You Clicked a Phishing Link. What Should You Do in the First Hour?

Password first, sessions second, mail rules third, report fourth. The order matters, and the first hour counts.

Resources / You Clicked a Phishing Link. What Should You

The first hour after a phishing click decides whether this becomes a bad moment or a bad month. If you entered a password, change it now from a different device, sign out every session, check for mail rules you didn't create, and report it. Australians lost $2.18 billion to scams in 2025, and phishing remains one of the most reported attack types.4 Here is the playbook, in order.

1 hour

the window where fast action beats the attacker's automation

4 steps

password, sessions, mail rules, report, in that order

$2.18B

lost by Australians to scams in 2025, per the Targeting Scams report

Did you just click, or did you enter something?

Triage first. Clicked but entered nothing and downloaded nothing: lower risk. Modern browsers isolate most drive-by tricks; still do steps two and three below, because some pages steal session cookies rather than passwords. Entered a password: treat the account as compromised and work the full playbook now. Downloaded or ran a file: different problem. Disconnect the machine from the network and get it scanned before it touches anything else.1

The first hour, in order

  1. Change the password from a different device. If the attacker is already in, they may be watching the compromised one. Change the password of the account the phish imitated, and make it one you have never used anywhere else.
  2. Sign out every session. Microsoft 365 and Google both have a "sign out everywhere" control. A stolen password or session token is useless once every session is killed.
  3. Check mail rules and forwarding. In the account's settings, look for rules you did not create: auto-forwards to outside addresses, or rules that move replies to hidden folders. This is how attackers stay in a mailbox after the password changes.
  4. Report it. Businesses can report cybercrime through ReportCyber, and scams to Scamwatch.23 If bank or card details went in, ring the bank before anything else on this list.

Why do mail rules matter so much?

Because the profitable phish is patient. The attacker who gets into a business mailbox rarely announces it; they set a quiet forwarding rule and read your invoices for a month, then send your customers a "we've changed bank accounts" email that looks exactly like yours. Business email compromise costs Australian businesses more than almost any other scam type, and a thirty-second check of mail rules is the countermeasure.4

What about your other accounts?

If the phished password was reused anywhere, those accounts are burned too; attackers try stolen passwords everywhere within hours. Change every account that shared it, then fix the underlying problem: a password manager generating a different password per site turns one stolen credential from a skeleton key into a dud.

When is it more than an inconvenience?

If customer data may have been exposed, an Australian business can have notification obligations under the Privacy Act, and if money moved, time matters enormously: banks can sometimes recall transfers caught within hours. When in doubt, report through ReportCyber2 and get help; pretending it did not happen is the only unrecoverable mistake.

How do you stop the next one?

Multi-factor authentication everywhere is the single biggest step: it is the first control on the Essential Eight priority list for a reason, because a phished password without the second factor is mostly a dead end for the attacker. After that: a password manager, and a team culture where "I think I clicked something" is reported in minutes without embarrassment. The person who reports fast is the hero of this story, not the problem.

References

  1. Australian Signals Directorate, Phishing, cyber.gov.au.
  2. Australian Signals Directorate, Report a cybercrime, incident or vulnerability (ReportCyber), cyber.gov.au.
  3. National Anti-Scam Centre, Phishing scams, Scamwatch.
  4. National Anti-Scam Centre, Targeting Scams report (combined 2025 losses of $2.18 billion), Scamwatch.

Related resources

Essential Eight for small business: MFA is control number one for exactly this reason.
Does Microsoft back up my emails?: what an attacker in your mailbox can and cannot destroy.
All resources: tools, guides and case studies.

Frequently asked questions

I clicked the link but didn't type anything. Am I safe?

Probably, but not certainly. Some phishing pages attempt to steal active session cookies rather than passwords. Sign out of your sessions, watch the account's sign-in activity for a few days, and get the device scanned if anything downloaded.

I have MFA. Do I still need to change the password?

Yes. MFA blocks most abuse of a stolen password, but sophisticated phishing kits capture session tokens that ride around MFA. Change the password and sign out all sessions; the two together close the door.

Do we need to wipe the computer?

Only if a file was downloaded and run. A credentials phish lives in the account, not the machine. A malware infection lives in the machine, and that is when isolation and a proper scan, or a rebuild, is warranted.

Who do I report a phishing attack to in Australia?

ReportCyber for cybercrime affecting your business, and Scamwatch for scams generally. If financial details were involved, contact your bank first; recalls are time-sensitive.

How do I know if my email is already compromised?

Check for mail rules and forwarding you did not create, look at the account's recent sign-in activity for unfamiliar locations, and check the Sent folder for messages you did not write. Any one of those is confirmation, not suspicion.

General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. If you have been scammed or breached, contact your bank, call IDCARE on 1800 595 160, and report it via ReportCyber at cyber.gov.au. For help securing your business, get in touch.

Think something got in?

Tell us what happened and when. We'll help you work out what was exposed, close the doors that matter, and set up the controls that stop the sequel. Same-day response for active incidents.

Prefer to talk? Call (02) 9053 8789.