I already clicked a phishing link or entered my password — what to do next

Got an email that turned out to be phishing — and you already clicked, signed in, opened something, or replied? You are not the first person this week, and you are not in trouble for telling us. Looking this up was the right move. Speed and a calm checklist matter more than a perfect write-up.

Heads up — managed clients only. The response steps below are how we support The I.T. Experience managed clients. If you are not a client and you are worried about an account, contact that service’s support from a device you trust.
Stop interacting, contact us, we reset and check

The 30-second version

  1. Stop interacting with the email and the website. Close the tab. Do not click “log in again” to see if it still works.
  2. Do not warn the office by forwarding the phishing email to a distribution list. That spreads the bait. Tell a neighbor verbally, or open a normal support request.
  3. Contact us right away — phone (603) 505-4290, email [email protected], or submit a support request — with the five facts below.
  4. If you typed a password or approved an MFA prompt you did not mean to: do not try to “fix” it yourself with a self-serve password reset. Stop using that session, contact us, and we will reset the password and revoke sign-in sessions with you.
Prefer the phone if credentials or MFA were involved in the last hour. A live call is faster than waiting on email when minutes matter.

Which path am I on?

Pick the first row that matches. You can belong to more than one — follow the stricter path (B, C, or D over A).

What happened Start here
Clicked a link, but did not type a password or approve MFA Path A — Link only
Typed your username/password, or approved an MFA prompt you did not mean to Path B — Password or MFA
Opened an attachment, or ran a downloaded file / “security update” Path C — Attachment or something ran
Replied with sensitive info (payroll, wire instructions, W-2, invoice change) Path D — You sent sensitive information
Path A link only, Path B password or MFA, Path C attachment, Path D sent sensitive info
  1. Close the browser tab. Leave the site alone.
  2. Note the approximate time and the sender display name (do not click again to look things up).
  3. Leave the message in your inbox for now. After you have contacted us (or when we ask), you can report it using How to send us a suspicious email for automated analysis.
  4. Message us with the five facts. We will tell you if anything else is needed.

You often will not need a password reset for Path A. We would rather confirm than guess.

Still unsure whether you typed anything? Treat it as Path B and contact us. Over-reporting is fine; under-reporting is how small events get bigger.

Path B — Password or MFA

This is the path where we want a ticket or phone call first — not a DIY password change.

  1. Stop using that browser session for work email, Teams, or portal sign-ins. Close the tab/window.
  2. Do not approve any further MFA / Authenticator prompts you did not just initiate yourself.
  3. Contact us immediately using one of these (pick the fastest you can reach):
  1. Say clearly that credentials or MFA may be involved so we prioritize a password reset and session revocation.
  2. Keep the device you used nearby. We may ask whether Outlook, Teams, or the browser looked unusual afterward.
Do not use a self-serve password-reset page as your first move after phishing. Changing the password yourself (or inside the same browser that just phished you) is not enough and can leave stolen sessions active. Submit a ticket or call us — we reset the account and revoke sessions on our side.
Changing a password inside the same tab that just phished you is not reliable. Even if you know how to reset passwords normally, after a phishing click we still need the ticket so we can revoke sessions, check mailbox rules, and confirm nothing else is open.

Path C — Attachment or something ran

  1. Disconnect from Wi‑Fi or unplug Ethernet if you are comfortable doing that; leave the computer powered on.
  2. Do not start deleting files, installing cleanup tools from a pop-up, or resetting Windows yourself.
  3. Call us by phone if you can: (603) 505-4290. Say you opened or ran something from email.
  4. Capture what you can without digging: filename, approximate time, any on-screen message. See also Reporting an IT Security Incident.

If what you saw looked like a fake virus / “call Apple/Microsoft” scare screen, also read Fake virus pop-ups and tech-support scams — and still tell us.

Pop-up says call a 1-800 number or install a “cleanup” tool? Close the browser if you can; do not call numbers from the pop-up; do not download their tool. Call us at (603) 505-4290 instead.

Path D — You sent sensitive information

  1. Call us by phone: (603) 505-4290. This is the path where minutes matter for finance and HR follow-up.
  2. Tell us who you replied to, what you sent, and whether money, payroll, W-2, or invoice/banking changes were involved.
  3. Do not send a “correction” email on the same thread until we say so — attackers often watch those threads.
  4. If you also typed a password along the way, follow Path B’s contact steps as well (ticket/phone → we reset).

Do this now (ordered checklist)

Use this when you want one list instead of path cards:

  1. Leave the site/tab. Do not “log in again to check.”
  2. Do not forward the phishing email to coworkers as a warning.
  3. Contact us: (603) 505-4290 · [email protected] · support request.
  4. If Path B: say credentials/MFA were involved — we handle the reset and session revoke.
  5. If Path C: disconnect network if you can; leave the PC on; wait for us.
  6. If Path D: phone first; do not reply again on that thread.
  7. Have the five facts ready.

The five facts we need

Copy/paste into your email or support request, or have them ready on the phone:

Five facts we need checklist
  1. About what time it happened (include time zone if you are traveling).
  2. What you did — clicked / typed password / approved MFA / opened attachment / replied with sensitive info.
  3. Which account — usually your work email address.
  4. Which device — office PC, laptop, phone; home or office network.
  5. Whether anything seemed to install, or whether a ransom / “locked files” / scareware message appeared.

Anything else is bonus (subject line, screenshot of the message without clicking links again). Those five let us start.

Opening a support request? Put “Possible phishing — credentials entered” (or “link only” / “attachment opened”) in the subject so it is easy to prioritize.

What we typically do on our side

You do not need to run these yourself. Depending on the path, we may:

  • Reset your password with you and revoke sign-in sessions
  • Check your mailbox for forwarding rules or inbox rules you did not create
  • Search for the same campaign across your organization
  • Check the device health tooling already on managed computers
  • Walk finance / HR through next steps if Path D applies
  • Ask you to forward the original as an attachment for analysis once the urgent steps are done — see How to send us a suspicious email…

We will tell you what we changed and whether you need to sign back into Outlook, Teams, or other apps on each device.

Why we insist on a ticket for Path B: A password change alone does not always kick out a session the attacker already opened. Our process pairs the reset with session revocation and a quick mailbox check — that is the part clients cannot see from a public reset page.

What not to do

Skip these — they make things worse or burn time we need:
  • Do not pay a ransom, “fine,” or gift-card demand from a page or email.
  • Do not call a phone number from the suspicious email or pop-up.
  • Do not run cleanup tools advertised by the page you landed on.
  • Do not wipe your PC or reinstall Windows unless we ask you to.
  • Do not blast the original phishing email to “All Staff.”
  • Do not treat a self-serve password-reset page as the whole fix after phishing — contact us so we can reset and revoke properly.

If you are on the road with only a phone

Call (603) 505-4290. We would rather reset things with you live than wait overnight for a perfect write-up. When you can reach a desktop later, you can still forward the original as an attachment for analysis.

If you cannot reach the phone line, email [email protected] or submit a support request with the five facts and “credentials involved” in the subject when that applies.

Aftercare (next few days)

  • Treat unexpected password-reset messages seriously — tell us if you did not request a reset (and did not just finish one with us).
  • If colleagues ask “did you email me to buy gift cards / change wiring?”, call them back on a known number and call us.
  • If Outlook rules, auto-forwarding, or your signature changed, tell us even if mail seems fine.
  • Approve MFA prompts only for sign-ins you just started.

Need us now? [email protected] · (603) 505-4290 · Submit a support request

Was this article helpful?