Incident Playbook
Phishing & Scams
Summary
A staff member received, clicked or acted on a deceptive message designed to steal credentials, money or access.
- Category
- Accounts and access
- Typical severity
- Medium to high
- Response led by
- Incident lead, with technical support
First 15 minutes
- Stop. Don't type anything else into the page or reply to the message.
- If you typed a password, change it immediately from a trusted device, and change it anywhere else you used it.
- Sign out of all other sessions and check that 2-step verification is on.
1. Overview
Phishing is any message designed to trick you into giving away a password, a verification code, money or personal information, or into opening something that infects your device. It arrives by email, text message, messaging apps, social media and phone calls. It's the most common way attackers get into organisations, because it targets people rather than technology.
2. How it happens
- The message creates urgency or fear: an account about to close, an overdue invoice, a grant deadline, a legal threat.
- It pretends to come from someone you trust: a funder, a bank, a partner, a colleague, your director or "IT support".
- It links to a fake login page that looks like your email, cloud storage or bank, and records whatever you type.
- It carries an attachment, such as an invoice, invitation or report, that installs malware when opened or when you click "Enable content".
- Targeted versions (spear phishing) use real names, projects and events, often gathered from your website and social media.
- Phone and text scams ask you to read out a code, send money "sent by mistake", or pay a fee for a prize, job or conference.
3. Indicators
Signs that this incident may be happening:
- The sender's address or number is slightly different from the real one, or comes from a personal account.
- You're asked for a password, a code, a PIN or payment details. Legitimate services don't ask for these.
- Unusual pressure: "urgent", "confidential", "don't tell anyone", "today only".
- A link's real address (seen by hovering or long-pressing) doesn't match the organisation it claims to be.
- An unexpected attachment, or a login page that appears after clicking a link in a message.
- Offers that are too good: grants, jobs or paid trips you never applied for.
4. Triage questions
Answer these first to understand scope and severity:
- Did anyone click a link, open an attachment, enter a password or code, or send money?
- Which accounts, devices or payments are involved?
- Did other staff receive the same or a similar message?
- Is the sender impersonating a real partner, funder or colleague?
- Is the message targeted, using real names, projects or events?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | Reported before anyone interacted with it. |
| Medium | A link was clicked, but no details were entered and nothing was opened. |
| High | A password was entered, a file was opened, or a code was shared. |
| Critical | Money was sent, sensitive data was accessed, or the attacker used the account to reach others. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- Stop. Don't type anything else into the page or reply to the message.
- If you typed a password, change it immediately from a trusted device, and change it anywhere else you used it.
- Sign out of all other sessions and check that 2-step verification is on.
- If you opened an attachment or enabled content, disconnect the device from the internet and get expert help before using it.
- If you sent money or payment details, contact your bank or payment provider straight away. Speed matters.
- Tell your incident lead, and warn colleagues who may receive the same message.
- Keep the message as evidence: don't delete it.
7. Communication
Who to inform, and when:
- Incident lead and technical support, immediately.
- All staff, with a screenshot of the message (link removed), so they can spot and report it.
- The impersonated partner or funder, through a known contact, so they can warn their own networks.
- Your bank or payment provider, if money or payment details were involved.
- Affected contacts, if the account was used to send further messages.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- The original message, kept in the mailbox (not deleted or forwarded as an attachment by the user).
- Full email headers, including sender address and sending servers.
- The link address and any attachment, handled only by someone qualified.
- Times of the click, password entry and any account changes.
- Account activity logs for the affected account.
9. Recovery and review
- Check the affected account for forwarding rules, new devices, connected apps and changed recovery details.
- Review account activity to see what the attacker may have read or sent.
- Warn partners if your account was used to send messages in your name.
- Report the message to your email provider or platform.
- Record the incident in your log, including how it got through and how it was noticed.
- Share the lesson with the team, without blaming the person who clicked.
10. Prevention checklist
- Turn on 2-step verification for email and key accounts, using an authenticator app or security key where possible.
- Use a password manager. It won't fill in your password on a fake site, which is a useful warning sign.
- Agree a rule: any change to bank details or any urgent payment is confirmed by phone, on a number you already have.
- Make reporting easy and blame-free, so people speak up straight away when they click something.
- Train regularly with real examples, and practise as a team, for example with Chips Down.
- Limit how much staff information, such as roles and email addresses, is public on your website.