forumNew topic

a phishing email spread across the company, 30 people clicked the link — what to do?

LLeyla A***Member
Job title
Quality Assurance Manager
Sector
Food wholesale
Organization type
cooperative
Joined
Aug 2023
Message
103
#1

got an alert from the security email this morning: employees clicked on fake 'Microsoft Teams' emails, 30 people might have given up credentials. the email address looks like Microsoft's but it's fake.

i don't know if the passwords for those 30 people were changed. some accounts are now showing 'suspicious activity' — was malware downloaded? do we need to change passwords for the whole company?

what should we do next? police? insurance? notify clients? there's pressure on how many days we can keep the system down.

AAli Y***Member
Job title
Site Manager
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
129
Most Helpful#2

An incident response plan is required for the phishing attack. Immediate actions: 1) Identify the 30 affected accounts, 2) Review mail logs, 3) Check if any downloads/uploads occurred, 4) Initiate a malware scan.

Credentials: 1) change passwords immediately, 2) check if MFA was disabled, 3) scan the devices of those 30 people, 4) check all email logs from the last 48 hours.

Notification: inform clients that 'we are conducting a system security check, no data risk'.

HHüseyin Ş***Member
Job title
Network Administrator
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2023
Message
81

Doki · Brand identity · 2025

#3

clicking on phishinng links is normal about 100 people fall for this stuff every week. what matters is what you do now. if a download happened (malware installed) that's the concern.

ZZeynep E***Member
Job title
Customer service representative
Sector
Energy
Organization type
regional distributor
Joined
Apr 2025
Message
53
#4

30 people gave credentials but which ones gave passwords or 2FA codes? which ones just 'clicked' without providing info?

DDamla Y***MemberCommunity member
Joined
Sep 2022
Message
131
#5

examine the mail headers, find the IP of the fake mail server. check antivirus logs to see if any malware was detected.

Edit: asked below, I wrote the answer in the second message.

MMeryem A***Member
Job title
Logistics planning
Sector
Electrical-electronics
Organization type
regional distributor
Joined
May 2023
Message
62
#6

Urgent: Force password reset for 30 users (via email channel, force an antivirus product), enable MFA for the entire company, add the phishing email address to the spam list. Complete within 1 day.

BBeren C***Expert
Job title
Information Security Specialist
Sector
Logistics
Organization type
early-stage startup
Joined
Jul 2023
Message
227
#7

notify the client, no harm done. you've been victimized the client will hear about it from elsewhere anyway. if you report 'we've got it under control', your image stays better.

SSelim P***Veteran
Job title
Customer service representative
Sector
Plastic
Organization type
chain store
Joined
Jan 2024
Message
41
#8

I have no experience with phishing attack, so I'm asking. Everything goes well for the first three months; problems arise in the fourth.

Taking measures without an inventory leaves doors you haven't seen open. Hope this helps.

EEceMember
Job title
Legal Counsel
Joined
Feb 2024
Message
98

Doki · Backup setup · 2023

#9

You're right.

ÖÖmer M***MemberCommunity member
Joined
Nov 2023
Message
108
#10

Following. Forgotten test environments are more often the entry point than live systems.

KKübra M***MemberCommunity member
Joined
May 2025
Message
62
#11

I'd appreciate it if you shared the outcome. Most time waste accumulates in tasks waiting for approval.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. If you post the result here, it will help others too.

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
#12

Following.

OOsman A***ExpertCommunity member
Joined
Aug 2025
Message
316
#13

I didn't know that. If permission and scope aren't in writing, don't start that test.

Good luck with that.

BBerkMember
Job title
Real Estate Agent
Joined
Apr 2024
Message
102

Doki · Incident response support · 2026

#14

Correct.

YYiğit K***Member
Job title
Data entry clerk
Sector
Textile
Organization type
120-person company
Joined
Aug 2022
Message
193
#15

I was thinking the same thing. Trying to do this alone is the most expensive way.

Just leaving this note, it might be useful.

TTolga C***MemberCommunity member
Joined
Oct 2024
Message
97
#16

My perspective changed after experiencing that. The answer varies greatly by industry; there is no one-size-fits-all rule.

I'm also curious if anyone does it differently.

RRecepNew member
Job title
Plumber
Organization type
20-person company
Joined
Dec 2024
Message
22
#17

let me share my experience but btw if you scold false alarms, nobody will report again.

payment information changes are never verified through the channel they came from then if I were you, I'd go this route.

EElif Z***Expert
Job title
Production planning
Sector
Glass
Organization type
medium-sized business
Joined
Feb 2023
Message
164
#18

Saved.

NNazlıMember
Job title
Local marketing
Organization type
boutique agency
Joined
Aug 2024
Message
126
#19

If I understood correctly, you're saying: Mistakes made on the phishing attack side are usually reversible but expensive.

Good luck with that.

İİsmail K***New member
Job title
Grocery
Organization type
medium-sized business
Joined
Dec 2024
Message
22

Doki · Log management setup · 2025

#20

we need to make a distinction here. the biggest time-waster for us was not knowing who had the final say.

the biggest time-waster for us was not knowing who had the final say. this is my opinion I'm not claiming it's absolute truth.

Reply