top of page
it support sheffield

Email & Identity Security

What to Do When a Phishing Attack Happens

In this guide:

- What a phishing attack is


- How to spot signs of a phishing incident


- What to do immediately after a phishing attack


- What to do if someone clicked a link or entered details


- What to avoid during a phishing incident


- Who to notify after a phishing attack


- How to prevent future phishing attacks


- How IT Desk can help with phishing protection and email security

TL;DR

If a phishing attack happens, act quickly to understand what was clicked, opened or shared. Report the message internally, preserve evidence, reset compromised passwords, revoke suspicious sessions, check for mailbox rules or forwarding changes, and contact IT support if an account or device may be compromised.


Key Takeaways

  • A phishing attack can involve fake emails, messages, websites, QR codes, calls or attachments designed to steal information or access.

  • The response depends on whether someone only received the message, clicked a link, entered credentials, opened an attachment or shared sensitive information.

  • If login details were entered, change the password, enable MFA, sign out of active sessions and review sign-in activity.

  • If an attachment was opened, isolate the device and contact IT support before continuing to use it.

  • If money or banking details were shared, contact the bank immediately.

  • Businesses should assess whether personal data or sensitive information was exposed.

  • IT Desk can help businesses improve phishing protection, Microsoft 365 security, user awareness and account compromise response.

When does phishing become a reportable incident?

Phishing itself isn’t always reportable, but it can become one if:

  • Personal data is accessed or exfiltrated

  • Financial fraud occurs

  • The attacker gains access to sensitive systems


In these cases, legal and regulatory guidance may be required.


Note: This is general guidance, not legal advice.


Preventing future phishing attacks

Most successful phishing incidents exploit a combination of:

  • Weak or missing MFA

  • Over-privileged users

  • Poor visibility into login activity

  • Lack of user awareness


Key controls include:

  • MFA for all users (especially admins)

  • Conditional access policies

  • Regular user awareness training

  • Strong email filtering

  • Monitoring for suspicious sign-ins and rule changes


Signs the attacker may still have access

After remediation, watch for:

  • Reappearing mailbox rules

  • Repeated MFA prompts

  • New OAuth app permissions

  • Logins from unfamiliar locations

  • Unexpected password reset requests


If any appear, treat it as an active incident.


People Also Ask

What should a business do first after a phishing attack?

The first step is to understand what happened. Check whether the message was only received, whether a link was clicked, whether login details were entered, whether an attachment was opened or whether money or sensitive data was shared. Report the incident internally and contact IT support if an account or device may be compromised.


What should I do if I clicked a phishing link?

If you clicked a phishing link, do not enter any more information. Close the page, report the incident and tell your IT support team. If you entered login details, change the password immediately from a trusted device, enable multi-factor authentication and sign out of active sessions.


What should I do if I entered my password into a phishing site?

Change the password immediately, making sure the new password is strong and unique. Sign out of all active sessions, enable multi-factor authentication, check account recovery details, review sign-in activity and look for suspicious mailbox rules or forwarding settings. For a business account, an administrator should review the account.


Can a phishing attack cause a data breach?

Yes. A phishing attack can cause a data breach if personal data, customer information, employee records, financial information or sensitive business data is accessed, disclosed or stolen. Businesses should assess what information may have been exposed and whether reporting obligations apply.


Should we warn customers or suppliers after a phishing attack?

You should warn customers, suppliers or contacts if suspicious emails may have been sent from a compromised account, or if their information may be at risk. The message should be clear, factual and explain what action they should take, such as ignoring suspicious emails or not clicking links.


How can businesses prevent phishing attacks?

Businesses can reduce phishing risk with email filtering, multi-factor authentication, user awareness training, secure password policies, Microsoft 365 security configuration, monitoring, phishing simulations and clear reporting processes for suspicious messages.


Can IT Desk help after a phishing attack?

Yes. IT Desk can help businesses respond to phishing incidents by reviewing account access, checking Microsoft 365 sign-ins, removing suspicious forwarding rules, improving MFA, strengthening email security and supporting users after a suspected compromise.

Need help improving phishing protection?


IT Desk helps businesses reduce phishing risk with email security, Microsoft 365 protection, multi-factor authentication, user awareness training and account compromise response. We can review your current setup, strengthen controls and help protect your users from future phishing attacks.



What is a phishing attack?

A phishing attack is when attackers impersonate a trusted sender — such as a colleague, supplier, bank, or Microsoft — to trick users into clicking malicious links, opening attachments, or entering login details.


Modern phishing attacks are increasingly convincing. They often:

  • Use real branding and language

  • Target Microsoft 365 and cloud logins

  • Lead to follow-on attacks such as ransomware, invoice fraud, or data theft


Phishing is now one of the most common entry points for wider cyber incidents.


First signs of a phishing incident

You may be dealing with a phishing attack if:

  • A user clicked a suspicious link or entered credentials

  • A login alert appears from an unusual location

  • Emails are sent from an account the user didn’t send

  • Mailbox rules appear that forward or hide emails

  • MFA prompts appear unexpectedly


Even if “nothing seems wrong”, phishing incidents should always be treated seriously.


Immediate actions (first 15–30 minutes)

  1. Change the affected user’s password immediately Start with email and Microsoft 365. If the password is reused elsewhere, change those too.

  2. Revoke active sessions Force sign-out across devices to remove attacker access.

  3. Check MFA status

  4. Confirm MFA is enabled

  5. Look for newly added authentication methods (phone numbers, apps)

  6. Preserve evidence

  7. Save the phishing email (including headers if possible)

  8. Screenshot login alerts or suspicious activity

  9. Note the time and user affected


Assess what the attacker may have done

Once credentials are compromised, attackers often move quickly.


Check for:

  • Mailbox rules that auto-forward or delete emails

  • OAuth app permissions added without approval

  • Admin role changes

  • Internal phishing emails sent from the compromised account

  • Unusual file access in SharePoint or OneDrive

  • Login attempts from multiple countries


This step determines whether the incident is limited or part of a wider breach.


What NOT to do

Don’t ignore it because “nothing happened.” Many attacks are quiet at first.

Don’t just change the password and move on. Access may persist elsewhere.

Don’t blame the user. Fear reduces reporting and increases risk next time.


Containment and remediation

After initial response:

  • Reset passwords for affected users and any linked admin accounts

  • Review and tighten MFA and conditional access policies

  • Remove unauthorised mailbox rules and app permissions

  • Check whether phishing was delivered to other users

  • Update email filtering rules if needed

Why this matters

A phishing attack can quickly put business email accounts, passwords, devices, data and money at risk. Some phishing attempts are easy to spot, while others appear to come from trusted suppliers, colleagues, banks, delivery companies or cloud services.


This guide explains what to do when a phishing attack happens, how to respond if someone clicked a link or entered details, what mistakes to avoid, and how businesses can reduce the risk of future phishing incidents.

Phishing Attack Response
steve harper

Written by:

Steve Harper

Commercial Director

Need help improving phishing protection?


IT Desk helps businesses reduce phishing risk with email security, Microsoft 365 protection, multi-factor authentication, user awareness training and account compromise response. We can review your current setup, strengthen controls and help protect your users from future phishing attacks.



Relating Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

bottom of page