
Phishing email to my co-workers
I had a phishing email come into my office and wonder how i should attack this one? Whenever the link is clicked, it seems to go through their sent emails and send 500+ emails with the screenshot attached. Everyone has MFA enabled, and all have secure passwords. Should i tell staff to change passwords even though they haven't been alerted of a sign in attempt? I can't tell what the endgame of these emails are since it can't tell was was collected with the click.
Can anyone tell me exactly what is located in the URL? and how it works?
Any tips that i can take besides more cyber training for them? Thanks!