What to Do When You've Been Phished: A Step-by-Step Response Guide
Imagine you just clicked a link sent from an unknown email address. You are now pretty sure it was a Phishing attempt. They caught you off guard, and now you’re thinking of your next move.
First, take a breath. Phishing happens to smart, careful people every day. Phishing attacks are continually improving to look more believable every day. Often, they rely on us being distracted. They mimic trusted brands, use professional language, and are psychologically engineered to produce interaction.
What you do in the minutes after being phished matters most.
Step 1 - Report the Incident
Report it to your IT department. This is an important step: make sure to tell your IT department what happened. The sooner they are aware, the sooner they can begin to check for compromise.
Step 2 - Take Action
- Disconnect from WiFi or unplug from the network. If the link downloaded something malicious, disconnecting cuts off its ability to connect with the attacker.
- Do not enter any credentials or information on the page that opened. Many phishing attacks build fake login pages (like banks, Google, or Microsoft login pages) to capture your credentials.
Step 3 - Change Your Passwords
Change your password(s) immediately, from a different device. If there is a chance your credentials were exposed, it is a best practice to change your passwords from a different device. If you reuse that password for other accounts, you will want to change those as well.
At MNS Group, we use and recommend Keeper Password Management Software, to create and manage passwords across your applications.
Step 4 - Turn On 2FA (Two-Factor Authentication)
While you are changing your passwords, it is a good idea to turn on 2FA. Start with your email, as this is often the key to a password reset. Make sure to set up a backup email or phone number that you control.
Even if your password is stolen, 2FA provides a second lock that is difficult for attackers to get past.
Step 5 - Be Vigilant
Continue to watch your account for unusual activity for a week or two after the incident. Be alert and keep an eye out for suspicious activity, 2FA prompts you didn't ask for, fraudulent purchases, login attempts from remote locations, and unusual activity in your social media accounts.
Final Thought
The worst outcome of a phishing attack is not usually from clicking alone, but from clicking and ignoring it as if nothing happened.
MNS Group works with businesses to develop a fast incident response, complete with security awareness training for phishing, social engineering, and monitoring that catches suspicious activity before an incident occurs.
Reach out to us today to learn more.
