It happens. You are tired. You are in a hurry. And you click a link you should not have. Your stomach drops. You feel stupid. But do not panic. This blog gives you a clear, step-by-step plan. Follow these steps immediately. You can still prevent damage.
Step 1: Do Not Click Anything Else
Stop. Do not click anywhere. Do not close the browser window yet. Do not type anything. Just take your hands off the mouse and keyboard.
Step 2: Disconnect From the Internet
This is important. If malware is downloading, disconnecting stops it.
-
On a desktop computer – Pull out the Ethernet cable or turn off Wi-Fi.
-
On a laptop – Turn off Wi-Fi using the button or settings.
-
On a phone – Turn on airplane mode.
Do this right now before reading further.
Step 3: Do Not Enter Any More Information
If the page is asking for your password, do not type it. If you already typed it, go to Step 4. If you only clicked the link but did not enter anything, you are safer. But still follow all steps
Step 4: Change Your Password From a Different Device
Use a different computer or your phone (but not connected to the same network). Change your password for:
-
Your work email
-
Any system you logged into recently
-
Personal accounts if you use the same password (you should not)
Make the new password strong and unique.
Step 5: Scan for Malware
If you have antivirus software, run a full scan. If you do not, tell your IT team so they can scan for you. On a personal device, use Windows Defender (free) or Malwarebytes (free version).
Step 6: Tell Your IT Team or Manager Immediately
This is the hardest step. Many people feel embarrassed. But telling someone fast is the best thing you can do.
Your IT team can:
-
Check if the attack spread
-
Block the phishing site for others
-
Reset your account properly
-
Start their incident response plan
Do not wait. Do not try to fix it alone.
Step 7: Watch for Unusual Activity
For the next few weeks, check for:
-
Emails you did not send
-
Password reset requests you did not make
-
Strange logins to your accounts
-
Missing files or new files you did not create
Report anything unusual immediately.
What If You Entered Your Password?
This is serious. The hacker now has your login details. They may not use them right away. They might wait weeks.
So after changing your password (Step 4), also check your account settings. Look for:
-
Forwarding rules (hackers forward your emails to themselves)
-
New recovery email addresses
-
New devices connected to your account
Remove anything you do not recognise.
What If You Downloaded a File?
Do not open it. Delete it immediately. Then run a malware scan.
If you already opened it, your computer may be infected. Your IT team might need to wipe it completely and reinstall everything.
The Good News
Most phishing attacks are stopped quickly if you report them fast. IT teams deal with this every day. You will not be the first person to click a bad link.
The worst thing you can do is say nothing.
Prevention Is Better Than Cure
The best way to handle a phishing mistake is to prevent it entirely. That is why training matters.
Our Phishing Awareness for Healthcare Workers CPD course teaches you:
-
How to recognise phishing before you click
-
What to do in the first 60 seconds after clicking
-
How to build safe email habits
Frequently Asked Questions
Q: Will I get fired for clicking a phishing link?
Good employers do not fire people for honest mistakes. They use it as a training opportunity. Covering it up is worse than the click.
Q: How fast do I need to act?
Immediately. Every minute counts. Hackers can move very fast once they have access.
Q: What about phishing on my personal phone?
The same steps apply. Turn on airplane mode. Change passwords from another device.
Q: Do I need to tell patients?
No. That is your organisation’s responsibility. But you must report to IT so they can decide.