White Rock Advisory

· Cyber Resilience · 5 min read

I clicked on a phishing email. What happens next?

Clicked a suspicious link or opened a phishing email? Find out what to do next, what information matters and how to reduce the risk of further harm.

Clicked a suspicious link or opened a phishing email? Find out what to do next, what information matters and how to reduce the risk of further harm.

You clicked the link. Then something did not feel right.

Perhaps the website looked unusual. Maybe you entered a password before realising the page was fake. Perhaps an attachment opened and nothing seemed to happen.

The first question is usually: “What have I done?”

The answer depends on what happened after you clicked.

Simply opening an email is very different from entering your password, approving an MFA request, downloading a file or making a payment. The important thing is to work out what happened and respond accordingly.


First: do not panic

Phishing works because criminals create urgency.

That urgency often continues after somebody realises they may have made a mistake. People rush to delete messages, reset random passwords, or switch devices off without understanding what has happened.

Instead, establish the facts. Ask yourself:

  • Did I only open the email?
  • Did I click a link?
  • Did I enter a username or password?
  • Did I provide banking or personal information?
  • Did I download or open a file?
  • Did I install software?
  • Did I approve an MFA request?
  • Did I make a payment?

Your next step depends on the answer.


I only opened the email

If you simply opened a phishing email but did not click anything, reply, download an attachment or provide information, the risk is generally much lower. Report the message and delete it.

Suspicious emails can be forwarded to the National Cyber Security Centre at: report@phishing.gov.uk

The NCSC uses reports to help identify and remove malicious websites and campaigns.


I clicked the link but entered nothing

Close the website. Do not download anything or follow further instructions.

If the link was opened on a work device, report it to your IT support or security team, particularly if the website attempted to download software or produced unusual security warnings.

Make sure the device and browser are fully updated and run a security scan if appropriate.

You can find current NCSC phishing guidance here: Phishing guidance


I entered my password

Treat the password as compromised. Change it immediately using the genuine website or application, not a link from the suspicious email. If that password was used anywhere else, change it there too.

Then:

  • Enable 2 Step Verification.
  • Log out other sessions where possible.
  • Review recent login activity.
  • Check auto forward rules.
  • Check recovery email addresses and telephone numbers.
  • Look for changes to security settings.

If the password was for your email account, prioritise it. Access to email can allow a criminal to reset passwords for many other services.


I approved an MFA request

If you approved a login request you did not initiate, the attacker may have gained access despite MFA being enabled. Immediately:

  • Change the affected password.
  • Log out all active sessions.
  • Review registered authentication methods.
  • Remove devices you do not recognise.
  • Contact IT support if it is a business account.

MFA remains one of the most effective account protections available, but users should never approve unexpected authentication prompts.


I opened an attachment or installed software

This needs more attention.

Disconnecting a device from the network may be appropriate if you believe malicious software is actively running, but for a managed business device, contact your IT provider as quickly as possible. They may need to:

  • Isolate the device.
  • Run security tools.
  • Review logs.
  • Check whether other systems were contacted.
  • Preserve evidence.
  • Reset credentials safely.

For personal devices, make sure your security software is updated and run a full scan. If you were instructed to install remote access software, contact your bank immediately if you also accessed financial services or disclosed financial information.


I entered bank or card information

Contact your bank using a trusted number, or dial 159.

Do not use telephone numbers provided in the suspicious email or website. If you believe money has been lost or fraud has taken place, report it through the appropriate UK reporting service. In England, Wales and Northern Ireland, fraud and related cyber crime can be reported through: Report Fraud

In Scotland, contact Police Scotland.


I made a payment

Act immediately.

Contact your bank on the trusted number or dial 159 and explain that you may have been deceived into making a fraudulent payment.

The faster your bank knows, the more opportunity there may be to intervene. Do not continue communicating with the person who requested the payment, even if they promise to return the money.


Why reporting the click matters at work

Employees sometimes hide phishing mistakes because they fear criticism.

That is exactly the wrong culture for an organisation to create.

A clicked link that is reported within minutes may be manageable.

A clicked link that is hidden for 3 days can become a much larger incident.

Good organisations make it easy for employees to say: “I think I clicked something I should not have.”

The response should be: “Thank you for telling us quickly.”

The NCSC has repeatedly encouraged organisations to move away from blame-based phishing cultures and instead combine awareness with strong technical controls.


What should businesses have in place?

Phishing cannot be solved by training alone. Organisations should consider:

  • Multi-Factor Authentication.
  • Strong email filtering.
  • Secure email configuration.
  • Automatic software updates.
  • Limited administrator privileges.
  • Simple internal reporting processes.
  • Regular awareness exercises.
  • Tested incident response arrangements.

The objective is not to create employees who never make mistakes, it is to make sure one mistake does not become a major incident.


Need support?

White Rock Advisory helps organisations improve phishing awareness, incident readiness and practical cyber resilience without relying on fear or technical jargon.

Contact Us

Back to Blog
Chat on WhatsApp