What To Do When a Student Clicks a Phishing Link
NZ school and parent response when a student clicks a phishing link: first 5 minutes, Privacy Act 2020, CERT NZ and Netsafe reporting, parent letter.
Quick answer
If a student has clicked a phishing link — with or without entering details — act in this order: stop the immediate access, contain the account exposure, alert the school, report the message, and monitor for follow-up activity. Use the step-by-step guide below. A parent-letter template the school can adapt and send home is at the end of this page.
First 5 minutes: stop the bleeding
If the student entered a password, recovery code, or other credentials:
-
Change the password from a clean device — a different phone, tablet, or computer that was not used to click the link. If the attacker is still logged in, changing the password will boot them out.
-
Sign out of all other active sessions — most email and cloud services (Google Workspace, Microsoft 365) let you view and revoke active sessions. Do this immediately after the password change.
-
Check account activity for anything unusual — new logins from unknown locations or devices, changed recovery phone numbers or email addresses, sent messages you did not write.
-
If the same password is used elsewhere, change those accounts too — this is the fastest way to contain a credential-stuffing attack where the attacker tries the same password on multiple services.
If the student only clicked the link but did not enter any information: the risk is lower, but you should still monitor the account for 48 hours and treat any unexpected emails or messages as suspicious.
Also check the school's public website while you are responding. Phishing pages often impersonate school portals. Run the school's website through nzscan — a free NZ-built tool that checks TLS, security headers, exposed files, cookie flags, and mixed content in seconds. No signup, no data sent to third parties. If the scan shows missing headers or exposed files, the school IT team can fix them before attackers notice.
First 24 hours: contain the damage
Once the immediate access is revoked:
-
Alert the school’s IT team or the person responsible for digital safety — they need to know in case the incident affects school systems or other students. The school may also have obligations under its own cyber safety policy.
-
If personal information was entered — full name, date of birth, address, health information, or anything that could identify the student — the school may have obligations under the Privacy Act 2020 to assess whether a notifiable privacy breach has occurred. Refer to the Privacy in Education resource for what this means in practice.
-
Report the phishing message to CERT NZ — even if no harm was done, your report helps CERT NZ warn other schools and individuals. Report at cert.govt.nz/report [1].
-
Report to Netsafe — if the message was received in New Zealand and involved harassment, impersonation, or fraud, Netsafe can provide guidance and escalate if needed. Report at netsafe.org.nz [2].
-
Do not delete the message — keep a screenshot of the phishing message before deleting it. This helps the reporting process and may be needed if the incident escalates.
School reporting obligations under the Privacy Act 2020
If a phishing incident results in access to or exposure of student personal information, the school may have a notifiable privacy breach obligation to the Office of the Privacy Commissioner (OPC).
A notifiable privacy breach occurs when:
-
There is a loss of personal information, or access to it by an unauthorised person
-
The breach is caused by a failure of the agency’s security or procedures
-
The breach is likely to cause serious harm to any affected individual
Examples of what this means in a school phishing context:
-
A student enters their full name, date of birth, and home address into a fake form
-
A teacher enters their school email password into a phishing page, and the attacker accesses the school’s Google Workspace or Microsoft 365 tenant
-
Student academic records or health information stored in a cloud system linked to the compromised account are accessed
If any of these apply, the school should use the OPC’s privacy tools for agencies to assess the breach and determine whether notification is required.
The Privacy in Education resource covers the full framework for what schools should check and who to contact.
Talking to the student without creating shame
The most important thing to say to a student after a phishing click is that this is normal and expected — phishing messages are designed by professional scammers to catch people at exactly the right moment of distraction. The student did not do anything foolish; the scammer designed the message to be convincing.
The goal of the conversation is:
-
To make sure the student knows what to look for next time (see Phishing Anatomy: NZ Examples & Red Flags)
-
To encourage the student to tell a trusted adult immediately if something similar happens again, without fear of getting into trouble
-
To reduce the shame barrier that causes students to not report incidents until the damage is much worse
Signs the student may not have told you everything: unusual emails or messages appearing in their account, new contacts they do not recognise, settings changes on their phone or accounts.
Reporting the phishing message
CERT NZ
Report phishing and cyber security incidents at cert.govt.nz/report. CERT NZ triages incidents by severity and can:
-
Help contain an active attack
-
Advise on next steps for businesses and organisations
-
Pass actionable intelligence to downstream law enforcement
Reports are confidential and do not result in any public disclosure without your consent.
Netsafe
Report online harm including scams, impersonation, and fraud at netsafe.org.nz. Netsafe handles:
-
Online scams and fraud
-
Harmful or illegal content
-
Privacy breaches involving individual harm
The school’s own IT provider
If the incident affected school systems, student data, or school-managed accounts, the school’s IT provider should be notified directly. They can:
-
Check logs for any wider compromise
-
Reset affected accounts
-
Put additional monitoring in place
Parent-letter template
The following template can be adapted by the school and sent home to parents or caregivers after a phishing incident. It is intentionally calm and non-alarmist, focused on what parents can do to help.
[School Name] — Digital Safety Notice
Dear Parents and Caregivers,
We are writing to let you know about a digital safety incident that may have affected some of our students.
What happened
A student at our school recently received a phishing message — a type of online scam that tries to trick people into clicking a link or sharing personal information. In this case, the student clicked the link. We are not aware of any resulting harm, but we are informing all families as a precaution.
What we have done
Our school has:
-
Notified the relevant IT and leadership team
-
Reported the incident to CERT NZ and Netsafe
-
Taken steps to secure any potentially affected accounts
-
Reviewed our digital safety practices with the students involved
What you can do at home
Please take a moment to:
-
Ask your child if they have received any unusual messages, texts, or emails recently — particularly ones asking them to click a link or enter a password
-
If your child uses the same password for multiple accounts, consider updating them to be unique for each account
-
If your child uses a password manager, this is a good time to make sure it is set up and being used
If you are concerned
If you believe your child’s personal information may have been accessed, please contact the school office so we can assess next steps together. You can also:
-
Report directly to CERT NZ at cert.govt.nz/report
-
Contact Netsafe at netsafe.org.nz or 0508 638 723
We take the digital safety of our students very seriously. This incident is a useful reminder for all of us to stay vigilant online.
Thank you for your support.
[School Name] [Contact Name and Details]
Knowledge check
Sources and references
[1] CERT NZ. (2025). Top 11 cyber security tips. https://www.cert.govt.nz/individuals/guides/top-11-cyber-security-tips/
[2] Netsafe New Zealand. (2025). Phishing. https://netsafe.org.nz/scams/phishing
[3] New Zealand. Office of the Privacy Commissioner. (2025). Privacy tools for agencies. https://www.privacy.org.nz/responsibilities/privacy-tools-for-agencies/
[4] Google. (2025). Avoid and report phishing emails. https://support.google.com/mail/answer/8253
What to do next
-
See real NZ phishing patterns: Phishing Anatomy — NZ-Specific Examples.
-
Learn to recognise phishing before it is clicked: How to Spot Phishing Emails, Scams, and Fake Messages.
-
Understand social engineering tactics: Social Engineering: What NZ Students Need to Know.
-
School privacy obligations: Privacy in Education: What Teachers and Students Should Check and Privacy Act 2020 Guide for NZ Schools.
-
Build account-level protection: Passwords, Passphrases, and MFA: A Simple Guide.
-
See the full phishing cluster: Phishing Hub for NZ Schools.