.png)
Email & Identity Security
What to Do When a Phishing Attack Happens
In this guide:
- What a phishing attack is
- How to spot signs of a phishing incident
- What to do immediately after a phishing attack
- What to do if someone clicked a link or entered details
- What to avoid during a phishing incident
- Who to notify after a phishing attack
- How to prevent future phishing attacks
- How IT Desk can help with phishing protection and email security
TL;DR
If a phishing attack happens, act quickly to understand what was clicked, opened or shared. Report the message internally, preserve evidence, reset compromised passwords, revoke suspicious sessions, check for mailbox rules or forwarding changes, and contact IT support if an account or device may be compromised.
Key Takeaways
A phishing attack can involve fake emails, messages, websites, QR codes, calls or attachments designed to steal information or access.
The response depends on whether someone only received the message, clicked a link, entered credentials, opened an attachment or shared sensitive information.
If login details were entered, change the password, enable MFA, sign out of active sessions and review sign-in activity.
If an attachment was opened, isolate the device and contact IT support before continuing to use it.
If money or banking details were shared, contact the bank immediately.
Businesses should assess whether personal data or sensitive information was exposed.
IT Desk can help businesses improve phishing protection, Microsoft 365 security, user awareness and account compromise response.
When does phishing become a reportable incident?
Phishing itself isn’t always reportable, but it can become one if:
Personal data is accessed or exfiltrated
Financial fraud occurs
The attacker gains access to sensitive systems
In these cases, legal and regulatory guidance may be required.
Note: This is general guidance, not legal advice.
Preventing future phishing attacks
Most successful phishing incidents exploit a combination of:
Weak or missing MFA
Over-privileged users
Poor visibility into login activity
Lack of user awareness
Key controls include:
MFA for all users (especially admins)
Conditional access policies
Regular user awareness training
Strong email filtering
Monitoring for suspicious sign-ins and rule changes
Signs the attacker may still have access
After remediation, watch for:
Reappearing mailbox rules
Repeated MFA prompts
New OAuth app permissions
Logins from unfamiliar locations
Unexpected password reset requests
If any appear, treat it as an active incident.
People Also Ask
What should a business do first after a phishing attack?
The first step is to understand what happened. Check whether the message was only received, whether a link was clicked, whether login details were entered, whether an attachment was opened or whether money or sensitive data was shared. Report the incident internally and contact IT support if an account or device may be compromised.
What should I do if I clicked a phishing link?
If you clicked a phishing link, do not enter any more information. Close the page, report the incident and tell your IT support team. If you entered login details, change the password immediately from a trusted device, enable multi-factor authentication and sign out of active sessions.
What should I do if I entered my password into a phishing site?
Change the password immediately, making sure the new password is strong and unique. Sign out of all active sessions, enable multi-factor authentication, check account recovery details, review sign-in activity and look for suspicious mailbox rules or forwarding settings. For a business account, an administrator should review the account.
Can a phishing attack cause a data breach?
Yes. A phishing attack can cause a data breach if personal data, customer information, employee records, financial information or sensitive business data is accessed, disclosed or stolen. Businesses should assess what information may have been exposed and whether reporting obligations apply.
Should we warn customers or suppliers after a phishing attack?
You should warn customers, suppliers or contacts if suspicious emails may have been sent from a compromised account, or if their information may be at risk. The message should be clear, factual and explain what action they should take, such as ignoring suspicious emails or not clicking links.
How can businesses prevent phishing attacks?
Businesses can reduce phishing risk with email filtering, multi-factor authentication, user awareness training, secure password policies, Microsoft 365 security configuration, monitoring, phishing simulations and clear reporting processes for suspicious messages.
Can IT Desk help after a phishing attack?
Yes. IT Desk can help businesses respond to phishing incidents by reviewing account access, checking Microsoft 365 sign-ins, removing suspicious forwarding rules, improving MFA, strengthening email security and supporting users after a suspected compromise.
Need help improving phishing protection?
IT Desk helps businesses reduce phishing risk with email security, Microsoft 365 protection, multi-factor authentication, user awareness training and account compromise response. We can review your current setup, strengthen controls and help protect your users from future phishing attacks.
What is a phishing attack?
A phishing attack is when attackers impersonate a trusted sender — such as a colleague, supplier, bank, or Microsoft — to trick users into clicking malicious links, opening attachments, or entering login details.
Modern phishing attacks are increasingly convincing. They often:
Use real branding and language
Target Microsoft 365 and cloud logins
Lead to follow-on attacks such as ransomware, invoice fraud, or data theft
Phishing is now one of the most common entry points for wider cyber incidents.
First signs of a phishing incident
You may be dealing with a phishing attack if:
A user clicked a suspicious link or entered credentials
A login alert appears from an unusual location
Emails are sent from an account the user didn’t send
Mailbox rules appear that forward or hide emails
MFA prompts appear unexpectedly
Even if “nothing seems wrong”, phishing incidents should always be treated seriously.
Immediate actions (first 15–30 minutes)
Change the affected user’s password immediately Start with email and Microsoft 365. If the password is reused elsewhere, change those too.
Revoke active sessions Force sign-out across devices to remove attacker access.
Check MFA status
Confirm MFA is enabled
Look for newly added authentication methods (phone numbers, apps)
Preserve evidence
Save the phishing email (including headers if possible)
Screenshot login alerts or suspicious activity
Note the time and user affected
Assess what the attacker may have done
Once credentials are compromised, attackers often move quickly.
Check for:
Mailbox rules that auto-forward or delete emails
OAuth app permissions added without approval
Admin role changes
Internal phishing emails sent from the compromised account
Unusual file access in SharePoint or OneDrive
Login attempts from multiple countries
This step determines whether the incident is limited or part of a wider breach.
What NOT to do
Don’t ignore it because “nothing happened.” Many attacks are quiet at first.
Don’t just change the password and move on. Access may persist elsewhere.
Don’t blame the user. Fear reduces reporting and increases risk next time.
Containment and remediation
After initial response:
Reset passwords for affected users and any linked admin accounts
Review and tighten MFA and conditional access policies
Remove unauthorised mailbox rules and app permissions
Check whether phishing was delivered to other users
Update email filtering rules if needed
Why this matters
A phishing attack can quickly put business email accounts, passwords, devices, data and money at risk. Some phishing attempts are easy to spot, while others appear to come from trusted suppliers, colleagues, banks, delivery companies or cloud services.
This guide explains what to do when a phishing attack happens, how to respond if someone clicked a link or entered details, what mistakes to avoid, and how businesses can reduce the risk of future phishing incidents.


Written by:
Steve Harper
Commercial Director
Need help improving phishing protection?
IT Desk helps businesses reduce phishing risk with email security, Microsoft 365 protection, multi-factor authentication, user awareness training and account compromise response. We can review your current setup, strengthen controls and help protect your users from future phishing attacks.
Relating Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.










