Act in the first few minutes and do not blame the person. Disconnect the computer from the network, change their password from a different device, make sure multi factor sign in is on, and tell whoever looks after your IT. Most of the damage happens in the hour after the click, so a fast report from a staff member who is not scared of getting into trouble is the most valuable thing you have.
Why blame makes it worse
A scam email is designed to be clicked, and good staff click them every day. If the person who clicks expects to be shouted at, they will stay quiet and hope nothing happens. That silence turns a small problem into a big one. So the message to your team is simple. If you click something and feel uneasy, tell us straight away, and nothing bad will happen to you for telling us.
What to do in the first minutes
- Disconnect the computer from Wi Fi or unplug the network cable. This stops anything that has been installed from talking to the outside world.
- Do not turn the computer off. Turning it off can destroy the evidence of what happened.
- From a different device, such as a phone, change the password for the account the person was signed in to. If they typed their email password into the fake page, assume the scammer has it.
- Check that multi factor sign in is turned on for that account. Multi factor means a code from an app such as Microsoft Authenticator is needed as well as the password. If it was already on, check whether anything was approved around the time of the click.
- Tell your IT support what happened, when, and what the email looked like.
- Check the sent items for messages the person did not send, then check the inbox rules for anything that forwards or deletes mail. Scammers often add a quiet rule that copies everything to an outside address.
- Ask the person what they typed in. A password is serious. Bank details, customer information or a login for another system is more serious again, and each needs its own password change or a call to the bank.
When it becomes a reportable data breach
Under the Privacy Act, a business covered by the scheme must notify the privacy regulator and the people affected when personal information has been accessed in a way likely to cause serious harm. A click on its own is not a breach. A scammer reading a mailbox full of customer details, or forwarding it to themselves, probably is. If the account was accessed, treat it as a possible breach and get advice that day.
How to make the next click less likely
Turn on multi factor sign in for every account, so a stolen password is not enough on its own. Keep email filtering switched on. Run short, regular reminders about what scam emails look like, using real examples from your own inbox. And keep the reporting culture described above. The businesses that come through these incidents well are the ones where people speak up within minutes.
What to do next
If the click has already happened, follow the steps above and then read what to do if you have been hacked for the follow up checks. To get ahead of it, our cyber security work covers multi factor sign in, email protection and staff awareness for small offices.
The person only clicked the link and did not type anything. Is that fine?
Usually, but not always. Some links install software just by being opened. Disconnect and have the machine checked.
Should I just wipe the computer?
Not before someone has looked at it. Wiping removes the evidence of what happened and whether anything spread.
Do I need to report it to anyone?
Report scams to Scamwatch, and if money was lost or an account was accessed report it to the ACSC. If personal information was exposed, the Privacy Act section above applies.
If this is happening in your business and you would like it sorted, call DM1 on (08) 6202 6012 or send us a message. We look after IT, Microsoft 365, websites and domain names for Perth small businesses.
