An employee typed their password into a fake sign-in page. Here are the five things to do next — and the one habit that decides how bad it gets.
Your office manager forwards you an email at 3:40 on a Tuesday. Subject line: "Sorry — I think I did something dumb." She got a message that looked like it came from your accounting software, typed her password into the sign-in page, and something about the next screen felt off.
Most of the advice out there is about stopping her from clicking. That advice already failed. The question now is what happens in the next ten minutes — and the honest answer is that the biggest variable isn't technical. It's how long she sat there deciding whether to tell you.
You are probably not too late
There's a useful finding in Verizon's 2026 Data Breach Investigations Report: in half of ransomware cases, a credential or infostealer event happened within the 95 days before the attack. Stolen passwords usually get traded, tested, and sat on. The break-in and the damage are often months apart.
That cuts two ways. It means somebody clicking at 3:40 doesn't mean you're being encrypted at 3:41. It also means if someone clicked last Thursday and only mentioned it today, acting now is still very much worth doing. Do not let embarrassment about the delay turn into a decision to skip it.
The five things to do
Microsoft publishes its own runbook for exactly this — responding to a compromised cloud email account. Stripped of the PowerShell, it comes down to five moves. Whoever holds your admin login can do all of them; so can your outside IT provider.
1. Reset the password — and don't email the new one. Microsoft's guidance says this explicitly, because if the account really is compromised, the attacker is reading that mailbox. Say it out loud or text it.
2. Sign the account out everywhere. This is the step people skip, and it's the one that matters most. A password reset does not automatically kill sessions that are already open. Modern phishing pages steal the session cookie along with the password, and that cookie keeps working after the password changes. In Microsoft's terms, it's "revoke sessions."
3. Look at the sign-in methods on the account. Attackers who get in add their own phone number or authenticator as a second factor, so they can walk back in later through the front door, legitimately, after you've reset everything.
4. Check the mailbox rules — including hidden ones. The classic move is a rule that forwards anything containing "invoice" or "wire" to an outside address, or quietly files replies into RSS Subscriptions where nobody looks. Microsoft's list of compromise symptoms leads with exactly this.
5. Check which apps the account has approved. A connected app holds its own key. Changing the password doesn't take it away.
Then assume she wasn't the only one. The same message almost certainly went to three other people in your company, and one of them may not have said anything.
The part that actually decides how bad it gets
Every step above is faster than the delay in front of it. And that delay is set by one thing: whether the person who clicked expects to be punished for saying so.
If your team has ever watched someone get chewed out over a security mistake, you have accidentally bought yourself an hour of attacker head start on every future incident. CISA's small-business phishing guidance puts it plainly among the basics — be sure employees know how and to whom to report suspicious emails. Knowing who to tell is only half of it. The other half is knowing it's safe.
The 2026 DBIR found the human element present in 62% of breaches. People are going to click. What separates a ten-minute annoyance from a three-week mess is almost always the speed of the confession.
Three things you can do this week
- Say the sentence. At your next team meeting, out loud: "If you ever click something you shouldn't have, tell me immediately. Nobody has ever gotten in trouble here for reporting it." Takes twenty seconds and it is the highest-value item on this list.
- Write the five steps on one page. Put it where whoever handles your admin account can find it at 3:41 on a Tuesday. Ten minutes of work turns a scramble into a checklist.
- Ask your IT provider one question. By name: "If someone added a forwarding rule to a mailbox tomorrow, would we find out?" Their answer tells you a lot.
One last thing worth knowing: how much damage one stolen password can do depends entirely on what that account was allowed to reach. If you've never had a straight answer on that, Tenant Strike runs a read-only scan of your Microsoft 365 setup and grades it A–F — nothing to install, and it can see settings but never change them.
AI-researched from public sources, human-reviewed on September 1, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.