Field Scenario
A support technician discovers a customer clicked a suspicious link and entered their credentials on what looked like a legitimate login page.
What You Actually Do
- Treat this as a genuine security incident requiring a structured response, not just a minor inconvenience
- Guide the customer to change the compromised password and any reused passwords promptly
- Investigate whether any further compromise occurred beyond the initial credential entry
- Document what happened and communicate clearly and honestly with the customer throughout
Disclosure: This post may contain affiliate links which means I may receive a commission for purchases made through links. I will only recommend products that I have personally used! Learn more on my Private Policy page.
