aNetworks. We live IT. We prove IT.
← BlogCyber SecurityJuly 29, 2026

An Employee Clicked a Phishing Email. Here Is What to Do Right Now.

If an employee clicked a phishing email, act in this order: disconnect that device from the network, change the affected passwords from a different device and turn on multi-factor authentication, then call your IT or security provider. Do not wipe the machine or delete the email. Most of the damage is preventable in the first hour.
Cyber Security

An Employee Clicked a Phishing Email. Here Is What to Do Right Now.

A calm, step-by-step response for the first hour: what to do first, how to tell if you were actually breached, and whether you have to report it.

By aNetworks, Inc. | July 29, 2026 | 7-minute read

Employee at an office desk examining a suspicious email on her phone next to a laptop

The first hour after a phishing click matters more than anything you do later.

It is a sickening moment. An employee walks over, a little pale, and says they clicked something they should not have, or typed their password into a page that turned out to be fake. Your mind jumps straight to the worst case. The good news: what you do in the next hour matters far more than the click itself, and you do not have to figure it out from scratch. Here is the calm checklist.

The Short Answer

Move in this order. 1) Disconnect the affected device from the network. 2) From a different, trusted device, change the affected passwords and turn on multi-factor authentication. 3) Check the email account for sneaky forwarding rules. 4) Call your IT or security provider and warn your team. Do not shut the machine off, delete the email, or try to clean it yourself.

First, figure out what actually happened

Not every click is a breach. The severity depends on what your employee actually did, so start there:

  • They clicked a link and closed the page. Lower risk, but still act. Some pages try to load malware the moment they open.
  • They entered a username and password. High risk. Assume those credentials are now in the attacker's hands and that account is compromised.
  • They opened an attachment, enabled content or macros, or the device is now acting strangely. Assume malware. Isolate that device immediately.

The first hour: what to do right now

  1. Disconnect the affected device from the network. Unplug the network cable and turn off Wi-Fi. Do not power it down, delete anything, or try to clean it yourself. Isolating it stops the spread and preserves evidence your provider will need.
  2. Change the passwords from a different, trusted device. Start with email, then anywhere that password was reused. Turn on multi-factor authentication everywhere it is not already on.
  3. Check the email account for rules and forwarding. Attackers often add a hidden rule that quietly copies or redirects your mail. Remove anything you did not set up yourself.
  4. Call your IT or security provider. Tell them exactly what was clicked, whether a password was entered, and what the email was asking for. Speed helps them contain it.
  5. Warn your team. A compromised account is often used to phish coworkers next. Tell everyone to be skeptical of unusual requests, especially about payments or passwords.
  6. Freeze money movement. If the email involved an invoice, a wire, or a change to payment details, confirm any request by phone using a number you already trust before anyone sends a cent.

Just as important, here is what not to do:

  • Do not reply to the email or click anything else inside it.
  • Do not delete it. Take a screenshot and keep it as evidence.
  • Do not pay anything or verify your account through a link in the message.
  • Do not keep using the affected account until the password is changed and your provider confirms it is clean.

How do I know if we were actually breached?

Some clicks are near misses. Watch for the signs that an attacker actually got in:

  • Login alerts or sign-ins from unfamiliar locations or devices.
  • New inbox rules or mail forwarding nobody set up.
  • Coworkers or customers getting strange emails from your account.
  • Password reset messages you did not request.
  • Invoices or payment details changing unexpectedly.
  • A device running slowly, showing pop-ups, or locking files with a ransom message.

If you see any of these, treat it as a confirmed breach and let your provider lead the response rather than improvising.

Do we have to report it?

It depends on what data was exposed, and this is one area not to guess on. In Massachusetts, businesses that hold residents' personal information have breach notification obligations under state law (M.G.L. c. 93H) when certain data is compromised. You may also owe notice to customers or business partners, and almost every cyber insurance policy requires prompt notification. You can also report cybercrime to the FBI's Internet Crime Complaint Center (IC3). Confirm your specific obligations with your IT or security provider, and an attorney where needed, before you decide what to disclose. This is general information, not legal advice.

Calling your provider early helps here too: waiting to report can complicate an insurance claim later.

How to make sure this does not happen again

Most real-world attacks are stopped by a short list of controls done consistently. You do not need an enterprise budget, you need the basics in place before the next click:

  • Multi-factor authentication on everything, especially email. It blocks most account takeovers even when a password is stolen.
  • Modern email filtering to catch phishing before it reaches an inbox.
  • Endpoint protection that detects and isolates threats automatically.
  • Regular, tested backups so ransomware becomes a recovery instead of a ransom.
  • Ongoing phishing training so your team is the last line of defense, not the weak point.

If owning that list alone feels like a lot, that is exactly what a managed cyber security partner handles day to day. If you think you have an active incident right now, reach out or call 781-871-0709, and do the first two steps above while you wait.

Frequently Asked Questions

What is the very first thing to do if someone clicked a phishing email?

Disconnect that device from the network. Then, from a different clean device, change the affected passwords and turn on multi-factor authentication. Do not wipe the machine or delete the email.

Should I shut the computer down?

No. Disconnect it from the network instead. Powering it off can destroy evidence your IT provider needs to understand what happened. Isolate it and let a professional examine it.

My employee typed their password into a fake login page. What now?

Assume that account is compromised. Immediately change the password from a different device, turn on multi-factor authentication, check for unauthorized mail forwarding or rules, and have your provider review the account's recent activity.

Do I legally have to report a breach?

It depends on what data was exposed. Massachusetts businesses can have notification obligations under state law, and you may owe notice to customers or your cyber insurer. Confirm with your IT provider and an attorney before deciding. This is general information, not legal advice.

aN

aNetworks, Inc.

aNetworks is a managed IT and cyber security partner on the South Shore of Massachusetts, serving small and mid-sized businesses across New England. We bring AI, automation, cyber security, cloud, and managed IT together under one accountable team. See where AI fits your business with a free AI Readiness Assessment, or start a conversation. Call 781-871-0709.