What should I do if I clicked a phishing link?
Clicking a phishing link is common and usually recoverable. What you do in the next few minutes matters more than the click itself.
Short answer: close the page and don't enter anything else. Then assess what happened — whether you entered a password, downloaded a file, or just landed on a page. The right response depends on what you did after the click, and speed matters more than perfection.
First, breathe. Clicking a phishing link does not mean your identity is stolen or your bank account is drained. Millions of people click these links every year, and most of the time the outcome depends entirely on what happened next. A click by itself, with nothing entered and nothing downloaded, is usually harmless.
What matters is acting quickly and in the right order. Here's how to think about it.
Step one: stop and close it
The moment you realize the link might be bad, stop. Don't enter any more information — not your email, not a "verification code," nothing. Close the tab or window.
If a download started automatically, don't open the file. If a page is asking you to enable something, allow notifications, or install an extension, decline. The damage from phishing almost always comes from what you do on the page, not from arriving at the page.
This is the hardest step emotionally because the pages are designed to create urgency — warnings about locked accounts, expiring offers, security threats. That urgency is the weapon. Slowing down is the defense.
If you only clicked and did nothing else
This is the best-case scenario, and it's the most common one. You clicked, the page loaded, you realized something was wrong, and you left without entering anything or downloading anything.
In most cases, you're fine. Modern browsers are good at containing drive-by attacks, and simply visiting a page rarely compromises a device. Still, take a few sensible precautions: run a security scan with your antivirus or built-in security software, make sure your browser and operating system are up to date, and keep an eye on your accounts for anything unusual over the next few weeks.
If the page asked you to allow notifications and you clicked yes, go into your browser settings and revoke that permission. Malicious notification permissions are a common way these sites keep harassing you after you've left.
If you entered a password
This is where speed matters. Go to the real website — type the address yourself or use a bookmark, never use the link from the message — and change your password immediately.
Then think about whether you reuse that password anywhere else. If you do, change it everywhere. This is the moment password reuse becomes painful, and it's the reason security experts are so insistent about unique passwords. A password manager makes this far less agonizing.
Turn on two-factor authentication if it isn't already enabled. Check the account's recent activity or login history for anything you don't recognize. Review account recovery settings — email addresses, phone numbers, security questions — because attackers sometimes change these to lock you out later. And check for unfamiliar connected apps, forwarding rules, or authorized devices, which are quieter ways attackers maintain access.
If you downloaded or opened a file
Treat this more seriously. Disconnect the device from the internet if you suspect the file was malicious — this limits what any malware can send out or receive. Then run a full scan with reputable security software.
If the scan finds something, follow the software's instructions for removal. If you're unsure, or if the device is a work or school computer, contact your IT department — they'd much rather hear about it early than discover a breach later.
In serious cases, a full device reset may be the safest option. It's drastic, but it's the only way to be certain. Back up your important files first, then reset and restore. For most consumer phishing, this is overkill — but know that the option exists.
If you entered payment or financial information
Call your bank or card issuer right away, using the number on the back of your card or the official website — not any number from the suspicious message. Tell them what happened. They can watch for fraud, issue a new card number, and in some cases reverse unauthorized charges.
Check your statements carefully over the next month or two, not just for large charges but for small test charges. Attackers often run a tiny transaction first to verify the card works before attempting larger ones.
If you sent money directly — a wire transfer, a gift card code, a payment app transfer — contact the financial institution immediately and ask about recalling or reversing it. Time is critical here. The FBI notes that prompt reporting can sometimes help freeze funds, but recovery gets harder with every hour that passes.
If you shared identity documents or personal details
If you provided a Social Security number or equivalent national ID, or uploaded a photo of an ID document, visit IdentityTheft.gov (the FTC's identity theft resource) for a personalized recovery plan. In the US, you can also place a fraud alert or credit freeze with the major credit bureaus — a freeze is free and is the strongest protection against new accounts being opened in your name.
Monitor your credit reports. You're entitled to free reports, and staggering them across the year gives you ongoing visibility. Watch for accounts you didn't open, inquiries you didn't authorize, or addresses you don't recognize.
Report it
Reporting helps protect other people, and in some cases it's required. Forward phishing emails to reportphishing@apwg.org, the Anti-Phishing Working Group. Forward suspicious texts to 7726 (which spells SPAM). File a report with the FTC at ReportFraud.ftc.gov, and if money was involved, with the FBI's Internet Crime Complaint Center at IC3.gov.
It feels like shouting into the void, but these reports are how patterns get identified and how takedowns happen. The phishing site that got you is probably targeting thousands of others.
Protecting yourself going forward
The best time to set up defenses is right after a scare, while the motivation is fresh. Use a password manager and unique passwords everywhere. Turn on two-factor authentication on every important account, preferably with an authenticator app rather than SMS. Keep your devices and browsers updated — updates patch the vulnerabilities these attacks exploit.
Build a personal rule: if a message involves money, passwords, or personal data, verify through a separate channel before acting. Call the company at a number you look up yourself. Open the app directly. The thirty seconds this takes will prevent nearly every phishing attack.
If it was a work or school device
Tell your IT or security team immediately. This isn't optional, and it's not about getting in trouble — quick reporting is exactly what they're trained for, and early notice can prevent a minor incident from becoming a company-wide breach. Most organizations would far rather hear "I clicked something suspicious" within minutes than discover it weeks later.
Don't try to fix it yourself on a managed device. Don't hide it out of embarrassment. The people who cause real damage aren't the ones who click — they're the ones who click and say nothing.
Helping someone else who's been phished
There's a good chance the person who needs this advice isn't you — it's a parent, a grandparent, or a less tech-comfortable friend. Older adults are disproportionately targeted, and they often hide what happened out of embarrassment.
If someone tells you they clicked something suspicious, resist the urge to lecture. Shame makes people hide problems, and hidden problems get worse. Start with reassurance — this happens to millions of people — then walk through the steps together.
The most valuable thing you can do is sit with them while they change passwords and turn on two-factor authentication. These are simple tasks that feel overwhelming to someone who's rattled. Do it calmly, explain what you're doing, and use the moment to set up a password manager for them.
Consider setting up a family verification rule going forward: any unexpected message about money or accounts gets a phone call before any action. Make yourself the person they call. A thirty-second conversation — "Mom, did you get a weird text from the bank?" — prevents nearly every successful attack. Write the rule down and stick it on the fridge; the physical reminder matters more than you'd think.
The calm takeaway
Clicking a phishing link is a mistake, not a catastrophe. The attackers are professionals running industrial-scale operations against millions of targets. Getting caught by one doesn't make you careless — it makes you normal.
What separates a close call from a real problem is the next ten minutes. Stop, close the page, change the passwords that need changing, call the bank if money is involved, and report it. Then set up the defenses that make the next attempt fail. That's the whole playbook, and it works.
Latest posts
- Is it worth repairing an old car, or should I buy a new one?
- If I pay child support, do I have to pay for anything else?
- What credit score do I need to buy a house?
- How can I tell if a text message or email is a phishing scam?
- When is the best time to book international flights for the lowest price?
- EV vs hybrid vs gas: which car actually saves you the most money?
- How should my partner and I split expenses if one of us earns more?
- Should I buy a house with less than 20% down?
- What are closing costs, and how much are they?
- What percentage of my income should go to a mortgage?
- Is paying for a VPN worth it, or can I skip it?
- Why did my car insurance premium go up with no accidents?
- Is it still traditional for the bride's family to pay for the wedding?
- Are free password managers safe to use?
- Should I keep paying for antivirus, or is Windows Defender enough?