Overview

This article provides a low-risk, evidence-driven troubleshooting path for you clicked a phishing link: what to do next. Work from identity and service checks toward more disruptive actions, and stop before a change could cause data loss, broaden access, weaken security, or interrupt other users.

Start with the safest layerRecord the current state before changing settings. Use only approved accounts, tools, and administrative processes.

Why this happens

Security warnings and suspected account compromise require evidence preservation, safe containment, credential protection, and coordinated administrator-side review rather than ordinary trial-and-error troubleshooting.

Before You Begin

  • Preserve screenshots, alert text, times, sender addresses, and other useful evidence.
  • Use a known-clean device for sensitive account changes when practical.
  • Do not approve unexpected MFA prompts or communicate secrets to an unverified requester.
  • If ransomware or active compromise is suspected, prioritize containment and escalation over ordinary troubleshooting.

Navigation reference: Official work account portal > Security.

Click-by-Click Troubleshooting

Step 1: Stop interacting with the page

Action: Close the suspicious browser tab. Do not enter credentials, approve MFA, download files, or continue through prompts.

Why this matters: Stopping interaction limits additional exposure.

What to look for: Note whether credentials, payment data, or files were already entered or downloaded.

Expected result: No further information should be submitted to the suspicious site.

Step 2: Disconnect only when active malware is suspected

Action: If a download ran, security warning appeared, or the device is behaving abnormally, disconnect Wi-Fi or Ethernet and contact IT immediately. Otherwise keep the device available for account remediation.

Why this matters: Unnecessary isolation can disrupt evidence collection, but active malware may require containment.

What to look for: Look for downloads, unexpected applications, security alerts, or unusual device behavior.

Expected result: The response path should match whether this is credential exposure only or possible malware execution.

Step 3: Change the exposed password from a known-clean session

Action: If credentials were entered, use a known-clean device or trusted browser session to change the affected work password through the official account portal.

Why this matters: Changing the password can invalidate a stolen secret before it is reused.

What to look for: Confirm the change succeeds and do not reuse the old password elsewhere.

Expected result: The exposed password should no longer be valid.

Step 4: Review MFA and sign-in activity

Action: Open the official account security page and review recent sign-ins and authentication methods.

Why this matters: Attackers may register an additional method or create sessions after credential theft.

What to look for: Look for unfamiliar locations, devices, methods, or successful sign-ins.

Expected result: Suspicious authentication activity should be identified for IT review.

Step 5: Report the incident

Action: Contact the organization's IT/security channel and provide the phishing URL, message, time clicked, whether credentials were entered, and whether anything downloaded.

Why this matters: Rapid reporting lets administrators revoke sessions, search related mail, and assess broader exposure.

What to look for: Provide facts without deleting browser history or evidence unless directed.

Expected result: IT should have a clear exposure timeline.

Step 6: Follow containment instructions

Action: Complete only the approved follow-up actions such as session revocation, endpoint scan, or mailbox review.

Why this matters: Coordinated remediation avoids destroying evidence or missing persistence mechanisms.

What to look for: Watch for new MFA prompts, password-reset notices, forwarding rules, or additional alerts.

Expected result: The account and device should return to a verified safe state.

What to Look For

  • Whether the issue affects one user/device or multiple users.
  • Whether a clean browser or alternate approved client changes the result.
  • Whether the error points to identity, permission, licensing, service, device, or network state.
  • Whether the same controlled test succeeds after the targeted correction.

When to Stop

Stop before troubleshooting becomes riskyDo not broaden access, bypass MFA/security, erase evidence, permanently delete business data, change tenant-wide settings, or perform destructive resets unless the approved IT process specifically requires it.

When to Contact IT

Contact J3 Systems Group if the issue remains unresolved, affects multiple users, requires administrator-level changes, involves security or data-loss risk, or the next step would be disruptive. Include article code KB-07.002, the affected account/device/resource, exact error, time observed, and the results of the controlled tests above.

Need help with this issue?

J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.

Contact J3 Systems Group

Authoritative references

Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.

Article KB-07.002 · Review after material vendor, licensing, interface, security, or service changes.