Password first, sessions second, mail rules third, report fourth. The order matters, and the first hour counts.
Resources / You Clicked a Phishing Link. What Should You
The first hour after a phishing click decides whether this becomes a bad moment or a bad month. If you entered a password, change it now from a different device, sign out every session, check for mail rules you didn't create, and report it. Australians lost $2.18 billion to scams in 2025, and phishing remains one of the most reported attack types.4 Here is the playbook, in order.
the window where fast action beats the attacker's automation
password, sessions, mail rules, report, in that order
lost by Australians to scams in 2025, per the Targeting Scams report
Triage first. Clicked but entered nothing and downloaded nothing: lower risk. Modern browsers isolate most drive-by tricks; still do steps two and three below, because some pages steal session cookies rather than passwords. Entered a password: treat the account as compromised and work the full playbook now. Downloaded or ran a file: different problem. Disconnect the machine from the network and get it scanned before it touches anything else.1
Because the profitable phish is patient. The attacker who gets into a business mailbox rarely announces it; they set a quiet forwarding rule and read your invoices for a month, then send your customers a "we've changed bank accounts" email that looks exactly like yours. Business email compromise costs Australian businesses more than almost any other scam type, and a thirty-second check of mail rules is the countermeasure.4
If the phished password was reused anywhere, those accounts are burned too; attackers try stolen passwords everywhere within hours. Change every account that shared it, then fix the underlying problem: a password manager generating a different password per site turns one stolen credential from a skeleton key into a dud.
If customer data may have been exposed, an Australian business can have notification obligations under the Privacy Act, and if money moved, time matters enormously: banks can sometimes recall transfers caught within hours. When in doubt, report through ReportCyber2 and get help; pretending it did not happen is the only unrecoverable mistake.
Multi-factor authentication everywhere is the single biggest step: it is the first control on the Essential Eight priority list for a reason, because a phished password without the second factor is mostly a dead end for the attacker. After that: a password manager, and a team culture where "I think I clicked something" is reported in minutes without embarrassment. The person who reports fast is the hero of this story, not the problem.
Essential Eight for small business: MFA is control number one for exactly this reason.
Does Microsoft back up my emails?: what an attacker in your mailbox can and cannot destroy.
All resources: tools, guides and case studies.
Probably, but not certainly. Some phishing pages attempt to steal active session cookies rather than passwords. Sign out of your sessions, watch the account's sign-in activity for a few days, and get the device scanned if anything downloaded.
Yes. MFA blocks most abuse of a stolen password, but sophisticated phishing kits capture session tokens that ride around MFA. Change the password and sign out all sessions; the two together close the door.
Only if a file was downloaded and run. A credentials phish lives in the account, not the machine. A malware infection lives in the machine, and that is when isolation and a proper scan, or a rebuild, is warranted.
ReportCyber for cybercrime affecting your business, and Scamwatch for scams generally. If financial details were involved, contact your bank first; recalls are time-sensitive.
Check for mail rules and forwarding you did not create, look at the account's recent sign-in activity for unfamiliar locations, and check the Sent folder for messages you did not write. Any one of those is confirmation, not suspicion.
General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. If you have been scammed or breached, contact your bank, call IDCARE on 1800 595 160, and report it via ReportCyber at cyber.gov.au. For help securing your business, get in touch.
Tell us what happened and when. We'll help you work out what was exposed, close the doors that matter, and set up the controls that stop the sequel. Same-day response for active incidents.
Prefer to talk? Call (02) 9053 8789.