Clicked a phishing link – what to do now

Clicked a suspicious link, or even typed something in? Do not panic. These calm steps limit the damage – and most of the time nothing has happened at all.

Five minutes: do this right now
  1. Disconnect from the internet briefly if you downloaded a file (Wi-Fi off or airplane mode).
  2. Enter nothing else and close the phishing page.
  3. Change the password if you typed one – on that service first, then everywhere you use it too.
  4. Turn on two-factor authentication, so a stolen password alone is not enough.

First, size it up: how bad is it really?

Good news first: clicking a link is harmless in most cases. It only gets dangerous once you entered details on the fake page (password, card number, a verification code) or downloaded and opened a file.

Work through it calmly:

  • Only clicked and closed the page right away? Probably nothing happened. Watch the account for a few days anyway.
  • Entered details? Now speed matters – follow the plan below.
  • Opened a file (“invoice”, “photo”, attachment)? Treat the device as possibly infected and check it.

These three questions take you straight to the right steps:

1Did you enter anything on the fake page (password, card number, a code)?

Yes
  • Change that password right away - and everywhere else you used it
  • Turn on two-factor authentication
  • If bank or card details were involved: call the number on the back of your card
No
  • Close the tab - in most cases nothing happened
  • Keep an eye on the account for a few days

2Did you open a file from the message (attachment, "invoice", "photo")?

Yes
  • Treat the device as possibly infected, disconnect from the internet briefly
  • Run a scan with the built-in protection (Microsoft Defender, XProtect)
  • Update the operating system and your apps
No
  • Usually nothing further is needed on the device

3Have you already sent money or approved a payment?

Yes
  • Call your bank immediately and ask them to stop or recall the payment
  • Report it at IdentityTheft.gov and file a police report
  • Save screenshots and receipts as evidence
No
  • Good. Watch your account and inbox for a few days anyway

Step by step

What to do now

  • Change the password on the affected account – ideally from a different, clean device.
  • Used the same password elsewhere? Change it everywhere you reused it.
  • Turn on 2FA for email, banking and anything that matters.
  • Sign out of active sessions (most services offer “sign out on all devices”).
  • Check the account for traces: a changed email address or phone number, new forwarding rules, logins you do not recognize.
  • If bank details were involved: call your bank and watch the account – see Online banking fraud .

What not to do

  • Do not fill in more fields on the page “to see what happens.”
  • Do not reply to follow-up messages from the scammers, by email, text or phone. They are trying to get more out of you.
  • Do not install attachments or “security updates” from the same message.
  • Do not keep the old password just because “nothing has happened yet.”

Who to contact

  • Your bank, if account, card or code details were involved – use the number on the back of your card, never one from the suspicious message.
  • The real service (PayPal, Amazon, your email provider) through its official website, to secure the account.
  • The FTC at IdentityTheft.gov if you handed over personal information.
  • Your local police, and IC3.gov, if you lost money.

Preserve the evidence

Before you delete the message, take screenshots: the email or text with the sender, the fake web address, and anything you typed in. That helps with your bank, with a report and with the platform. You can also forward phishing emails to the Anti-Phishing Working Group at [email protected] , and forward scam texts to 7726 (SPAM) free of charge.

Protecting yourself from now on

One click is not a disaster – a pattern of them is. How to become resistant:

Rule of thumb Real banks, real agencies and reputable companies never ask you, through a link in a message, to “confirm your account” or enter your credentials. When in doubt: close the tab and open the site yourself through the address bar or the app.

Frequently asked questions

I only opened the link but did not type anything. Am I in danger?

Usually not. Simply loading a phishing page is generally not enough to take over your account. It gets dangerous if you entered details or downloaded and opened a file. To be safe, make sure your device is up to date and keep an eye on the account.

I typed my password into the fake page. What now?

Change that password immediately – on the affected service, and everywhere else you used the same one. Then turn on two-factor authentication. The faster you act, the smaller the damage.

Should I run a virus scan now?

If you only clicked and downloaded nothing, an up-to-date operating system is usually enough. If you opened a file, run a scan with the built-in protection (Microsoft Defender on Windows) and install any pending updates.

Topics: Scams, Emergency