Incident response
Someone Clicked a Phishing Link
Quick answer
Treat a clicked phishing link as a signal to secure the account and preserve evidence, even when nothing looks wrong yet.
Who this is for: Teams responding to a suspicious message or link.
What to do
- 01Tell the person to stop interacting with the message and report it.
- 02Secure the affected account, revoke sessions where appropriate, and enable MFA.
- 03Check sign-ins, forwarding rules, and recent changes.
- 04Preserve the message, links, timestamps, and logs before deleting evidence.
What this does not cover
The correct response depends on the account, provider, data, and actions taken. Get professional help if credentials or sensitive data may be exposed.
This page is educational information, not legal advice or a professional security audit. Check the official requirements and get qualified help when your circumstances require it.
Continue exploring