Nope, don't need to worry actually. The system logs what triggered it and what it picked up that said it was phishing; we had a similar issue with a different user a few days ago with a web file uploader too.
For curiosity, was yours named Webmin or Web Admin, with a copyright header saying...