Phishing email response: what to do if you get or click one

For employees who get a suspicious email: what to check, how to report it, and what to do right away if you clicked, typed a password or paid.

Phishing email response: what to do if you get or click oneEmployeeSecurityCHECK THE EMAILACT FAST IF YOU CLICKEDSECURITY TRIAGEYes or not sureProbably genuineYesNoYesYesNoYesNoYesNoNoYesYesNoNoSuspicious email arrivesFor employees who get a suspiciousemail: what to check, how to report it,and what to do right away if youclicked, typed a password or paid.Don't click links, open attachments,reply or use unsubscribe links whileyou check.Look for the warning signsSender address that doesn't matchthe company, or a lookalike such asamazan.com. Hover over links to seethe real address. Shortened linkshide it.Urgency or threats, such as anaccount on hold. Requests forpasswords, payment, gift cards ornew bank details. Unexpectedattachments. A generic greeting.Perfect spelling and grammar don'tmake it safe. Attackers use AI towrite convincing messages.Could it be phishing?Report it with the Reportphishing buttonUse the Report or Report phishingbutton in Outlook, Gmail or your mailapp. No button? Forward it to thesecurity team's reporting address.Outside work, forward scam emailsto reportphishing@apwg.org (US) orreport@phishing.gov.uk (UK).Check with the senderthrough a known contactUse a phone number or website youalready know, not details from theemail. Never confirm by replying.Did the senderconfirm it's real?Genuine email. Carry onDid you click a link,open an attachmentor reply?Reported. Delete it and stayalertThe report button usually removesthe email. Watch for similarmessages, and don't forward it tocolleagues.Tell security right away, evenif you're unsureSay what you clicked, opened ortyped, and when. Fast reports limitthe damage, and good securityteams don't blame people forreporting.Did you open anattachment or installanything?Disconnect the device fromthe networkUnplug the network cable and turnoff Wi-Fi. Don't try to clean it yourselfunless security asks you to.Run a full antivirus scan only ifsecurity tells you to.No file openedDid you enter apassword or a codeon the page?Change that password nowon another deviceGo to the real site by typing itsaddress yourself, not through theemail. Change any other account thatuses the same password.Sign out everywhere andcheck your MFA settingsUse the account's option to sign outall sessions. Check that no new MFAdevice or email forwarding rule wasadded. Turn on MFA if it was off.No password enteredDid you send money,bank details orcompany data?Call finance and the bankimmediatelySpeed matters. Ask the bankwhether the payment can bestopped or recalled. Use the numberon your card or statement.If you sent card details, cancel thecard. Report data you sent, such ascustomer records, to security andyour privacy lead.No money or data sentHand over to the securityteamReview the reported emailCheck the headers, links andattachments. Find everyone else whogot the same email.Remove the email from everymailbox and block thesender and linksAdd the sender, domains and linkaddresses to your email and webfilters.Did anyone click,enter details or run afile?Close the report and thankthe reporterQuick feedback shows staff thatreporting is worth it.Reset credentials and revokesessions for affectedaccountsRe-provision accounts that may becompromised. Audit account accessafterwards to confirm the attackerno longer has it. Check for new MFAdevices and mailbox rules.Isolate and examine affecteddevicesIsolating the workstation stopsmalware spreading. Have themalware analyzed, remove it, thenrestore or rebuild the device andconfirm it works.Was money,personal data or awider systemaffected?Escalate to a full securityincidentBring in finance, legal and privacy.Personal data breaches may havelegal reporting deadlines.US organizations can report to CISAat report@cisa.gov or the FBI's IC3. Inthe UK, report fraud to Report Fraudor Police Scotland.Contained. Close withlessons learnedShare a short warning about thisemail with staff if others may get it.

Check the email

  1. Suspicious email arrivesEmployee

    For employees who get a suspicious email: what to check, how to report it, and what to do right away if you clicked, typed a password or paid.

    Don't click links, open attachments, reply or use unsubscribe links while you check.

  2. Look for the warning signsEmployee

    Sender address that doesn't match the company, or a lookalike such as amazan.com. Hover over links to see the real address. Shortened links hide it.

    Urgency or threats, such as an account on hold. Requests for passwords, payment, gift cards or new bank details. Unexpected attachments. A generic greeting.

    Perfect spelling and grammar don't make it safe. Attackers use AI to write convincing messages.

  3. Could it be phishing?Employee
  4. Report it with the Report phishing buttonEmployee

    Use the Report or Report phishing button in Outlook, Gmail or your mail app. No button? Forward it to the security team's reporting address.

    Outside work, forward scam emails to reportphishing@apwg.org (US) or report@phishing.gov.uk (UK).

    Then go to step 8, Did you click a link, open an attachment or reply?

  5. Check with the sender through a known contactEmployee

    Use a phone number or website you already know, not details from the email. Never confirm by replying.

  6. Did the sender confirm it's real?Employee
  7. Genuine email. Carry onEmployee
  8. Reported. Delete it and stay alertEmployee

    The report button usually removes the email. Watch for similar messages, and don't forward it to colleagues.

  9. Tell security right away, even if you're unsureEmployee

    Say what you clicked, opened or typed, and when. Fast reports limit the damage, and good security teams don't blame people for reporting.

Act fast if you clicked

  1. Did you open an attachment or install anything?Employee
  2. Disconnect the device from the networkEmployee

    Unplug the network cable and turn off Wi-Fi. Don't try to clean it yourself unless security asks you to.

    Run a full antivirus scan only if security tells you to.

    Then go to step 14, Did you enter a password or a code on the page?

  3. No file openedEmployee
  4. Did you enter a password or a code on the page?Employee
  5. Change that password now on another deviceEmployee

    Go to the real site by typing its address yourself, not through the email. Change any other account that uses the same password.

  6. Sign out everywhere and check your MFA settingsEmployee

    Use the account's option to sign out all sessions. Check that no new MFA device or email forwarding rule was added. Turn on MFA if it was off.

    Then go to step 18, Did you send money, bank details or company data?

  7. No password enteredEmployee
  8. Did you send money, bank details or company data?Employee
  9. Call finance and the bank immediatelyEmployee

    Speed matters. Ask the bank whether the payment can be stopped or recalled. Use the number on your card or statement.

    If you sent card details, cancel the card. Report data you sent, such as customer records, to security and your privacy lead.

    Then go to step 21, Hand over to the security team

  10. No money or data sentEmployee
  11. Hand over to the security teamEmployee

Security triage

  1. Review the reported emailSecurity

    Check the headers, links and attachments. Find everyone else who got the same email.

  2. Remove the email from every mailbox and block the sender and linksSecurity

    Add the sender, domains and link addresses to your email and web filters.

  3. Did anyone click, enter details or run a file?Security
  4. Close the report and thank the reporterSecurity

    Quick feedback shows staff that reporting is worth it.

  5. Reset credentials and revoke sessions for affected accountsSecurity

    Re-provision accounts that may be compromised. Audit account access afterwards to confirm the attacker no longer has it. Check for new MFA devices and mailbox rules.

  6. Isolate and examine affected devicesSecurity

    Isolating the workstation stops malware spreading. Have the malware analyzed, remove it, then restore or rebuild the device and confirm it works.

  7. Was money, personal data or a wider system affected?Security
  8. Escalate to a full security incidentSecurity

    Bring in finance, legal and privacy. Personal data breaches may have legal reporting deadlines.

    US organizations can report to CISA at report@cisa.gov or the FBI's IC3. In the UK, report fraud to Report Fraud or Police Scotland.

  9. Contained. Close with lessons learnedSecurity

    Share a short warning about this email with staff if others may get it.

Outcomes

Genuine email. Carry on

You get here from step 6, Did the sender confirm it's real? (Yes).

Reported. Delete it and stay alert

The report button usually removes the email. Watch for similar messages, and don't forward it to colleagues.

You get here from step 8, Did you click a link, open an attachment or reply? (No).

Close the report and thank the reporter

Quick feedback shows staff that reporting is worth it.

You get here from step 24, Did anyone click, enter details or run a file? (No).

Escalate to a full security incident

Bring in finance, legal and privacy. Personal data breaches may have legal reporting deadlines.

US organizations can report to CISA at report@cisa.gov or the FBI's IC3. In the UK, report fraud to Report Fraud or Police Scotland.

You get here from step 28, Was money, personal data or a wider system affected? (Yes).

Contained. Close with lessons learned

Share a short warning about this email with staff if others may get it.

You get here from step 28, Was money, personal data or a wider system affected? (No).