Phishing threats have been around for years, but attacks are becoming increasingly sophisticated and much harder to spot. Recently, we’ve seen a rise in businesses coming to us for support after staff clicked on phishing link, resulting in their systems and clients’ systems being compromised.
One click can be enough to expose a business to malware, data theft or even a full-scale ransomware attack.
If you find yourself in this situation, acting quickly is essential to contain the threat and minimise the potential damage. In this blog post, we’ll share our top tips on what to do after your staff clicked on the phishing link and the immediate steps you should take to protect your business.
Disconnect From The Internet
The first thing to do is disconnect from the internet. The longer you leave the internet on, the attacker has more of an opportunity to spread the malware further throughout your network and servers. We understand that every business set up is different. Main ways to disconnect include:
Wifi Connection
To disconnect Wi-Fi, go to your device settings and turn the switch off. You can also click the network icon and select forget or disconnect.
If for any reason you’re unable to do this, turn off your internet router. This will disconnect every device, however, this may be the best way forward depending how far the threat has spread.
Ethernet
If you have Ethernet, you must unplug the cable. This is the quickest way to switch the system off.
Devices
Either quickly switch to Airplane mode which will disconnect wireless connections automatically. You can also simply use the wifi toggle.
Don’t switch your computer off
Your first instinct may be to just switch the computer off. However, this can cause more issues. Keeping the device switched on helps preserve evidence, allowing us to investigate the source of the problem and determine how far the malware has spread.
After disconnecting the affected device, simply hand it over to IT experts to get to the bottom of the issue. If you’ve clicked on a phishing link, we strongly advice that you don’t attempt to fix it yourself. You may miss threats that have been hidden by attackers.
Reset Passwords
Attackers move fast so it’s important that you move faster. This means changing passwords and setting up multi-factor authentication.
While they might not have accessed all sensitive data, you should assume that they have. That means changing passwords to devices, Microsoft 365, CRM systems, cloud storage, social media platforms, and banking platforms.
Start with your email account, as this is often one of the first places attackers will target. Gaining access to your email can make it easier for them to access other accounts and systems linked to it.
Set up multi-factor authentication
If you didn’t have multi-factor authentication before, now is the time to start. MFA makes it more difficult for hackers to access sensitive data as it requires more than just a password to access. Having multiple verification steps means they will need access to your email, phone, or authentication app.
Whether you are looking at setting up an authenticator app, sms codes, or biometrics, our team of experts are here to help.
check for Suspicious Activity
Look out for suspicious activities throughout your systems. This can include:
- Unexpected logins from unrecognised locations
- Password changes
- Unusual file access or downloads
- Suspicious email forwarding
Warn Other Employees
If the scam has reached one employee, assume that is has reached everyone. Make everyone in the business aware of the malicious email and advise them to avoid interacting with the message. If they have clicked on phishing link, encourage them to let the right people know immediately.
Provide Your Team with Cyber Security Training
Cyber security awareness training helps your employees understand the digital threats businesses face and, importantly, how they can play their part in preventing them.
Our team can deliver practical cyber security training that gives your employees the knowledge and confidence to recognise potential risks and respond appropriately. This can cover key areas such as:
- Recognising the latest cyber threats and common warning signs
- Creating strong passwords and understanding the importance of multi-factor authentication
- Protecting personal, company and client information
- Keeping software and devices up to date and understanding why regular updates are essential
How We Can Help
Has your employee clicked on phishing link? We are here to help. Our team of experts go above and beyond to ensure our clients are protected from cyber attacks through email protection, managed security services, MFA, cyber training, and continuous monitoring.
The key is to tackle the problem as quickly as possible. Expert IT specialists can help you to do this.
If you have any questions or are in need of emergency support, contact us today.







