SecurCheckCyber Centre

FIRST RESPONSE · PHISHING

I clicked a phishing link: what should I do? The emergency guide

Secur Cloud ·

It can happen to anyone. Stop interacting with the message or website and choose your situation below. A click does not prove compromise; acting promptly helps limit the consequences.

1. You only clicked, without entering anything

Risk is generally lower if you entered nothing, approved nothing and opened no file, but it is not zero.

  1. Close the page

    Do not approve notifications, permissions, installations or sign-in requests. Do not call a number displayed in a fake security warning.

  2. Do not open downloads

    An automatic download is not the same as execution. Do not run the file to test it. At work, let IT arrange collection or quarantine; do not forward it to colleagues.

  3. Preserve the context

    Record the time, address and any permissions granted without reopening the link. Clearing cache or cookies does not disinfect a device or revoke a stolen session. At work, avoid clearing history before IT gives instructions.

If you installed an extension, ran a command or allowed remote access, follow scenario 4. If you approved a sign-in or MFA request, follow scenario 2.

2. You entered a password or approved a sign-in

Treat access as potentially exposed. Use a trusted device if you also suspect infection.

  1. Change the password on the real service

    Open the official address from a known bookmark. Choose a unique password and replace it on other accounts where it was reused.

  2. Have sessions revoked

    Use “Sign out everywhere” if available. For a work Microsoft 365 account, immediately ask an administrator to revoke sessions and review connected applications. Permissions and options vary; some application sessions need a service-specific action. Revocation may not take effect instantly.

  3. Review recovery and MFA

    Report unknown MFA methods, recovery addresses, authorised apps or forwarding rules. Have IT or official support secure these settings. A password change alone does not close the incident.

Understand AiTM session theft through the Storm-2755 case

3. You shared banking details

  1. Contact your bank immediately

    Use its app or an official number you already know. If your card details were exposed, request that the card be blocked immediately. If you shared banking credentials or approved a transfer, ask the bank to secure access and urgently investigate the transaction. Recovery of funds is not guaranteed.

  2. Monitor transactions and keep evidence

    Review your statements over the following days and weeks. Promptly report unrecognised transactions to the bank and keep messages, dates, amounts and references. At work, notify the finance team too.

  3. Use the appropriate reporting route

    In France, Perceval covers unauthorised online card purchases when you still hold the card and have already blocked it. THESEE accepts complaints for certain online scams, subject to its eligibility criteria. Check the official procedures below; if your case does not qualify, contact the police or gendarmerie. Elsewhere, use your local reporting service.

    Perceval · THESEE

4. You opened or ran a suspicious attachment

Opening a file does not prove infection. If you ran a suspicious file, enabled a macro, received an antivirus warning or noticed unusual behaviour, act promptly.

  1. Isolate the device from the network

    Unplug Ethernet and disable Wi-Fi, mobile data or other active connections. Isolation limits spread and network traffic but may not stop local encryption. Stop using the device to sign in to accounts.

  2. Avoid reflexively restarting

    At work, let IT decide: shutting down can destroy evidence in memory. If encryption is ongoing, a protective shutdown may nevertheless be necessary. Report it immediately; do not start cleanup or reinstall the system yourself.

  3. Have the device examined

    On a personal device, a full scan with your updated local antivirus can help. Preserve useful evidence first; if problems persist or files are encrypted, seek specialist help. A clean scan does not guarantee that the device is uninfected.

At work: report immediately

Do not let fear of making a mistake delay reporting. Share the facts: time, message, click, file opened, credentials entered, MFA approval and affected device. Keep the original message and alerts without distributing them widely.

Payment card, transfer or changed bank details?

Contact your bank immediately through its official number if payment details were disclosed or a suspicious transaction occurred. At work, also notify finance to review payments and pause questionable changes. Do not wait for a technical diagnosis.

Stay calm: these steps reduce risk but do not prove the attacker has lost all access. Resume normal activity after IT or a professional has checked the situation.

Break the cycle of urgency

A click does not mean all is lost. Closing the page, securing access, contacting your bank if needed and reporting the facts helps contain the consequences. Match your actions to the situation and have IT check recovery after a workplace incident.

Deploy SecurCheck Business to support your teams every day

Sources and help

Guidance checked on 23 September 2026. Follow your incident-response team’s instructions for your environment.

Need help in France? Visit 17Cyber