Most ransomware starts with one click.
Phishing, spoofing, and their voice and text cousins are still the number one way attackers get in. Here's what to watch for, and exactly what to do if you already clicked.
Signs of a phishing attempt
The whole family of social engineering
Business Email Compromise (BEC)
An attacker impersonates an executive or vendor, usually to redirect a wire transfer or payment.
Smishing
Phishing by text message, often impersonating delivery services, banks, or even your own IT provider.
Vishing
Phone-based social engineering — increasingly using AI-cloned voices of real executives or family members.
Quishing
Malicious QR codes, often placed over legitimate ones on parking meters, menus, or flyers.
Steps to take right away
Disconnect from the network
Unplug or disable Wi-Fi on the device you clicked from.
Don't enter any more information
If a fake login page is still open, close it without typing anything further.
Change your password from a different, clean device
Assume the password you entered is already compromised.
Confirm MFA is still yours
Check for any MFA method you don't recognize and remove it.
Tell IT or safemode IT immediately
The faster this is reported, the smaller the blast radius. See our full incident response guide.
Report it without fear of blame
Anyone can be fooled by a good phishing attempt. Fast reporting is a win, not a mistake.
Where to send a phishing attempt
See how your team does against a real simulated phishing test.
We can run a baseline phishing simulation and turn the results into a short list of what to fix first.