Blog · By Nimrics · 6 Sept 2026 · 5 min read
You Clicked a Phishing Link. Here Is What to Do in the First Ten Minutes
Clicking is not the disaster; what happens in the next ten minutes decides whether it becomes one. A calm, step-by-step response for the moment you realise a message was not what it claimed to be.

The message looked right. It came from a name you recognised, it mentioned a real project, and the link went to a page that asked you to sign in. You signed in. Then something felt off — a spelling mistake, a wrong logo, a colleague asking "did you send me this?" — and your stomach dropped.
I have taken that phone call many times. The people who come out of it fine are not the ones who never click; everyone clicks eventually. They are the ones who act in the first ten minutes instead of hoping it will be fine. Here is the plan. Keep it somewhere you can find it without thinking.
Minute 0: stop, do not tidy up
Do not delete the email. Do not close the tab in a panic. Do not reply to the sender. Evidence helps whoever investigates, and the attacker cannot see what you do on your screen. Take a breath and work out which of three things happened:
- You only clicked. The page loaded, you looked, you closed it.
- You typed a password (or a two-factor code) into a page that was not the real service.
- You opened or ran an attachment, or the page asked you to "update" or "install" something and you agreed.
Each has a different next step.
If you only clicked
The realistic risk here is low. Modern browsers and phones make it hard for a web page alone to compromise a device, though not impossible if the software is badly out of date. Do these three things:
- Close the tab.
- Check the browser has no new extensions and the device has no new apps you did not install.
- Report the message to whoever handles security at your company, or forward it to your email provider's phishing report address. Reporting is not admitting fault; it protects the next person who receives the same message.
Then move on with your day.
If you typed a password: the ten-minute sequence
This is the case that matters, because the attacker now has a working credential and is usually trying it within minutes.
Minute 1–2 — change the password on the real site. Go to the genuine service by typing its address yourself or using your password manager, not by clicking anything in the message. Change the password. If that password was reused anywhere else, those accounts are next on your list.
Minute 3–4 — sign out everywhere. Most services have a "sign out of all sessions" or "sign out other devices" option in security settings. Use it. Changing the password alone does not always end a session the attacker already opened.
Minute 5 — check the account's rules. Attackers who get into email love to leave quietly: they add a forwarding rule to their own address, or a filter that deletes security alerts. Open your mail settings, look at forwarding and filters, and remove anything you do not recognise. Look at connected apps and recovery email or phone numbers while you are there.
Minute 6 — if you gave away a two-factor code, assume they used it. One-time codes are valid for seconds, and real-time phishing kits relay them instantly. Treat the account as accessed: do the steps above and review recent activity, sent items and, for financial accounts, recent transactions.
Minute 7–8 — tell someone. Your IT person, your manager, the founder — whoever can widen the response. If the account was your work email, the attacker may already be sending the same message to your contacts from your name. A one-line heads-up to the team ("if you get an email from me about an invoice in the last hour, it is not me") stops the spread.
Minute 9–10 — write down what happened. The time, the message, what you entered, what you changed. Two sentences. You will be asked, and memory gets worse under stress.
If you opened an attachment or installed something
This is the one where the device, not just the account, may be compromised.
- Disconnect from the network — turn off Wi-Fi, unplug the cable. This does not undo an infection, but it can interrupt one that is still downloading its next stage or spreading to shared drives.
- Do not log in to anything else from that device. Use your phone or another machine for the account steps above.
- Run a full scan with the security software on the device, and get it looked at by someone who can check running processes and startup items. On a company laptop, this is the point to hand it to IT rather than fixing it yourself.
- If the attachment was a document that asked you to "enable content" or "enable macros", and you did, treat it as a full compromise regardless of what the scan says.
What phishing looks like in 2026
Knowing the shapes helps you catch the next one earlier:
- Sign-in pages that arrive by link. Legitimate services rarely need you to sign in from an email link. Go to the site yourself instead.
- Urgency and authority. "Your account will be suspended", "the CEO needs this today", "payment failed". Pressure is the tell.
- Invoice and payment changes. A supplier "updating their bank details" by email is the classic business email compromise. Confirm by phone, on a number you already had.
- QR codes in emails and on posters, which take you to a phishing page while bypassing the link-scanning that email systems do.
- Messages on WhatsApp, Telegram and SMS, which have none of the protections corporate email has, and which people trust more.
Make the next one less likely
- Use a password manager; it will not autofill a password on a fake domain, which is a surprisingly good phishing detector.
- Prefer passkeys or hardware security keys for email and admin accounts. They cannot be phished, because the credential is bound to the real website's domain.
- Agree a "call to confirm" rule for any payment or bank-detail change, no exceptions for seniority.
- Practise the ten-minute plan once, as a team, before you need it.
Nobody gets through a career without clicking something they should not have. The measure of a secure team is not that it never happens; it is that when it does, everyone knows what the next ten minutes look like.