A student at a laptop looking at a suspicious message with a calm adult beside them — student clicks phishing link

Quick answer

If a student has clicked a phishing link — with or without entering details — act in this order: stop the immediate access, contain the account exposure, alert the school, report the message, and monitor for follow-up activity. Use the step-by-step guide below. A parent-letter template the school can adapt and send home is at the end of this page.

First 5 minutes: stop the bleeding

If the student entered a password, recovery code, or other credentials:

  • Change the password from a clean device — a different phone, tablet, or computer that was not used to click the link. If the attacker is still logged in, changing the password will boot them out.

  • Sign out of all other active sessions — most email and cloud services (Google Workspace, Microsoft 365) let you view and revoke active sessions. Do this immediately after the password change.

  • Check account activity for anything unusual — new logins from unknown locations or devices, changed recovery phone numbers or email addresses, sent messages you did not write.

  • If the same password is used elsewhere, change those accounts too — this is the fastest way to contain a credential-stuffing attack where the attacker tries the same password on multiple services.

If the student only clicked the link but did not enter any information: the risk is lower, but you should still monitor the account for 48 hours and treat any unexpected emails or messages as suspicious.

Also check the school's public website while you are responding. Phishing pages often impersonate school portals. Run the school's website through nzscan — a free NZ-built tool that checks TLS, security headers, exposed files, cookie flags, and mixed content in seconds. No signup, no data sent to third parties. If the scan shows missing headers or exposed files, the school IT team can fix them before attackers notice.

First 24 hours: contain the damage

Once the immediate access is revoked:

  • Alert the school’s IT team or the person responsible for digital safety — they need to know in case the incident affects school systems or other students. The school may also have obligations under its own cyber safety policy.

  • If personal information was entered — full name, date of birth, address, health information, or anything that could identify the student — the school may have obligations under the Privacy Act 2020 to assess whether a notifiable privacy breach has occurred. Refer to the Privacy in Education resource for what this means in practice.

  • Report the phishing message to CERT NZ — even if no harm was done, your report helps CERT NZ warn other schools and individuals. Report at cert.govt.nz/report [1].

  • Report to Netsafe — if the message was received in New Zealand and involved harassment, impersonation, or fraud, Netsafe can provide guidance and escalate if needed. Report at netsafe.org.nz [2].

  • Do not delete the message — keep a screenshot of the phishing message before deleting it. This helps the reporting process and may be needed if the incident escalates.

School reporting obligations under the Privacy Act 2020

If a phishing incident results in access to or exposure of student personal information, the school may have a notifiable privacy breach obligation to the Office of the Privacy Commissioner (OPC).

A notifiable privacy breach occurs when:

  • There is a loss of personal information, or access to it by an unauthorised person

  • The breach is caused by a failure of the agency’s security or procedures

  • The breach is likely to cause serious harm to any affected individual

Examples of what this means in a school phishing context:

  • A student enters their full name, date of birth, and home address into a fake form

  • A teacher enters their school email password into a phishing page, and the attacker accesses the school’s Google Workspace or Microsoft 365 tenant

  • Student academic records or health information stored in a cloud system linked to the compromised account are accessed

If any of these apply, the school should use the OPC’s privacy tools for agencies to assess the breach and determine whether notification is required.

The Privacy in Education resource covers the full framework for what schools should check and who to contact.

Talking to the student without creating shame

The most important thing to say to a student after a phishing click is that this is normal and expected — phishing messages are designed by professional scammers to catch people at exactly the right moment of distraction. The student did not do anything foolish; the scammer designed the message to be convincing.

The goal of the conversation is:

  • To make sure the student knows what to look for next time (see Phishing Anatomy: NZ Examples & Red Flags)

  • To encourage the student to tell a trusted adult immediately if something similar happens again, without fear of getting into trouble

  • To reduce the shame barrier that causes students to not report incidents until the damage is much worse

Signs the student may not have told you everything: unusual emails or messages appearing in their account, new contacts they do not recognise, settings changes on their phone or accounts.

Reporting the phishing message

CERT NZ

Report phishing and cyber security incidents at cert.govt.nz/report. CERT NZ triages incidents by severity and can:

  • Help contain an active attack

  • Advise on next steps for businesses and organisations

  • Pass actionable intelligence to downstream law enforcement

Reports are confidential and do not result in any public disclosure without your consent.

Netsafe

Report online harm including scams, impersonation, and fraud at netsafe.org.nz. Netsafe handles:

  • Online scams and fraud

  • Harmful or illegal content

  • Privacy breaches involving individual harm

The school’s own IT provider

If the incident affected school systems, student data, or school-managed accounts, the school’s IT provider should be notified directly. They can:

  • Check logs for any wider compromise

  • Reset affected accounts

  • Put additional monitoring in place

What to do when a student clicks a phishing link — NZ parent and teacher guide

Parent-letter template

The following template can be adapted by the school and sent home to parents or caregivers after a phishing incident. It is intentionally calm and non-alarmist, focused on what parents can do to help.

[School Name] — Digital Safety Notice

Dear Parents and Caregivers,

We are writing to let you know about a digital safety incident that may have affected some of our students.

What happened

A student at our school recently received a phishing message — a type of online scam that tries to trick people into clicking a link or sharing personal information. In this case, the student clicked the link. We are not aware of any resulting harm, but we are informing all families as a precaution.

What we have done

Our school has:

  • Notified the relevant IT and leadership team

  • Reported the incident to CERT NZ and Netsafe

  • Taken steps to secure any potentially affected accounts

  • Reviewed our digital safety practices with the students involved

What you can do at home

Please take a moment to:

  • Ask your child if they have received any unusual messages, texts, or emails recently — particularly ones asking them to click a link or enter a password

  • If your child uses the same password for multiple accounts, consider updating them to be unique for each account

  • If your child uses a password manager, this is a good time to make sure it is set up and being used

If you are concerned

If you believe your child’s personal information may have been accessed, please contact the school office so we can assess next steps together. You can also:

  • Report directly to CERT NZ at cert.govt.nz/report

  • Contact Netsafe at netsafe.org.nz or 0508 638 723

We take the digital safety of our students very seriously. This incident is a useful reminder for all of us to stay vigilant online.

Thank you for your support.

[School Name] [Contact Name and Details]

Knowledge check

Q1Your child clicked a phishing link but did not enter any information. What is the main thing to do in the next 48 hours?tap to flip
Answer: Answer: Monitor the account for unusual activity. Clicking a link without entering information is low-risk, but attackers sometimes use the click to confirm the email address is active. Treat any unexpected emails or messages as suspicious for 48 hours [1][2].
Q2A student entered their school email password into a phishing page. Why does the school need to assess this under the Privacy Act 2020?tap to flip
Answer: Answer: Because the school's Google Workspace or Microsoft 365 tenant may have been accessed, potentially exposing student records, emails, or other personal information stored in the school system. If personal information was accessed or is at risk, the school may have a notifiable privacy breach obligation to the Office of the Privacy Commissioner [3].
Q3A student receives a phishing message on their phone and forwards it to a parent. What should the parent do with the message?tap to flip
Answer: Answer: Screenshot or preserve the message without clicking any links, then report it to CERT NZ at cert.govt.nz/report and to Netsafe at netsafe.org.nz. Forwarding the message to a trusted adult is exactly the right first step — the student did the right thing by not clicking [1][2].

Sources and references

[1] CERT NZ. (2025). Top 11 cyber security tips. https://www.cert.govt.nz/individuals/guides/top-11-cyber-security-tips/

[2] Netsafe New Zealand. (2025). Phishing. https://netsafe.org.nz/scams/phishing

[3] New Zealand. Office of the Privacy Commissioner. (2025). Privacy tools for agencies. https://www.privacy.org.nz/responsibilities/privacy-tools-for-agencies/

[4] Google. (2025). Avoid and report phishing emails. https://support.google.com/mail/answer/8253

What to do next