Skip to content

What to Do If You Clicked a Phishing Link

Applies toMicrosoft 365OutlookMicrosoft TeamsOneDrive
15 min fix Updated 29 Jul 2026
Quick Answer

If you entered a password or opened an attachment, disconnect from Wi-Fi, change your password from a different device, then use Sign out everywhere in your Microsoft account. If you only viewed the page and typed nothing, close the tab and report the email.

Checked against Microsoft Learn - end of support and retirement, Microsoft 365 Roadmap and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Last updated:

Frequently asked questions

I clicked a phishing link but did not enter my password. Am I hacked?
Almost certainly not. Loading a page does not hand over your account. The danger begins when you type credentials into it, approve an MFA prompt, or open a file it offered you. Close the tab, report the email, and run a malware scan to be certain.
How long do I have to act after clicking a phishing link?
Attackers often use stolen credentials within minutes, so treat the first five minutes as the window that matters. Changing your password and signing out of all sessions are the two actions that shut the door fastest.
Should I delete the phishing email after I report it?
Report it first using the Report button in Outlook, which sends a copy to Microsoft and your security team. Once it has been reported, deleting it is fine. Do not delete it before reporting — IT needs the message headers to trace who else received it.