You think you have been phished: what to do in the first ten minutes

You think you have been phished: what to do in the first ten minutes

You clicked a link, typed your password into a page that looked right, and something feels off. Maybe the page reloaded and asked again. Maybe a colleague replied to an email you never sent. This one catches everyone, including people who are good with computers, because the fake pages are copies of the real ones.

The next ten minutes matter more than anything else. Nobody at YouGrowIT will tell you off for clicking something. What we care about is knowing early, because early is what limits the damage.

Try this first

  1. Change your password from a different device. If you typed your password into a fake page on your laptop, use your phone, or another computer. If the laptop is the thing that is compromised, changing the password on it can hand the new password straight to the attacker. Go to the real sign-in page yourself by typing the address in, not by clicking a link in any email.
  2. Call us on 03 9028 4358. Do not email. If someone else is reading your mailbox, an email saying "I think I have been hacked" tells them you are onto them, and they will move faster. A phone call does not. Tell us what you clicked, roughly when, and what you typed in.
  3. Do not delete the email. It is tempting, and it is the wrong move. That email carries the technical details we need to work out where it came from, who else received it, and what the attacker was after. Leave it where it is. If it is upsetting to look at, drag it to a folder rather than the bin.
  4. Warn anyone who may have been emailed from your account. If your mailbox has been used, the first thing it sends is more phishing, usually to your contacts and often to people mid-conversation with you. A quick phone call or message to your team, and to any supplier or client you were emailing that week, stops the second wave. Tell them plainly: if you got an email from me in the last day asking you to open a link or change bank details, ignore it and ring me.
  5. Check for new inbox rules. This is the step people miss. Attackers almost always add a hidden rule that files your incoming mail into a folder like Archive or RSS Feeds, or forwards it elsewhere, so you do not see the replies. In Outlook on the web, open Settings, then Mail, then Rules. In new Outlook for Windows, it is under View, then View settings, then Mail, then Rules. If you see a rule you did not create, do not delete it yet, take a photo or a screenshot and tell us. It is evidence.

If that didn't fix it

If you cannot sign in at all, the attacker may have already changed the password or the multi-factor settings. Multi-factor authentication is the code or prompt you approve on your phone. Ring us straight away on 03 9028 4358 rather than trying repeatedly, and we will recover the account from the administrator side.

While you wait, gather what you can: the time you clicked, the address of the page you landed on if you can still see it in your browser history, whether you approved any prompt on your phone, and whether any money or bank detail change was involved. If a payment was made or bank details were changed, tell us immediately and call your bank as well.

Why speed matters

Once an attacker is in a mailbox, the clock is on them, not you. They read your recent conversations, look for invoices and payment threads, set up rules to hide their tracks, and then use your name to ask someone for money. Every one of those steps takes them time. Reporting in the first ten minutes usually means we lock the account before the useful part of their work is done.

The reverse is also true, and it is the honest reason we push this so hard. Most of the expensive incidents we see were not clever attacks. They were ordinary ones that nobody mentioned for two days.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • How to spot a phishing email

      Phishing is an email designed to get you to do one of three things: type your password into a fake page, open an attachment, or pay someone. The good ones do not look like scams. They look like a Microsoft notice, a delivery slip, a signature ...
    • Ransomware: what it looks like and what to do

      Ransomware is software that locks up your files and then asks for money to unlock them. Businesses of every size get hit, and getting hit is not evidence that anyone was careless. What separates a bad week from a very bad month is what happens in the ...
    • Why we send you security alerts, and which ones matter

      If we look after your systems, you will get emails from us about security. Some ask you to do something, most do not, and after a while it is easy to stop reading them. That is the outcome we most want to avoid, so here is exactly what we send and ...
    • Invoice fraud and payment redirection: the scam that costs the most

      Of everything that goes wrong with email, this is the one that takes real money out of a small business, and often tens of thousands of dollars at once. It is not a virus and it is not clever software. It is an ordinary email that asks you to pay the ...
    • Using your own phone or laptop for work, safely

      Most small businesses run on personal devices to some extent. Someone checks email on their own phone, a director works from a home laptop, a part-timer uses their own machine two days a week. That is normal and it can be done safely. The risk is not ...