UK IT & website support · plans from £25/month · £45/hour ad-hoc01623 650333 · Client login
Get help

Clicked a Phishing Link? What To Do Now

If you clicked a phishing link, act straight away: disconnect the device if you downloaded anything, change the password from a different device, sign out all sessions, turn on MFA and check for new inbox rules or forwarding. Report the email to report@phishing.gov.uk. dijitul secures compromised accounts for UK businesses at £45 an hour + VAT.

Updated 2026-10-10 · by the dijitul support team, Mansfield, UK

Key facts

  • Clicking alone is usually lower risk than entering a password or opening a downloaded file
  • Attackers often add hidden inbox rules that forward or delete mail so they can stay unnoticed
  • Changing a password does not end existing sessions; you also need to sign out everywhere or revoke sessions
  • Suspicious emails can be forwarded to the NCSC at report@phishing.gov.uk, and scam texts to 7726
  • Report Fraud replaced Action Fraud for England, Wales and Northern Ireland in December 2025
  • The UK Government's Cyber Security Breaches Survey 2025/26 found phishing affected 38% of businesses, by far the most common attack
  • dijitul investigates and secures compromised accounts at £45 an hour + VAT

First, work out what actually happened

Phishing is the most common attack UK businesses face. The UK Government's Cyber Security Breaches Survey 2025/26 found 38% of businesses had experienced phishing in the previous 12 months, by far the most prevalent type of breach or attack. What you need to do depends on how far you went:

  • You clicked but did nothing else: close the page. The risk is lower, but run a malware scan and stay alert.
  • You typed a password on the page: assume the account is compromised. Follow every step below.
  • You downloaded or opened a file, or allowed a 'remote support' tool: treat the device as infected.
  • You entered card or bank details: phone your bank immediately using the number on the back of your card.

Do not feel embarrassed. Modern phishing pages are convincing copies of Microsoft 365, DocuSign, couriers and HMRC. Speed matters far more than blame.

If you opened a file or installed something

  1. Disconnect the device from the network: unplug the cable and switch off Wi-Fi. Do not turn it off, because that can destroy evidence.
  2. Use a different, clean device for everything that follows.
  3. Tell whoever looks after your IT straight away.
  4. Run a full scan with Microsoft Defender or your antivirus once advised. If remote access software was installed, uninstall it and assume anything on the device could have been seen.

Keep a note of the time you clicked, what the email said and what you did next. It helps whoever investigates work out what the attacker could have reached.

If you entered your password

  1. Change the password from a different device, and anywhere else you used the same password.
  2. Sign out everywhere. In Microsoft 365, an administrator can revoke sessions for the user in the Entra admin centre; users can use Sign out everywhere in their My Account page. Otherwise the attacker's existing session keeps working after the password change.
  3. Turn on MFA and check the registered methods for any phone or app you do not recognise. Our guide on how to enable MFA in Microsoft 365 explains how.
  4. Check inbox rules and forwarding. In Outlook on the web, open Settings, Mail, Rules and Forwarding. Attackers often create rules that forward invoices to them or move replies into a little-used folder such as RSS Feeds or Archive.
  5. Check Sent Items and Deleted Items for emails you did not send. If the attacker sent phishing from your account, warn your contacts.
  6. Check app permissions for unfamiliar third-party apps you were tricked into approving.

An administrator should also review the Entra sign-in logs for sign-ins from unexpected countries and the unified audit log for mailbox activity.

Report it

  • Forward the phishing email to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk. Forward scam texts to 7726.
  • If you lost money or data, report it to Report Fraud, which replaced Action Fraud for England, Wales and Northern Ireland in December 2025, online at reportfraud.police.uk or on 0300 123 2040. In Scotland, call Police Scotland on 101.
  • If personal data about customers or staff may have been accessed, consider whether you must report a breach to the ICO, which must happen within 72 hours of becoming aware where reporting is required.
  • Use the Report button in Outlook so Microsoft's filters learn too.

When to call dijitul

Call us as soon as a password has been entered, a file has been opened, or you see emails you did not send. We secure the account, revoke sessions, remove malicious rules and app consents, check sign-in logs, scan devices and tell you plainly what the attacker could have seen, at £45 an hour + VAT. See phishing protection and cyber security support, or contact us now.

To reduce the chances next time, combine MFA with staff security training and properly configured email authentication: see set up SPF, DKIM and DMARC.

Frequently asked questions

I clicked a phishing link but did not enter anything. Am I safe?

Usually the risk is low if you only opened the page and entered nothing. Close it, clear your browser's recent downloads, run a malware scan and watch for unusual activity. If anything downloaded or you allowed a browser notification or extension, ask your IT support to check the device.

What should I do if I entered my Microsoft 365 password on a fake page?

Change the password from another device, revoke all sessions, turn on MFA, check for new inbox rules and forwarding, review Sent Items and remove any unknown MFA methods or app permissions. An administrator should check the sign-in logs. dijitul can do all of this for £45 an hour + VAT.

Why do attackers create inbox rules?

Rules let attackers stay hidden and profit. A common rule moves replies from your contacts into an obscure folder, so you do not see warnings, or forwards emails containing words like invoice or payment so they can send fake bank details. Always check rules after a compromise.

Where do I report a phishing email in the UK?

Forward phishing emails to the NCSC at report@phishing.gov.uk and scam texts to 7726. If you have lost money or data, report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales and Northern Ireland, or to Police Scotland on 101.

Is changing my password enough after a phishing attack?

No. Changing the password does not always end sessions the attacker already has, and they may have added inbox rules, forwarding, an MFA method or app permissions that survive a password change. Revoke sessions and check each of these as well.

Do I need to report a phishing incident to the ICO?

Only if personal data was breached and the breach is likely to risk people's rights and freedoms. If so, UK GDPR requires reporting to the ICO within 72 hours of becoming aware. Record your reasoning either way. Take advice if customer or staff data was in the mailbox.

Related

Get it fixed

One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.

Call usGet help now