Skip to content

What to do if you clicked, or think you're compromised

The most important move after a mistake is to report it fast — not to hide it. Here's the calm, step-by-step response, and why speed matters more than blame.

EveryoneIntro5 min· Updated Jul 22, 2026
TL;DR

The short version

Don't panic and don't hide it. If you entered a password, change it (and anywhere you reused it) and sign out of all sessions. Then report it to your IT or security team immediately — fast reporting is what limits the damage. You will not get in trouble for reporting; you might for staying quiet.

Everyone slips eventually — a convincing email, a busy moment, one click. What separates a scare from a serious breach is what you do in the next few minutes. The instinct to feel embarrassed and quietly hope it's fine is the one instinct to override, because time is the attacker's biggest advantage and reporting is how you take it away.

If you entered your password on a suspicious page

  • **Change that password now** — from a device you trust, by going to the real site directly, not through the suspicious link.
  • **Change it everywhere you reused it.** This is exactly the situation reuse makes worse.
  • **Turn on MFA** if it wasn't already on, and **sign out of all active sessions** in the account's security settings so any attacker session is cut.
  • **Report it** to IT or security straight away.

If you approved an MFA prompt or shared a code

Treat the account as compromised. Change the password, sign out all sessions, and report it immediately — the attacker may already be inside, and your IT team can revoke access and lock things down far faster than you can alone.

If you opened an attachment or the device is acting strangely

  • **Disconnect from the network** (turn off Wi-Fi / unplug the cable) to stop anything spreading.
  • **Don't turn it off or try to "clean" it yourself** unless IT tells you to — they may need to see it as-is.
  • **Report it immediately** and follow their instructions.
Pitfall

Hiding it is the only real mistake

A phishing click, reported in the first ten minutes, is often a non-event. The same click discovered a week later can be a major breach. Organizations with a healthy security culture thank people for reporting — they don't punish them.

How to report

Know the path before you need it: most workplaces have a security email address, a "report phishing" button in the mail app, or a helpdesk number. Include what happened, when, and what you clicked or entered — even a quick "I think I fell for a phishing email" is enough to get help moving. If it involved a personal bank or payment account, contact that provider directly too, and consider reporting fraud to the relevant national authority.