Clicked a phishing link at work: what now
Clicked a phishing link at work: what now
If you clicked a phishing link at work, what you do next is a one-hour job, and it differs from what you would do on a private phone. Disconnect the laptop if you can do so safely, stop typing, and tell whoever runs IT the same day. You do not need to decide whether a crime was committed before you report.
Consumer pages, including the BACS phishing note, tell a private person to change the password immediately, and to change every service tied to that email address. That order is right for a personal account. A company mailbox needs one more step. Microsoft lists revoking sign-in sessions separately, because that is what invalidates the refresh tokens an attacker may already hold. A new password does not do it. Do not email the new password to the user while the mailbox may still be open (Microsoft Learn). Your IT partner does the reset, not you on the same laptop.
This is for employees and line managers in a Swiss company of roughly 20 to 250 people, often without a security team. It covers the first hour. Spotting the mail before anyone clicks is a different article.
Stop and disconnect
Unplug Ethernet or turn off Wi-Fi on the affected laptop if IT has not told you otherwise. Leave the tab open if someone needs a screenshot. Do not download another file, and do not open the link a second time.
Report inside the company, the same day
Use the channel you already have: a ticket, a shared mailbox, or the number in your incident note. Say what you clicked, at what time, and whether you typed a password, entered a code, or approved a sign-in on your phone.
Reset with IT, not alone
Microsoft’s preferred first step is to disable the account while it is checked, then revoke sessions, then set a new password. A rushed reset on the wrong account locks a colleague out and misses the mailbox the attacker took.
Have rules and payments checked
BACS describes a forwarding rule as a typical next move once a business mailbox is taken. Finance and IT check the rules, the recent sign-ins and any payments waiting to go out before anything is released.
Click only, password entered, or an attachment opened
The three cases look the same from across the office, yet each needs a different hour.
Link only, nothing typed, no attachment: report the sender and the time. IT can block the domain. BACS describes the harm of phishing mainly as credentials or card details handed over. Do not announce that the laptop is certainly infected, and do not clear the browser history before someone has looked.
Password, one-time code, or an Approve tap on the phone: treat the mailbox as open until IT says otherwise. That includes a Microsoft 365 password. IT disables the account for the check or resets it, revokes sessions, reviews registered sign-in methods, and looks for rules, including hidden ones, that forward mail out or move it to Notes, Junk or RSS. Those are the folders Microsoft names. The new password is given by phone or in person and never mailed back to the same inbox.
If the fake page also got a private password or a card number, that is a second call the same day. BACS says to change that password everywhere you reused it, and to call the card company so the card can be blocked. That is your private account, and it does not replace the report at work.
An opened attachment is a different risk from a copied login page. Tell IT about it explicitly, stop working on that machine, and do not plug it into another network to finish the invoice. This article has no malware-removal procedure: IT decides whether the device is examined.
What a supervisor does in the first hour
Thank the person for reporting. A reprimand before the facts are known teaches the next person to stay quiet. Keep them off the affected machine, and bring in IT or your external partner the same day.
Ask for a short note: time, sender or link, whether any credential was entered, whether an attachment was opened. Do not forward the original mail to a personal address or a WhatsApp group. Use the ticket or the channel you already have.
On a taken business mailbox, BACS on invoice fraud lists a password change, a look at the IT environment, a check of filters and forwarding rules, and a warning to people who might receive fraudulent messages. It also recommends a police report, including when money has already been lost. Management files it. If money is moving and nobody can reach the bank, call 117 or 112. One click with no payment is not that emergency.
Emails that say “your account was hacked, click here” are a common lure of their own. BACS says not to open those links and to type the service’s real address by hand (account hacked).
Reporting to BACS, the FDPIC, and the police
The internal process comes first. A report to BACS is voluntary for most companies and helps get the page blocked, especially on a .ch or .swiss domain. If you do not need a reply, forward the mail to reports@antiphishing.ch or submit the link at antiphishing.ch. If you want a reply, start from the BACS reporting page, which is in German. The form’s exact address changes from time to time, so start from that page.
The cyberattack reporting duty in force since 1 April 2025 applies to operators of critical infrastructure, not to a typical SME (BACS on the duty). So there is no 24-hour deadline you could miss tonight.
A click alone does not automatically mean a report to the Federal Data Protection and Information Commissioner (FDPIC). The revised Federal Act on Data Protection requires a report only when a high risk to the people concerned is likely, and then as soon as possible. It sets no 72-hour deadline of the GDPR kind. Whether the mailbox held customer, staff or applicant data, and whether anyone could read it, is for management to judge. Write down the facts, the effects and what was changed. This is practical orientation, not legal advice (Art. 24 FADP).
Knowing whom to call is the kind of organisational measure the act has in mind for data security. It does not literally require training (Art. 8 FADP). Fines of up to CHF 250,000 apply to natural persons and require intent (FDPIC on criminal provisions). An accidental click does not meet that test.
For scale: BACS counted 29,006 voluntary reports and 145 under the reporting duty in the second half of 2025. Deloitte’s 2026 survey of 924 people at firms under 250 staff names phishing as the most common attack, at 25 percent (Deloitte, PDF). Both are their measurements, not ours.
Share of voluntary reports to BACS in the second half of 2025 classed as fraud, in the semi-annual report. Their count, not a figure for your company.
Tuesday morning in a 45-person firm
A made-up example: a company with 45 staff in the canton of Bern, no client names. On Tuesday at 09:15 an employee opens a message that looks like a parcel notice, clicks the link, types their Microsoft 365 password on a copied login page, and taps Approve on their phone. At 09:22 they unplug the cable and call the office manager. By 09:40 the IT partner has disabled the account, revoked the sessions, set a new password and read it out by phone. Among the mailbox rules is a hidden forwarder sending copies of invoices to an outside address. Finance holds two payments that were approved only by email, until a colleague confirms the IBAN by phone. The incident note is half a page and stays inside the firm. Later that week a voluntary report goes to BACS with the sender domain and no names.
Who can skip the long version
You only opened the mail, clicked nothing, opened no attachment and typed nothing: note the sender and use the normal reporting channel.
On your own phone, with no company mailbox: follow the BACS steps for private individuals. A sole trader with no staff follows the same steps without an internal IT contact.
Questions after the click
Should I change the password myself right now?
On a private account, yes. That is what BACS tells individuals, including on every service where the same password was reused. On the company mailbox, IT does it: disable or reset the account, revoke sessions, and inspect the rules. Do not email the new password back to that mailbox.
Is the click already a report to the FDPIC?
No, not by itself. A report is due when a high risk to the people concerned is likely, as soon as possible. Whether the mailbox held personal data, and whether anyone could read it, is a separate judgement. Write the incident down either way.
Do we have to tell BACS within 24 hours?
A typical SME does not. The duty since 1 April 2025 applies to operators of critical infrastructure. You can still report voluntarily afterwards, via antiphishing.ch or the BACS reporting page. Containment inside the company comes first.
I only opened the message. Does the same sequence apply?
No. Note the sender and report it internally so the domain can be blocked. Disconnecting, revoking sessions, and holding payments belong to a click with input, an approved sign-in, or an opened attachment.
Live training, after this hour is over
A live security awareness session spends one to two hours on how your company recognises phishing, smishing, and vishing, how people report internally, and what still applies after a click. The first hour belongs to IT. The session is a later appointment and does not replace today’s report. Format and scope are on the security awareness page.
Written by
Aurum Avis Labs
Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.
Related Articles
You might also be interested in these articles
Are phishing simulations allowed in Switzerland?
Phishing simulations are allowed in Switzerland if staff are told first and clicks are not used to judge a person. Swiss labour law, not German rules.
Security awareness training topics for Swiss SMEs
Which security awareness training topics belong in a session for Swiss SMEs: phishing, payments, passwords, reporting and role-specific risks.