Clicked a phishing link – what to do now
Clicked a suspicious link, or even typed something in? Do not panic. These calm steps limit the damage – and most of the time nothing has happened at all.
- Disconnect from the internet briefly if you downloaded a file (Wi-Fi off or airplane mode).
- Enter nothing else and close the phishing page.
- Change the password if you typed one – on that service first, then everywhere you use it too.
- Turn on two-factor authentication, so a stolen password alone is not enough.
First, size it up: how bad is it really?
Good news first: clicking a link is harmless in most cases. It only gets dangerous once you entered details on the fake page (password, card number, a verification code) or downloaded and opened a file.
Work through it calmly:
- Only clicked and closed the page right away? Probably nothing happened. Watch the account for a few days anyway.
- Entered details? Now speed matters – follow the plan below.
- Opened a file (“invoice”, “photo”, attachment)? Treat the device as possibly infected and check it.
These three questions take you straight to the right steps:
1Did you enter anything on the fake page (password, card number, a code)?
- Change that password right away - and everywhere else you used it
- Turn on two-factor authentication
- If bank or card details were involved: call the number on the back of your card
- Close the tab - in most cases nothing happened
- Keep an eye on the account for a few days
2Did you open a file from the message (attachment, "invoice", "photo")?
- Treat the device as possibly infected, disconnect from the internet briefly
- Run a scan with the built-in protection (Microsoft Defender, XProtect)
- Update the operating system and your apps
- Usually nothing further is needed on the device
3Have you already sent money or approved a payment?
- Call your bank immediately and ask them to stop or recall the payment
- Report it at IdentityTheft.gov and file a police report
- Save screenshots and receipts as evidence
- Good. Watch your account and inbox for a few days anyway
Step by step
What to do now
- Change the password on the affected account – ideally from a different, clean device.
- Used the same password elsewhere? Change it everywhere you reused it.
- Turn on 2FA for email, banking and anything that matters.
- Sign out of active sessions (most services offer “sign out on all devices”).
- Check the account for traces: a changed email address or phone number, new forwarding rules, logins you do not recognize.
- If bank details were involved: call your bank and watch the account – see Online banking fraud .
What not to do
- Do not fill in more fields on the page “to see what happens.”
- Do not reply to follow-up messages from the scammers, by email, text or phone. They are trying to get more out of you.
- Do not install attachments or “security updates” from the same message.
- Do not keep the old password just because “nothing has happened yet.”
Who to contact
- Your bank, if account, card or code details were involved – use the number on the back of your card, never one from the suspicious message.
- The real service (PayPal, Amazon, your email provider) through its official website, to secure the account.
- The FTC at IdentityTheft.gov if you handed over personal information.
- Your local police, and IC3.gov, if you lost money.
Preserve the evidence
Before you delete the message, take screenshots: the email or text with the sender, the fake web address, and anything you typed in. That helps with your bank, with a report and with the platform. You can also forward phishing emails to the Anti-Phishing Working Group at [email protected] , and forward scam texts to 7726 (SPAM) free of charge.
Protecting yourself from now on
One click is not a disaster – a pattern of them is. How to become resistant:
- Use a password manager : it only fills in logins on the real site, which exposes fakes automatically.
- Turn on two-factor authentication everywhere.
- Learn to spot phishing – the warning signs at a glance.
- Check a link before you click – ten seconds that prevent most of this.
Frequently asked questions
I only opened the link but did not type anything. Am I in danger?
Usually not. Simply loading a phishing page is generally not enough to take over your account. It gets dangerous if you entered details or downloaded and opened a file. To be safe, make sure your device is up to date and keep an eye on the account.
I typed my password into the fake page. What now?
Change that password immediately – on the affected service, and everywhere else you used the same one. Then turn on two-factor authentication. The faster you act, the smaller the damage.
Should I run a virus scan now?
If you only clicked and downloaded nothing, an up-to-date operating system is usually enough. If you opened a file, run a scan with the built-in protection (Microsoft Defender on Windows) and install any pending updates.