Cybersecurity
What should I do if I clicked a phishing link?
Immediate steps to contain risk after opening a suspicious link or attachment.
Answer
Act quickly, but do not panic. Disconnect the affected device from Wi-Fi or Ethernet if you entered credentials, downloaded a file, or noticed unexpected behavior. Use a different trusted device to change the password for the affected account and enable multi-factor authentication. Business users should notify their IT or security contact immediately so logs, sessions, and endpoints can be reviewed.
Recommended steps
- Disconnect the affected device if compromise is possible.
- Change the exposed password from a trusted device.
- Revoke active sessions and enable multi-factor authentication.
- Run an approved endpoint security scan.
- Report the message to your IT provider and email administrator.
