You Accidentally Clicked on a Phishing Email. Now What?

Phishing attacks are more common—and more sophisticated—than ever. Whether you’re a small business owner or just putting in your 9-5, you’re a target. Scammers are aiming to steal sensitive data, financial information, and even access to business systems. If you’ve accidentally clicked on a phishing email, it’s easy to panic. But you don’t need to.
What is Phishing and Why Does It Matter?
Phishing is a form of online fraud where scammers try to trick victims into sharing sensitive information like passwords, credit card details, or business credentials, or deceiving people into making fraudulent transfers and payments. These messages, usually emails or texts, are designed to look as real as possible, and can even appear to come from legitimate sources. For small businesses, phishing can lead to financial losses, data breaches, and reputational harm.
How to Identify a Phishing Message
Common Signs of Phishing Emails
- Urgent Language: Phrases like “Act now!” or “Your account will be suspended” are designed to spark panic.
- Spelling and Grammar Errors: Professional organizations rarely send communications riddled with mistakes.
- Unexpected Attachments: Files you weren’t expecting could contain malicious software.
- Strange Email Addresses: The sender’s address might look close to a real one but includes typos or odd domains. For example, “[email protected]” instead of “[email protected].”
- Suspicious Links: Hover over links to check the URL. If it doesn’t match the content of the email or leads to an unrelated site, it’s likely a fake.
Examples of Sophisticated Phishing Attempts
Personalization
Impersonation
Zero-click Attachments
Understanding Session Hijacking
How Does Session Hijacking Work?
How Phishing and Session Hijacking Work Together
- Cross-Site Scripting (XSS): Phishing sites can contain malicious scripts. Once a user loads that page, a script can steal the cookies containing the session ID and send them to the attacker’s server. The XSS attack is injected into the target website via a malicious link contained in the phishing email.
- Man-in-the-Middle (MitM) Attacks: A phishing email might redirect you through the attacker’s server before getting to the legitimate site. The MitM server then intercepts the session ID.
Potential Consequences
How to Detect Session Hijacking
- Check for active sessions by reviewing your account activity. Some platforms, such as Google or Microsoft, allow you to see where your account is logged in. You can log these devices out manually from here.
- Look for unusual activity, such as changed passwords or unauthorized logins from unknown locations.
Preventing Session Hijacking
- Use multi-factor authentication (MFA) options like one-time passcodes, preferably delivered through an authenticator app.
- Avoid public Wi-Fi or use a virtual private network (VPN) for secure connections.
- Don’t click on links in emails. Go directly to the website by typing in the address.
- Always log out of accounts when finished.

Immediate Steps After Clicking on a Phishing Email
Step 1: Assess the Damage
Step 2: Protect Your Information
- Disconnect from the internet: This helps prevent malware from spreading further.
- Change passwords: Update all compromised or potentially compromised accounts. Use strong, unique passwords.
- Run a malware scan: Use antivirus tools to check for harmful downloads or software.
- Contact your bank or credit card company: Report any abnormal activity immediately.
- Place a fraud alert on your credit report: Contact the credit bureaus (Equifax, Experian, and TransUnion) to place a fraud alert on your credit report. This will make it more difficult for someone to open new accounts in your name.
Step 3: Report the Incident
- Report To Authorities: File a report with the FTC, FBI’s Internet Crime Complaint Center (IC3), or local law enforcement.
- Inform Your Contacts: Notify colleagues or contacts not to open suspicious emails they may receive from your account.
- Report the Email: Use your email provider’s dedicated reporting tools to flag the email as a phishing attempt.
Phishing Recovery 101: Steps to Protect Your Data
Monitor Accounts for Fraud
Keep an eye on all your accounts moving forward to look for unauthorized transactions and any suspicious activity like password changes or contact information updates.
Strengthen Future Protections
- Using strong, unique passwords across platforms.
- Adopting multi-factor authentication to add extra layers of security.
- Staying vigilant against suspicious emails or attachments.
Protecting Your Business
Stay Cyber Aware
Phishing threats are constantly evolving, but by knowing how to identify and respond to them, you can protect both your personal information and your business. When it comes to phishing, prevention is your best method for protecting your business. But should the worst happen, taking quick action and using proactive methods can help reduce the damage and prevent future problems.
Ready for What’s Next?
Have questions? Ready to start building a relationship with one of our experienced bankers?



