Expert Tips

An Employee Clicked a Phishing Link. What Should You Do Next?

September 6, 2026

A phishing click does not automatically mean a breach, but the first response matters. Here is a practical containment and investigation sequence for businesses.

Phishing incident response after an employee clicks a malicious link

An employee clicking a phishing link does not automatically mean the company has been breached. The risk depends on what happened next: whether credentials were entered, a file was downloaded, an MFA prompt was approved, or malicious code executed.

The most useful response is fast, calm, and evidence-based.

1. Tell the employee to report exactly what happened

Do not begin by blaming the employee. You need accurate details quickly.

Ask what they clicked, whether a website opened, whether they typed a username or password, whether they downloaded or opened a file, whether they approved an MFA prompt, and what device they were using.

2. Preserve the phishing message

Keep the original email or message if possible. Security teams may need sender information, headers, URLs, attachments, timestamps, or other indicators.

A screenshot can be helpful, but the original message usually contains more useful evidence.

3. If credentials were entered, treat the account as potentially compromised

Reset or secure the affected credentials through the approved administrative process. Revoke active sessions or tokens where supported so an attacker cannot continue using a session established before the password change.

Review MFA methods and recent authentication activity for unexpected changes or approvals.

4. Review Microsoft 365 or email activity

For a Microsoft 365 account, investigate suspicious sign-ins, unexpected inbox rules, external forwarding, unusual sent messages, changed MFA methods, new application consent, or other activity inconsistent with the user.

If the account has administrative privileges, escalate immediately because the potential impact is much broader.

5. If a file was opened or software executed, investigate the device

Endpoint security tools may show detections or suspicious processes. Depending on the event, the device may need to be isolated from the network while it is investigated.

Do not assume a clean antivirus scan proves nothing happened. The investigation should reflect the actual attachment, behavior, and security telemetry available.

6. Check whether the phishing campaign reached other employees

Search for the same sender, subject, URL, attachment, or other indicators across the organization if your tools allow it.

Removing related messages can reduce the chance that another employee interacts with the same campaign.

7. Identify sensitive access tied to the account

Consider what the compromised identity could reach: email, SharePoint, OneDrive, financial systems, client applications, password managers, SaaS platforms, or SSO-connected tools.

If the user has authority to approve payments or access confidential information, involve the appropriate leadership and business owners.

8. Watch for business email compromise

Attackers sometimes use a compromised mailbox to request payment changes, payroll updates, gift cards, or confidential information. Review recent sent mail and warn finance or leadership if the account could plausibly be used for fraud.

9. Document what happened

Record the message, employee actions, timeline, affected account or device, containment steps, findings, and any follow-up work. Documentation is useful for future security improvements, insurance reporting, or escalation.

10. Decide whether outside incident-response support is required

Escalate when there is evidence of broader compromise, ransomware, data exposure, privileged account takeover, financial fraud, persistent malicious activity, or uncertainty beyond the internal team's capability.

Legal, regulatory, insurance, and notification obligations depend on the specific incident and should be evaluated with the appropriate advisors.

After containment, improve the process

Review why the message was convincing, whether the user knew how to report it, whether identity and endpoint controls worked, and whether the response team had the access it needed.

The goal of security awareness is not a zero-click workforce. It is faster recognition, reporting, and containment when mistakes happen.

Our security awareness training guide covers the employee side, while Managed Cybersecurity Services explains the technical controls that support incident readiness.

PUT THE GUIDANCE TO WORK

Need help applying this to your environment?

Two Factor can help assess the current setup, identify what actually matters, and turn the recommendation into a practical plan for your team.