If you clicked a phishing link, stop what you are doing and act quickly. The next few minutes matter — disconnect, avoid entering any details, change your passwords, and report the incident.
Turn off Wi-Fi and unplug the network cable if you have one. This stops any downloaded malware from talking back to the attacker while you clean up.
If the fake page is still open, close the tab or browser immediately. Don't type a password, tax number, credit card, or anything else — even if the page looks convincing.
From a different, trusted device, change the password for any account the fake page targeted. Start with email, then banking, then anything else that reuses the same password. Turn on multi-factor authentication if it isn't already.
Run a full antivirus / anti-malware scan. On Windows, Microsoft Defender is enough for most home users. On Mac, macOS handles most cases but a scan with a reputable tool doesn't hurt.
Look at your inbox for sent items you didn't send, mailbox rules you didn't create, and unexpected password-reset emails. Check your bank statements for the next fortnight.
If this happened on a work device, tell your IT team or manager straight away. Owning up quickly gives them a chance to contain the damage. On a personal device, tell anyone who might share credentials with you.
Report the scam to NCSC NZ at report.ncsc.govt.nz. If you gave away banking details, call your bank on the number on the back of your card, not one from the email.
Some phishing links just harvest your click and then load malware silently. Even if the page looked broken or blank, still change your passwords and scan your device.
If you think you've been targeted or you're not sure what to do next, the Decision1 team can walk you through it. No cost for a first conversation.