When it's already happened
I clicked a phishing link at work. What now?
You clicked, and now your heart is pounding. Here is what actually happened, what genuinely helps in the first five minutes, and how to report it in a way that gets you help instead of trouble.
A click is a maybe. A password you typed is a yes. Either way, tell someone in minutes rather than days, because speed is the thing that keeps it small.
Last reviewed 2026-08-18 by Grayson Dodson. Free, plain-English guidance for everyday work technology.
What you'll be able to do
tell the difference between a harmless click and a real compromise, do the few things in the first five minutes that actually help, and report it in the exact place your workplace expects without dreading the conversation
clicking a link versus entering credentials, and why the risk is not the samereal-time phishing kits that capture the session cookie so two-factor does not save youwhy signing out of all sessions matters more than changing your password alonereporting the message with a button versus telling a human that you clickedwhy deleting the phishing email destroys the evidence it needswhat a normal incident response looks like from the insidefast honest reporting versus the cover-up, and why speed protects you
First, breathe. A click is not a breach.
Take a breath before you do anything else. In most cases, clicking a phishing link and then closing the tab is not the disaster your stomach is telling you it is. A link opens a web page, and a web page loading in Chrome, Edge or Safari on a patched, company-managed laptop is not able to quietly take the machine over. The scenario where you get infected just by loading a page does exist, but it is rare, and it is precisely what your company's updates and endpoint software are there for. What phishing pages actually want is for you to do the next thing: type your password into a login screen that looks exactly like Microsoft 365 or Google, approve a push notification in Microsoft Authenticator or Duo, open an attachment, or paste something into a box. So the real question is not whether you are infected. It is what you did after the page loaded. If the honest answer is that you looked at it, felt something was off, and closed it, you are very probably fine. You should still report it, and the rest of this page explains why that is the good news rather than the scary part.
The line that matters: did you type anything or approve anything?
Everything hinges on one line. Did you only look, or did you hand something over? Clicking and closing sits at the bottom of the risk ladder. Typing your username and password into the fake page is a different event entirely, and from that second you should assume strangers have that password and every other place you reused it. Higher still is approving a multi-factor prompt you did not start, or typing a six-digit code from Microsoft Authenticator, Duo or a text message into the page. Modern phishing kits sit in the middle in real time, passing your password and code straight through to the genuine Microsoft or Google login and capturing the session cookie, which is the little pass that keeps you signed in. That is why "I have two-factor, so I am fine" is not quite true, and why the fix below includes signing out everywhere rather than only changing your password. The other serious case is running something: opening a downloaded file that asked you to Enable Content, or a page that told you to press the Windows key plus R and paste a command to prove you are human. When you report, say which of these happened. That one sentence shapes the whole response.
The first five minutes: what genuinely helps, what is theatre
Now the practical part, with the theatre stripped out. If you ran a file or pasted a command, disconnecting is genuinely useful. Turn Wi-Fi off or unplug the ethernet cable, but leave the laptop switched on and do not try to clean it yourself, because shutting down or wiping destroys the evidence that tells IT what happened. If you only typed a password, disconnecting does nothing at all, because that password is already sitting on someone else's server. Change it instead, from a device you trust, such as your phone on mobile data or a different computer. On a Windows work laptop with a Microsoft 365 account that is usually Ctrl+Alt+Delete, then Change a password, or the self-service reset page at aka.ms/sspr. For Google Workspace it is myaccount.google.com/security. Then sign out everywhere, which is the step almost everyone skips: myaccount.google.com/device-activity for Google, plus the Details link at the bottom right of Gmail's inbox to end other sessions, and mysignins.microsoft.com to review recent Microsoft sign-ins. Pure theatre: downloading some antivirus tool you found, buying a VPN, or deleting the email so it goes away. Deleting it removes the one thing your security team most needs.
Report the click, not just the email, and here are the exact buttons
In Outlook on Windows, select the message and use the Report button on the Home ribbon, then choose Report phishing. On older builds this is the Report Message add-in on the ribbon instead. In Outlook on the web, it is the three dots on the message, then Report, then Report phishing. In Gmail, open the message and use the three-dot menu beside the Reply arrow at the top right of the message, then Report phishing. If your company has no button, forward the mail as an attachment, which in Windows Outlook is Ctrl+Alt+F, to whatever address they publish, often phishing@ or security@ your company's domain. Here is the part that matters most: those buttons report the message. They do not tell anyone that you clicked. So send a human a short note as well, in the IT or helpdesk channel in Slack or Teams, or to your manager: the time, what you clicked, whether you typed a password, whether you approved an Authenticator or Duo prompt, and which device you were on. Ten specific words beat a long apology. If money or bank details were involved, tell finance in the same breath.
What a normal response from IT actually looks like
What happens next is far more boring than you are imagining. A typical response looks like this. They force a password reset and re-register your multi-factor method. They revoke your active sessions so any stolen cookie becomes useless. They read the sign-in logs to see whether anyone signed in from a country you have never visited. They check your mailbox for rules an attacker may have quietly added, because a hidden rule that forwards or deletes messages is the classic first move. They look at what your laptop did through Microsoft Defender for Endpoint, CrowdStrike, or whichever agent runs there. And because you reported the message, they can pull that same email out of everyone else's inbox before a colleague clicks it. Sometimes a laptop gets reimaged, which means a day of inconvenience and a fresh Windows build, not a black mark on your record. Someone may ask you to walk through what happened step by step. That is evidence gathering, not an interrogation; they need the timeline to know how far to look. A short training module afterwards is routine housekeeping, not a punishment.
Will I get fired for this?
For an honest mistake that you report promptly, essentially never. Nobody on the internet can promise you an outcome, because policies and employment law vary by country, state and employer, and the honest place to check the specifics for your workplace is the acceptable use policy or the employee handbook. But the pattern is remarkably consistent: security teams treat fast reporters as the reason an incident stayed small, and treating a reporter harshly guarantees the next person hides it. What genuinely creates trouble is the silence afterwards. Deleting the email, leaving out the part where you typed your password, or waiting three days while someone reads your mail and emails your customers from your account. Phishing that works is built by professionals who test it against people exactly like you, and the simulated ones your employer sends are designed so that a fair share of people click. So say it today, in plain words, even if it is late and you feel foolish. "I clicked something at 4:40 and I think I entered my password." That sentence turns you from the person who clicked into the person who caught it.
Common questions
I clicked a phishing link but didn't enter any information. Am I okay?
Most likely, yes. A link that only opened a page on an up-to-date work laptop generally leaves nothing behind but a browser history entry. The real danger starts when you type credentials, approve a Microsoft Authenticator or Duo prompt, or open and run a downloaded file. Report it anyway, using the Report button on Outlook's Home ribbon or Gmail's three-dot menu and Report phishing, and mention plainly that you clicked. Your report lets the security team remove the same email from colleagues' inboxes and check your account for things you cannot see yourself.
Do I have to report clicking a phishing link at work?
Yes, and quickly, because reporting is the single most useful thing you can do. Most workplaces require it, and even where the policy is vague, the security team would far rather hear about it in ten minutes than find it in a log next week. Reporting the message with Outlook's Report button or Gmail's Report phishing option is only half of it, since those buttons flag the email but not the fact that you clicked. Also send a person a short message saying you clicked, what you typed, and when.
Can you get fired for clicking a phishing link at work?
For an honest mistake reported promptly, essentially never. Employers know phishing is professionally built to fool careful people, and punishing a reporter guarantees the next person stays quiet. No one can guarantee an outcome, because policy and employment law vary by employer and location, and your handbook or acceptable use policy is the right place to check. What does cause real problems is concealment: deleting the email, downplaying that you entered a password, or saying nothing for days. Speed and honesty protect the company and protect you at the same time.
Should I disconnect from Wi-Fi or shut down after clicking a phishing link?
Disconnect only if you actually ran something. If you downloaded and opened a file, or pasted a command into the Windows Run box, turning off Wi-Fi is genuinely useful, but leave the machine powered on, because shutting down or wiping erases what IT needs to see. If you only typed a password into a fake page, disconnecting achieves nothing, since that password is already on the attacker's server. Change it from a different device and sign out of every session instead, at myaccount.google.com/device-activity or through your Microsoft sign-in settings.
I entered my password on a fake login page. What do I do first?
Change that password immediately from a device you trust, then sign out of every session, then tell IT. On Windows with a Microsoft 365 work account, Ctrl+Alt+Delete and Change a password works, or use aka.ms/sspr; Google Workspace users go to myaccount.google.com/security. Signing out everywhere matters because attackers often steal the session cookie, which can survive a password change: use myaccount.google.com/device-activity, or the Details link at the bottom right of Gmail. Change it anywhere else you reused it, then message the helpdesk with the time and what you entered.