How to Recognise Phishing Attacks and What to Do After Clicking a Phishing Link

What Phishing Actually Looks Like

How to Recognise Phishing Attacks and What to Do After Clicking a Phishing Link

What is Phishing?

Phishing is a scam where an attacker impersonates a trusted organisation or person — by email, text, or phone — to trick you into handing over credentials, payment details, or system access. If you’ve clicked a suspicious link, disconnect the device from the network immediately, avoid entering further information, and change your passwords from a separate, clean device before running a full malware scan.

What Phishing Actually Looks Like

Phishing remains the number one way attackers break into businesses and personal accounts — not because it’s technically sophisticated, but because it targets people, not firewalls. It arrives by email (phishing), text message (smishing), or phone call (vishing), and attackers have gotten increasingly good at mimicking real communications from banks, IT departments, and well-known brands.

According to CERT NZ, phishing consistently makes up the largest single category of cybersecurity incidents reported by New Zealanders each quarter, and it’s usually the first step before a more damaging attack, such as fraud or account takeover.

The Red Flags to Watch For

  • Urgency and fear. “Your account will be suspended in 24 hours” or “Unusual sign-in detected — verify now.” Scammers want you acting fast, before you think it through.
  • A mismatched sender address. The display name might say “Microsoft Support,” but the actual email address is something like support@micros0ft-security.net. Always check the real address, not just the name shown.
  • Links that don’t match their label. Hover over a link (don’t click) and look at the actual destination URL. A link labelled “paypal.com” that actually points to “paypal-secure-login.ru” is a giveaway.
  • Generic greetings. “Dear Customer” instead of your name, from a company that would normally address you personally.
  • Requests that bypass normal process. An invoice payment that skips your usual approval chain, or an “IT” request for your actual password (legitimate IT never needs it).
  • Improving — not disappearing — spelling errors. Poor grammar used to be a reliable tell. AI-written phishing emails are now often flawless, so don’t rely on this alone.
  • Unexpected attachments, especially .zip, .exe, or macro-enabled Office files you weren’t expecting.

Real Examples Worth Knowing

Business Email Compromise

The US$120 million invoice scam — Google and Facebook, 2013–2015. Lithuanian national Evaldas Rimasauskas set up a fake company using the name of Quanta Computer, a real hardware supplier both tech giants worked with. He sent forged invoices and contracts by email to employees at Google and Facebook, instructing them to wire payments to bank accounts he controlled — netting roughly $23 million from Google and $98 million from Facebook over two years. No malware was involved at all, just convincing paperwork and a sender who looked legitimate (U.S. Department of Justice). It’s a reminder that phishing doesn’t always involve a “click here” link — sometimes it’s a business email compromise built to exploit a routine process like invoice payment.

Credential Harvesting

The 2016 US campaign email breach. A senior staffer received an email that appeared to be a Google security alert, warning that someone in Ukraine had tried to access his account and urging an immediate password change via a provided link. The link led to a convincing fake Google login page. He entered his credentials, and attackers gained access to years of email correspondence, later leaked publicly. The email looked routine enough that it was initially treated as legitimate.

Vishing (Voice Phishing)

Twitter’s 2020 internal breach. Attackers didn’t email employees — they phoned them, posing as IT support and using social engineering to convince staff to hand over credentials to internal administrative tools. With that access, they took over high-profile verified accounts to promote a cryptocurrency scam. A good reminder that phishing isn’t limited to email — voice calls and texts are increasingly common vectors.

Locally Relevant: New Zealand

The fake Inland Revenue tax refund campaign (2021). CERT NZ identified an active phishing campaign impersonating Inland Revenue, sending emails with links to a site that closely mimicked the real IR website and asked victims to “claim their tax refund” by entering personal and financial details (CERT NZ). More recently, in 2023, fake toll-payment text messages impersonating NZ Post and Waka Kotahi circulated widely around public holidays, directing recipients to convincing fake payment pages. Attackers deliberately time these campaigns around public holidays, when people are less likely to double-check before clicking.

The pattern across every case: the request looks plausible, arrives through a channel you trust, and pushes you to act quickly without checking through a second channel.

What to Do Immediately After Clicking a Phishing Link

If you’ve clicked a link and realise something’s off, don’t panic — but move quickly. What you do in the next hour matters more than what happened in the click itself.

  1. Disconnect from the network. Turn off Wi-Fi or unplug the ethernet cable on the affected device. This limits any malware’s ability to communicate out or spread across a network, buying you time before further damage occurs.
  2. Don’t enter any more information. If the link led to a fake login page and you haven’t typed anything yet, close the tab. If you already entered a password or payment details, assume that data is compromised — the priority now shifts to containment.
  3. Change your passwords — from a different, clean device. Start with the account that was impersonated, then any account using the same or a similar password. Use a device you’re confident wasn’t affected; typing a new password on a compromised machine can hand it straight back to the attacker via keylogging malware.
  4. Turn on multi-factor authentication (MFA). If it isn’t already on, enable it now. If it’s already active, check for any unfamiliar approval requests or newly registered devices.
  5. Run a full antivirus/anti-malware scan. Use a reputable tool and run a thorough scan, not a quick one. If you’re not confident doing this yourself, this is exactly the kind of thing worth getting a professional to check — some phishing links silently install malware that a quick glance won’t reveal.
  6. Check financial accounts and set up alerts. If any banking or payment details were entered, contact your bank immediately. Ask about freezing cards, monitoring for fraudulent transactions, and setting up transaction alerts.
  7. Report it. Forward the phishing email to your IT team or managed service provider. In New Zealand, report it to CERT NZ and Netsafe. If money was lost, report it to your bank and to NZ Police via 105.
  8. If it happened at work, assume it might not be isolated. One clicked link can be the entry point for a much larger breach. Treat any confirmed click as an incident: check logs for unusual account activity, review what systems that account had access to, and check whether other staff received the same email.

Don’t wait to report it out of embarrassment. Early reporting — even five minutes sooner — is consistently what limits how far a breach spreads across a business. IT teams would always rather hear about it immediately than find out weeks later.

If you entered… Priority action
A work login password Change it from a clean device, notify IT immediately, check MFA logs
Personal banking details Call your bank now, freeze the card, monitor for transactions
Nothing — just clicked the link Disconnect from network, run a full malware scan before reconnecting
An email/password reused elsewhere Change it everywhere it’s reused, prioritising email and banking first

Not sure if a device has been compromised?

If you’ve clicked something suspicious and want a second opinion, or you’d like help setting up email filtering, MFA, or staff phishing-awareness training across your business, Advanced Computers can help — from a one-off device check to ongoing managed security.

Get in touch with our team →

Frequently Asked Questions

What is phishing? Phishing is a scam where an attacker pretends to be a trustworthy organisation or person — such as a bank, IT department, or supplier — by email, text message, or phone call, in order to trick you into revealing passwords, payment details, or granting system access.

What should I do immediately after clicking a phishing link? Disconnect the device from Wi-Fi or the network, avoid entering any further information, change your passwords from a separate clean device, enable multi-factor authentication, run a full malware scan, check financial accounts for unusual activity, and report the incident to your IT team, your bank, and CERT NZ or Netsafe.

How can I tell if an email is a phishing attempt? Look for urgent or threatening language, a sender address that doesn’t match the organisation it claims to be from, links whose destination doesn’t match the text shown, generic greetings, unexpected attachments, and requests that bypass your normal approval process, such as an unusual invoice or password request.

Is clicking a phishing link always dangerous? Not always, but it can be. Some phishing links only lead to a fake login page, which is only harmful if you enter your details. Others can silently install malware just by loading the page. Because you can’t always tell which type it is, it’s safest to disconnect the device and check it thoroughly.

Where can I report a phishing scam in New Zealand? Report phishing and scams to CERT NZ (cert.govt.nz) and Netsafe (netsafe.org.nz). If money has been lost, contact your bank immediately and report it to NZ Police via 105.

About Advanced Computers

Advanced Computers provides IT support, managed security, and staff cybersecurity training for New Zealand businesses, including phishing simulation, email filtering, and incident response for teams that have already clicked something they shouldn’t have.

Sources & further reading:

Posted in blog.