, and evidence-based.
1. Tell the employee to report exactly what happened
Do not begin by blaming the employee. You need accurate details quickly.
Ask what they clicked, whether a website opened, whether they typed a username or password, whether they downloaded or opened a file, whether they approved an MFA prompt, and what device they were using.
2. Preserve the phishing message
Keep the original email or message if possible. Security teams may need sender information, headers, URLs, attachments, timestamps, or other indicators.
A screenshot can be helpful, but the original message usually contains more useful evidence.
3. If credentials were entered, treat the account as potentially compromised
Reset or secure the affected credentials through the approved administrative process. Revoke active sessions or tokens where supported so an attacker cannot continue using a session established before the password change.
Review MFA methods and recent authentication activity for unexpected changes or approvals.
4. Review Microsoft 365 or email activity
For a Microsoft 365 account, investigate suspicious sign-ins, unexpected inbox rules, external forwarding, unusual sent messages, changed MFA methods, new application consent, or other activity inconsistent with the user.
If the account has administrative privileges, escalate immediately because the potential impact is much broader.
5. If a file was opened or software executed, investigate the device
Endpoint security tools may show detections or suspicious processes. Depending on the event, the device may need to be isolated from the network while it is investigated.
Do not assume a clean antivirus scan proves nothing happened. The investigation should reflect the actual attachment, behavior, and security telemetry available.
6. Check whether the phishing campaign reached other employees
Search for the same sender, subject, URL, attachment, or other indicators across the organization if your tools allow it.
Removing related messages can reduce the chance that another employee interacts with the same campaign.
7. Identify sensitive access tied to the account
Consider what the compromised identity could reach: email, SharePoint, OneDrive, financial systems, client applications, password managers, SaaS platforms, or SSO-connected tools.
If the user has authority to approve payments or access confidential information, involve the appropriate leadership and business owners.
8. Watch for business email compromise
Attackers sometimes use a compromised mailbox to request payment changes, payroll updates, gift cards, or confidential information. Review recent sent mail and warn finance or leadership if the account could plausibly be used for fraud.
9. Document what happened
Record the message, employee actions, timeline, affected account or device, containment steps, findings, and any follow-up work. Documentation is useful for future security improvements, insurance reporting, or escalation.
10. Decide whether outside incident-response support is required
Escalate when there is evidence of broader compromise, ransomware, data exposure, privileged account takeover, financial fraud, persistent malicious activity, or uncertainty beyond the internal team's capability.
Legal, regulatory, insurance, and notification obligations depend on the specific incident and should be evaluated with the appropriate advisors.
After containment, improve the process
Review why the message was convincing, whether the user knew how to report it, whether identity and endpoint controls worked, and whether the response team had the access it needed.
The goal of security awareness is not a zero-click workforce. It is faster recognition, reporting, and containment when mistakes happen.
Our security awareness training guide covers the employee side, while Managed Cybersecurity Services explains the technical controls that support incident readiness.