Clicking a phishing link is scary, but the next step depends on what happened after the click. A link that only opened a page is very different from entering a password or running a downloaded file.
Does this affect you?
Use this for phishing links opened from email, text messages, social media, or chat apps on iPhone, Android, Windows, or Mac.
What to do in the first few minutes
Start with calm triage before changing everything at once.
- If the page is still open and you have not entered anything, close it without typing, tapping login, or downloading anything.
- Disconnect from the internet if you downloaded or ran a file, or if this happened on a work device and you are unsure what occurred. Turn off Wi-Fi or unplug Ethernet.
- Think through what actually happened: did you only view a page, enter a password, enter card details, download a file, or install an app?
- If it involved work email, a work computer, or a company account, report it to IT or security right away. They can check logs and block related messages.
- Run a security scan if you downloaded or opened anything. Use Windows Security on Windows or a reputable scanner for the device.
What to check based on what happened
Match the response to the actual exposure.
- If you only clicked and closed the page, you are probably fine. Delete or report the message, but password changes are usually unnecessary.
- If you entered a password, go to the real site by typing the address yourself, change the password immediately, and change it anywhere else it was reused. Turn on two-factor authentication.
- If you entered payment or bank information, contact the bank or card issuer now and ask about fraud monitoring, replacement, or dispute options.
- If you opened a file or installed an app, scan the device and watch for new apps, browser toolbars, popups, unusual battery drain, or unexpected behavior.
- If you are unsure what you entered, secure the most important accounts first, especially email, then banking and password manager accounts.
- Watch for warning signs over the next few weeks, including password reset emails you did not request, unfamiliar sign-in alerts, or contacts receiving strange messages from you.
More control
Preview links before tapping
On a computer, hover over links. On a phone, press and hold carefully to preview when the app supports it. A mismatch between visible text and the destination is a strong warning.
Report the phishing message
Gmail, Outlook, and many other providers include a Report phishing option. You can also report to the organization being impersonated so similar links can be blocked.
A single click is often contained
Modern browsers and operating systems include sandboxing, malicious-site warnings, and built-in scanning. The biggest risk usually starts when information is entered or software is installed.
Sources
- CISA – Avoiding Social Engineering and Phishing Attacks (2024)
- FTC Consumer Advice – How to Recognize and Avoid Phishing Scams (2025)
- Google Safety Center – What to Do If You Think Your Account Has Been Hacked (2025)
