After a click
How To: Know the Risks of a Phishing Link
Updated 17 August 2026
In short. Opening the message is usually not the incident. Clicking the link or opening the attachment is.
What the click is for
- Credential harvesting — a copy of a bank, Microsoft 365, or intranet login. Anything you type goes to the attacker.
- Malware — a download or a page that tries to run something on the device.
- Session theft — capturing a cookie or token so they do not need your password.
- Payment diversion — a “Pay supplier” or CEO wire that sends money to the wrong place.
- List validation — even a page that “does nothing” can confirm the address is live.
“I only clicked, I did not type anything” is still worth reporting.
Warning signs on the page
- Unexpected login.
- Browser warning.
- Immediate download.
- An MFA prompt you did not start.
Close the tab. Do not enter more data. Do not “finish the reset” to be helpful.
Business email compromise
A forged executive asking you to pay quietly is the same family of risk. The damage is not always malware — it can be a wire nobody in finance approved.
Tells:
- Urgency and secrecy.
- A lookalike “intranet” button.
If the click already happened, respond on this checklist. Catch the next one by spotting the link first.
