An Employee Clicked a Phishing Link. Here Is What to Do in the First Hour

Somebody told you an employee clicked a phishing link. The first hour has four priorities, and they are shorter than you expect: the person stops using that computer, the password gets changed from a different device, the bank gets called if any money or bank detail was involved, and your IT provider gets told what happened and at what time. Everything else can wait until those four are done.

The instinct is to find out who clicked and how they fell for it. That conversation is worth having, later and calmly. In the first hour the only thing that changes the outcome is speed, because the people on the other end are already working with whatever the click gave them.

What to do in the first hour after an employee clicked a phishing link

  1. Have the person stop using the computer, and leave it switched on. Whoever looks at it later will want to see what happened. Switching it off erases some of that.
  2. Change the password from a different device. A phone or another computer works. Changing it on the machine that may be compromised puts the new password in the same hands as the old one.
  3. Find out straight away whether money was involved. Was a payment made, was a bank detail typed in, was an invoice approved. If the answer is yes to any of them, the bank comes before everything else.
  4. Tell your IT provider, with the time. The hour of the click matters more than the description of the email.
  5. Tell the rest of the team the same day. The same message usually arrives in several mailboxes at once.

Why changing the password does not always remove the intruder

When somebody signs in to a website, the site hands their computer a pass so it stops asking who they are every few minutes. That pass keeps working on its own. Somebody who captured it during the click can keep reading the mailbox after the password has been changed, which is why an owner sometimes changes a password twice and still sees strange activity.

Cancelling those passes is a separate action, and it is not something you can do from the login screen. Ask your IT provider: after the password change, please sign that account out of every device and cancel the passes it is still holding.

The money is the part of this with a deadline

Stolen money moves quickly, and the window in which it can still be pulled back is measured in hours. The insurer Coalition reported that in 2025 it recovered $21.8 million in stolen funds for its policyholders, with an average recovery of $202,000 per case, and that the first 48 hours usually decide whether the money comes back at all.

For a company your size, that changes the order of the phone calls. The bank is not the last call after the technical work is finished. It is the first call, and it is worth making before anybody has a full explanation of what happened.

The mailbox rule that is set up quietly and read by nobody

One of the most common moves after a successful click is to create a rule inside the mailbox that quietly forwards or files certain messages. Anything containing the word invoice, or the name of a supplier, disappears into a folder the owner never opens. The account looks normal for weeks while every payment conversation is being read by somebody else.

Ask your IT provider: please check every forwarding rule on that mailbox, and tell me who created each one and when. If your provider manages your systems day to day, this takes minutes.

Read these numbers honestly

The recovery figures above come from companies that carry cyber insurance and had somebody to call within hours. If you do not have a policy, the average recovery is not your number.

What does transfer is the shape of it. Money that leaves on a Monday and is reported on a Friday is usually gone, and money reported the same morning often is not. That holds whether the call goes to an insurer, a bank fraud line, or the local FBI field office.

Three things owners do that make the first hour worse

The first is deleting the email. It feels like cleaning up, and it removes the piece of evidence that tells your provider what the attacker was actually after and who else received it. Leave it where it is and forward a copy if you are asked to.

The second is wiping or reinstalling the computer before anybody has looked at it. That closes the incident on one machine and destroys the record of what happened on it, which matters if the same message went to four people and only one of them told you.

The third is keeping it quiet. Owners often wait until they understand the situation before saying anything, and in the meantime the accounts department pays an invoice that arrived in the same wave. A short message to everyone, even one that admits you do not yet know the extent of it, is more useful than a complete explanation two days later.

What to decide before the next one

The useful preparation here is a decision rather than a purchase. Somebody in your company has to be the person people tell, and that person has to be easy to reach and impossible to embarrass. A team that expects a lecture waits until lunchtime to mention the click, and lunchtime is too late.

Write three phone numbers on one page and keep it where you can find it without a computer: your IT provider, your bank fraud line, and your insurer if you have a policy. That page is worth more at eight in the morning than any tool you could buy this quarter.

It is also worth agreeing in advance who is allowed to make the call to the bank. In a lot of small companies the only person with the authority to speak to the bank is the owner, and the owner is in a meeting. Naming a second person, and telling the bank that person exists, costs one phone call today and saves an hour on the morning it matters.

The questions to ask your IT provider

  • If somebody clicks tomorrow, who do they call, and what happens after 6 p.m. or on a Saturday?
  • After a password change, do you cancel the passes the account is still holding, or only reset the password?
  • Do you check mailbox forwarding rules after an incident, and can you show me the last time you did?
  • Who watches for a strange sign-in on my accounts overnight, and how would that alert reach me?
  • What do you keep in writing after an incident, and could my insurer use it as evidence?
  • If I asked you today, could you tell me which of my accounts still have no code on a phone at sign-in?

A click is not a failure of the person who clicked. It is a normal Tuesday in a company that reads email. What separates a bad hour from a bad quarter is whether the people around that person know exactly what to do next, and whether the phone calls happen in the right order.

If you would like a second opinion on how your current setup would handle the next click, our team is happy to walk through it with you. You can also start with our answers to the questions owners ask most often.

Share this
Picture of Alchanis Technical
Alchanis Technical

Leave a Reply

Your email address will not be published. Required fields are marked *