Appearance
What to Do If You Clicked a Phishing Link
Applies to: Microsoft 365 (Outlook, Teams, OneDrive), Windows 11, Windows 10
Article Type: Troubleshooting
Last Updated: 2026-07-29
Summary
You clicked something you now think was fake. Take a breath — clicking a link is not the same as losing your account, and in most cases the damage is nothing at all. This article tells you exactly what to do in the first five minutes, in order of urgency, and helps you work out which of those steps actually apply to you.
Symptoms
You are in the right place if any of these describe what happened:
- You clicked a link in an email, text, or Teams message and the page looked wrong once it loaded.
- You typed your work email and password into a sign-in page that turned out to be fake.
- You approved a Microsoft Authenticator prompt right after clicking, or one arrived unexpectedly afterwards.
- You downloaded or opened a file the page offered you — an invoice, a scanned document, a "secure message" viewer.
- The page asked you to enable macros, run an installer, or copy and paste a command.
- Nothing visible happened at all, but the sender address looked wrong once you re-read the email.
Prerequisites
- A second device you can use — a phone, a tablet, or another computer.
- Your Microsoft 365 work account sign-in details.
- No admin rights required. Every step here is available to a standard user.
Instructions
1. Work Out How Serious This Is
Before you do anything else, work out which of these three levels you are in. They call for very different responses, and readers routinely assume the worst when they are at level one.
- Level 1 — You loaded the page and typed nothing. Your account is not compromised by this alone. A web page cannot read your saved password or sign in as you because you visited it. Go to Step 7, report the email, then run the scan in Step 8 for peace of mind.
- Level 2 — You entered your username and password, or approved an MFA prompt. Treat this as an active compromise. Do every step below, starting with Step 3, and do it now.
- Level 3 — You downloaded or opened a file, enabled macros, or ran something the page told you to run. Treat the device itself as compromised as well as the account. Start at Step 2.
Note: Entering only your email address on the first screen of a fake login page, and stopping before the password screen, is level 1. Attackers split the sign-in across two pages precisely so the first one looks harmless.
2. Disconnect from the Network If You Entered Details or Opened a File
This step applies to levels 2 and 3. Disconnecting stops anything that landed on the device from sending data out or pulling more down, and it buys you the minutes you need to change your password.
- If the computer uses Wi-Fi, click the network icon in the bottom-right corner of the taskbar, next to the clock, to open Quick Settings.
- Click the Wi-Fi tile so it turns from blue to grey. The network name disappears from under the tile and a globe with a slash appears in the taskbar.
- If the computer uses a cable, unplug the Ethernet cable from the back or side of the machine.
- Leave the computer switched on. Do not restart it, and do not switch it off.
Why leave it on: Restarting can wipe evidence that helps IT identify what ran. Disconnecting achieves the containment; a restart does not add to it.
3. Change Your Password from a Different Device
Use your phone or a second computer. If a keylogger landed on the machine you clicked on, changing the password from that same machine hands the new one straight over.
- On the second device, open a browser and go to
myaccount.microsoft.com. - Sign in with your work account. If a Microsoft Authenticator prompt appears and you did not trigger it, tap Deny — that prompt is the attacker, not you.
- Click Password in the left menu. On some tenants this sits under Security info instead.
- Enter your old password, then a new one that you have never used on any other account. A passphrase of four unrelated words with a number and a symbol, such as
Harbour-Cello-Ninety-Rust7!, beats a short complicated one. - Click Submit. The page returns to your account overview and Microsoft signs out most other sessions automatically.
Verification: Open Outlook on the affected computer once it is back online. Being prompted to sign in again confirms the old password no longer works anywhere.
4. Sign Out of Every Active Session
A password change ends most sessions but not all of them. Signing out everywhere invalidates the tokens an attacker may already be holding.
- Still on
myaccount.microsoft.com, click Devices in the left menu. - Click Sign out everywhere at the top of the device list.
- Confirm when the dialog asks. Each device in the list updates to show it has been signed out.
- Expect to sign in again on your own phone and computer afterwards. That is the step working.
5. Check Your Security Info for an Authenticator You Did Not Add
This is the step most guides leave out, and it is the one that decides whether the attacker is actually gone. If they registered their own phone or authenticator app while they had your password, they can pass MFA on your account even after you change the password.
- On
myaccount.microsoft.com, click Security info in the left menu. - Read every entry in the list. You are looking at phone numbers, Microsoft Authenticator registrations, alternate email addresses, and any Passkey or Security key entries.
- Compare the list against what you set up yourself. A phone number with digits you do not recognise, or a second Microsoft Authenticator entry when you only ever set up one, is the attacker.
- Take a photo of the screen with your phone before you touch anything. IT needs the exact wording and the timestamp.
- Report it immediately using the wording in Step 7. IT can block sign-in server-side, which is stronger than anything you can do from this page, and they may want the entry left in place while they check the audit logs.
- If you cannot reach anyone in IT and the entry is still listed, click Delete next to it and confirm. An attacker holding a registered authenticator can sign back in even after your password change, so removing it takes priority over preserving the record.
Note: While you are on this page, check that the phone number listed for text message codes is still yours. Swapping that number is a quieter way of achieving the same thing.
6. Check Your Mailbox for a Hidden Forwarding Rule
Attackers set up a mail rule within minutes of getting in, because it survives a password change. A typical rule forwards everything to an outside address and marks it read so you never notice.
- On the second device, go to
outlook.office.comand sign in. Use the web version — it shows every rule on the mailbox, including ones created by a script. - Click the gear icon in the top-right corner. In current Outlook on the web the full Settings window opens; in older versions, click View all Outlook settings at the bottom of the panel that appears.
- Select Mail in the left column of the Settings window, then Rules.
- Read every rule. Delete any rule you did not create by clicking the trash can icon to its right. Rules that forward mail to an address outside your organisation, delete incoming mail, or move it to RSS Subscriptions or Conversation History are the classic pattern.
- Select Forwarding in the same Mail list. If Enable forwarding is switched on and points at an address you do not recognise, switch it off and click Save.
- If you use classic Outlook for Windows as well, open it and click File > Manage Rules & Alerts to confirm nothing was left behind there.
Verification: After deleting a rule, the Rules page reloads and the rule is gone from the list. Send yourself a test message from your phone and confirm it arrives in your inbox unread.
7. Report It to IT with the Details They Need
IT can see things you cannot: which other people got the same message, whether the sign-in succeeded, and what the attacker did after it. Give them the facts in one message so nobody has to come back to you for them.
- Report the message itself in Outlook. Select the email, click Report on the ribbon, and choose Phishing. This sends a copy to Microsoft and to your security team with the headers intact.
- Send a separate note, or phone the helpdesk if your mailbox is involved, containing these five things:
- What you clicked — the sender address and the subject line of the email, copied exactly.
- What you entered — say plainly whether you typed your password, approved an MFA prompt, or neither.
- When — the approximate time you clicked, to the nearest ten minutes.
- What you have already done — "I changed my password, signed out everywhere, and checked my mail rules."
- What you found — the unrecognised authenticator entry, forwarding rule, or sign-in location, if any.
- If your account showed an authenticator you did not add, tell them in these words: "My security info lists an authenticator registration I did not create. Please block sign-in on my account and review the audit log from" followed by the time you clicked.
Tip: Report it even at level 1, when you typed nothing. The value to IT is knowing the campaign reached your organisation, so they can hunt for the colleagues who did enter their details and have not spoken up.
8. Run a Full Malware Scan on the Affected Device
This matters most at level 3, where you opened a file, but run it at any level. Reconnect the computer to the network first so the scanner can update its definitions.
- Reconnect Wi-Fi or plug the Ethernet cable back in.
- Click Start, type
Windows Security, and press Enter. - Click Virus & threat protection in the left sidebar.
- Under Current threats, click Scan options.
- Select Full scan and click Scan now. A progress bar appears with a running count of files checked. A full scan takes 30 minutes to two hours, and you can keep working while it runs.
- If you opened an attachment or ran an installer, return to Scan options afterwards, select Microsoft Defender Antivirus (offline scan), and click Scan now. The computer restarts and scans before Windows loads, which catches things that hide once Windows is running.
Verification: When the scan finishes, Current threats reads
No current threats.with the time of the last scan below it. If threats are listed, click Start actions to quarantine them, then tell IT the exact threat name shown.
Troubleshooting
WARNING
Never approve a Microsoft Authenticator prompt you did not trigger yourself, however many times it appears. Attackers who have your password send prompt after prompt hoping you will tap Approve to make them stop. Every Deny blocks them. If prompts keep arriving, your password is already known — go back to Step 3 and change it now.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| You cannot sign in to change your password | Attacker already changed it | Go to passwordreset.microsoftonline.com on your phone and reset it with your recovery method. If your recovery methods were changed too, phone the helpdesk and tell them: "I am locked out after a phishing compromise and need an admin password reset." |
| Authenticator prompts keep arriving after the password change | An attacker-added MFA method is still registered | Work through Step 5. A password change alone does not remove a second registered authenticator. |
| Colleagues say they got a strange email from you | Attacker sent mail from your mailbox | Check Sent Items and Deleted Items in Outlook on the web, then tell IT which contacts were mailed so they can warn them. |
| Mail has stopped arriving in your inbox | A hidden rule is diverting it | Follow Step 6 and check both Rules and Forwarding. Also check whether messages are landing in Archive or RSS Subscriptions. |
| The Report button is missing from the Outlook ribbon | Add-in not deployed on this mailbox | Forward the message as an attachment instead: create a new email, drag the suspicious message into it, and send it to your security team. Ask IT to enable the Report Message add-in for you. |
| You entered your password but nothing seems wrong | Credentials stored for later use | Do not wait for symptoms. Stolen credentials are frequently sold and used weeks later. Complete Steps 3 to 7 anyway. |
Related Articles
- How to Identify a Phishing Email
- How to Spot Fake Microsoft Login Pages
- How to Change Your Microsoft 365 Password
- How to Check Your Sign-In Activity in Microsoft 365
- How to Check If Your Email Was Compromised
- Understanding What to Do When You Suspect Your Account Has Been Hacked — An Employee Incident Response Guide
- How to Report an Email in Outlook
- How to Stop Fake Virus Pop-ups and Spam Notifications from Your Browser