Phishing messages increasingly look professional, use familiar branding and refer to a document, invoice or delivery the employee expects. Clicking a link is not proof of carelessness, but a slow response can turn one mistake into a serious business incident.
Opening a message is not the same as entering a password, approving an MFA request or running a downloaded file. The first task is to establish exactly what happened without hiding the mistake or creating panic.
First five minutes: stop further activity
The employee should close the suspicious page and contact the responsible person or IT support immediately. Do not reopen the link for another look and do not forward the message to colleagues without a warning.
If a file was downloaded and opened, disconnect the computer from the network, but avoid switching it off randomly before speaking to IT. In some incidents, the active state of the system is useful for investigation.
If a password was entered
Change the password from another trusted device and revoke all active sessions. A simple password change may not be enough because an attacker could already possess a valid session token.

Review MFA methods as well. Remove unknown phone numbers, authenticator applications and security keys. If the employee approved an unexpected MFA request, treat the account as compromised.
Check email rules and forwarding
Attackers often create inbox rules that hide incoming messages, move replies to an archive or forward mail to an external address. This allows them to follow a conversation and prepare a convincing fraudulent payment request.
Review inbox rules, automatic forwarding, delegates, applications with account access and recent sign-ins. Pay particular attention to unusual locations, devices and login times.
Warn colleagues and partners when necessary
If the compromised account sent messages, warn recipients quickly through another trusted channel. Avoid replying in the same email thread when the attacker may be monitoring the mailbox.

Requests to change bank details, make an urgent payment or send a confidential document should be confirmed by telephone using a previously known number.
If a file was downloaded or launched
IT should inspect running processes, antivirus alerts, browser extensions and recent system changes. A clean antivirus result at that moment is not enough. Saved browser sessions, local documents and shared-folder access may also be at risk.
Return the computer to the network only after the investigation is complete. When doubt remains, preserve necessary business data and perform a controlled reinstall.
Improve the process instead of blaming the employee
Record the time, message, link, user actions and response steps. This information helps assess the incident and improve filters, rules and employee training. An employee who reports a mistake quickly may prevent much greater damage.
NBG TEAM provides emergency IT support for businesses in Belgrade and can check Microsoft 365 sessions, mailbox rules and affected computers. Speed matters in a phishing incident, but the response steps also need to happen in the correct order.
Sources and further reading
For help with your specific business environment, see our business IT support service.



