When it's already happened
I failed the phishing test at work. Am I in trouble?
You clicked a fake phishing email your own company sent, and now you feel exposed and a bit stupid. You are neither. Here is what a phishing simulation actually is, what realistically happens next, and how to get genuinely better at spotting them.
One click on a test is data, not a disciplinary matter. Do the training, learn the four checks, and report fast next time.
Last reviewed 2026-08-18 by Grayson Dodson. Free, plain-English guidance for everyday work technology.
First, the reassuring part: this was a test, and you passed the part that matters
You clicked a fake email. Not a real one. No money left the company, no password went to a criminal, no files were encrypted. What actually happened is that a simulated phishing email, sent by your own employer or a service they pay for like KnowBe4, Proofpoint Security Awareness, Hoxhunt or Microsoft Defender for Office 365's Attack Simulation Training, recorded that you clicked a tracking link. That is the entire event. If a landing page appeared saying "This was a simulated phishing test", that page is the whole consequence for most people. Nobody is standing around your desk. The security team is not talking about you by name. They are looking at a dashboard with a percentage on it, and you are one row in a spreadsheet of hundreds. The feeling of being singled out is real and completely understandable, because the landing page is addressed to you personally and arrives with no warning. But the system that sent it does not know your name in any way that matters. It knows a click happened, and it moves on.
What a phishing simulation actually is, and why your company runs one
A phishing simulation is a harmless fake scam email your employer sends on purpose to see how staff respond. Someone in IT or security schedules a campaign, picks a template, and sends it to a mailing list. The links go to a company-controlled page, not to an attacker. If the email had an attachment, it was inert. Companies do this for two ordinary reasons. The first is that a real phishing email is the most common way an organization gets broken into, and practice genuinely lowers the odds. The second is compliance: many organizations are contractually or legally required to run awareness training and testing. If your employer handles card payments, PCI DSS requirement 12.6.3.1 expects security awareness training that covers phishing and social engineering. Similar expectations sit inside HIPAA security awareness rules, ISO 27001 controls, cyber insurance renewals and customer security questionnaires. That is worth saying plainly: sometimes the test exists because an auditor asked for evidence it happened, not because anyone suspected you specifically. You were on the list because you have a mailbox.
Your click rate is not unusual, and the test was built to catch you
Across these programs, it is completely normal for somewhere between roughly ten and thirty percent of recipients to click on an early campaign. That is not a precise published figure for your company, and vendors report it differently, but the honest general picture is the same everywhere: a meaningful chunk of every workforce clicks, including senior people, including the IT department, including the person who scheduled the test. You are not an outlier. You are the expected result. It helps to know these emails are engineered to work. They lean on urgency ("your mailbox will be deactivated in 24 hours"), on authority (a message that looks like it is from your CEO, HR or Payroll), on curiosity ("your parcel could not be delivered") and on routine (a fake Microsoft 365 password expiry notice that looks exactly like the real one). Some campaigns copy your company's actual email signature block and internal colour scheme. A well-built simulation is designed so that a busy, competent person clicks it while thinking about something else. That is the point. A test nobody fails teaches nothing.
What usually happens next: a short training module, not discipline
In the overwhelming majority of workplaces, the consequence is a training assignment. You get an email within a day or two from a platform such as KnowBe4, Proofpoint or your company's own learning system, with a five to fifteen minute video or click-through module and a short quiz. Do it promptly. One of the most common reasons for escalating a phishing test into an actual conversation with your manager is ignoring the follow-up training for weeks, because incomplete training is exactly what the compliance report highlights. If you entered your password on the fake login page, that is a slightly bigger deal but still not a disaster: change your real password now at myaccount.microsoft.com or myaccount.google.com under Security, and tell IT you did it, because they will want to confirm nothing was reused elsewhere. Repeat clicks matter far more than one click. Programmes typically escalate on pattern, not on a single incident: a second click means more training, a third might mean a conversation. Getting fired for one simulated click is not how these programs are designed to work anywhere reputable.
The four checks that will actually make you harder to fool
Skip the vague advice and learn four concrete habits. First, read the real sender address, not the display name. In Outlook, click the sender's name at the top of the message to expand the true address; on the Outlook mobile app, tap the sender. In Gmail, click the small triangle under the sender name to reveal the full "from" and "mailed-by" lines. Attackers control the display name completely, so "Microsoft Support" means nothing. Second, check where a link really goes before clicking: hover over it on a computer and read the address that appears in the bottom-left corner of your browser or Outlook window; on a phone, press and hold the link to preview the URL. Look at the part just before the first single slash. Third, treat urgency itself as the warning sign. Real IT departments almost never give you 24 hours to save your account. Fourth, verify through a channel you already trust: phone the person on the number in your company directory, or message them in Teams or Slack. Never reply to the email or call the number inside it.
How to tell IT, and why that conversation goes better than you expect
If you clicked and you are unsure whether it was a simulation or the real thing, report it immediately. In Outlook on Windows or the web, use the Report button on the Home ribbon and choose Report phishing; in Gmail, open the three-dot menu at the top-right of the message and choose Report phishing. If your company uses a Report Phishing add-in button, use that. Then send a short, plain message to your IT or service desk: what you clicked, roughly when, and whether you typed anything in. That is it. No apology essay required. Security teams genuinely prefer a fast report to a tidy one, because the first thirty minutes are when they can reset a password or block a session before anything spreads. Reporting early very rarely makes someone's situation worse, and staying quiet regularly has. And here is the kind truth to hold onto: being caught by your employer's practice email is the cheapest possible version of this lesson. You learned it in a safe environment, on a Tuesday, with nothing at stake but your pride. The people you should feel sorry for are the ones who learn it from a real attacker.
Common questions
Can you get fired for failing a phishing test?
Almost never for a single click. Phishing simulation programs are built as training tools, and the standard consequence for one click is a short assigned training module. Escalation is based on repeated clicks over months, not one mistake, and even then it usually means more training or a conversation with your manager. The situations where jobs are genuinely at risk involve people who repeatedly ignore mandatory training, or who bypassed a security control deliberately. Complete the follow-up training promptly and this stays a non-event on your record.
What happens after you click a phishing test email?
Usually a landing page appears telling you it was a simulated test, and a training assignment lands in your inbox within a day or two from a platform like KnowBe4, Proofpoint or your company's learning system. It is typically a five to fifteen minute video with a short quiz. Your click is logged against your account in a dashboard that security uses to measure the whole organization. No money moved, no data left, nothing on your computer was infected. The training completion matters more than the click itself, so do it early rather than letting reminders pile up.
I entered my password on a fake phishing test page, what do I do?
Change your real password right now, then tell IT. For a Microsoft 365 account go to myaccount.microsoft.com and choose Password; for Google Workspace go to myaccount.google.com under Security. If you used that same password anywhere else, personal accounts included, change it there too, because password reuse is what turns one mistake into several. Then send a short message to your service desk saying what you entered and when. They will not be angry. They ask precisely so they can confirm nothing needs resetting, and a fast report is far more useful to them than a perfect one.
Why does my company send fake phishing emails to employees?
Two reasons. Practice measurably reduces how many people fall for the real thing, and phishing is the most common way organizations get breached. The second reason is compliance: standards like PCI DSS requirement 12.6.3.1 expect security awareness training covering phishing and social engineering, and similar expectations appear in HIPAA, ISO 27001, cyber insurance renewals and customer security questionnaires. Your employer often needs documented evidence that testing happened. You were not targeted because anyone suspected you. You were on the list because you have a work mailbox.
How do I spot a phishing email before I click?
Check the real sender address rather than the display name. In Outlook click the sender's name to expand the full address; in Gmail click the small triangle under the sender to see the from and mailed-by lines. Hover over any link and read the destination in the bottom-left corner before clicking, or press and hold on a phone. Treat urgency as suspicious on its own, since real IT teams rarely give you 24 hours to save your account. When something asks for money, credentials or a change to payment details, verify by phoning the person on a number from your company directory or messaging them in Teams or Slack.