Staff Clicked a Phishing Link? Do This in the Next 30 Minutes

February 2026 ยท 7 min read ยท Email Security

"I've been hacked" Slack message at 3pm. Here's the exact 10-step playbook we use for 30+ SMEs in Pretoria when credentials are compromised.

First 5 Minutes: Contain the Breach

  1. Isolate device: Unplug ethernet cable, disable Wi-Fi. Don't shut down โ€” you need logs.
  2. Force sign-out all sessions: Azure AD > Users > [User] > "Revoke sessions". Kills access on all devices.
  3. Reset password: Use a different, clean device. Make it 16+ characters. No variations of old password.
  4. Enable MFA if not already: SMS codes can be intercepted. Use Authenticator app with number matching.
  5. Check for inbox rules: Outlook > Rules > Look for "forward to external" or "delete". Attackers hide here.

Next 25 Minutes: Investigate Damage

  1. Audit sign-in logs: Azure AD > Sign-ins > Filter "Failure" + look for IPs from Nigeria, Russia, China.
  2. Check mailbox audit: Did they send mail? Compliance > Audit > Search "Sent Items" for last 24h.
  3. Scan device: Full EDR scan with SentinelOne/Defender. Don't reconnect to network until clean.
  4. Review Safe Links: Defender > Submissions > Check if malicious URL was clicked. Block domain tenant-wide.
  5. Document timeline: Who clicked, when, what they entered. Needed for POPIA breach report if data leaked.

Next 24 Hours: Report + Harden

Prevention: 3 Settings to Change Today

Download 1-Page PDF Checklist

Print it. Stick it on your IT wall. Give to all staff.

Download PDF