I clicked a phishing link - what now?

Take a breath first. Opening a phishing page is not the same as being compromised, and in most cases nothing has happened yet. What matters is not whether you clicked, but whether you typed something afterwards. This page walks through each case in order.

The short version

If you clicked a link, looked at the page and closed it without entering anything, you are very probably fine. Merely loading a web page does not hand anyone your accounts, and on a phone or an up-to-date computer it does not normally install anything either.

If you typed something into that page - a password, a card number, a code from a text message - then something does need to happen, and it needs to happen now rather than tomorrow. Skip to the section that matches what you entered.

What actually happened when you clicked

Almost all phishing links lead to one thing: a web page that looks like a login screen or a payment form, and which sends whatever you type straight to the person who sent the message. It is a collection box, not an infection. It has no power over you unless you fill it in.

That is why the useful question is what you typed. A click alone leaves the attacker with almost nothing: they may learn that your address is live and that you open messages, which means you will probably get more of them, but they do not have access to anything.

There are less common cases. A link can lead to a file download, in which case what matters is whether you opened the file, not whether it downloaded. And on a computer that has not been updated in a long time, a malicious page can occasionally do more on its own. Both are far rarer than the simple fake login page, which is why the guidance below is ordered by likelihood.

If you only clicked and typed nothing

  1. Close the tab. There is no need to disconnect the wi-fi, power off the device or reset anything - those steps are for a different kind of incident and they will not help here.
  2. Do not go back to the page to have another look, and do not enter anything to test whether it is real.
  3. If a file downloaded, delete it without opening it. A file that has only been downloaded and never opened has not done anything.
  4. Run a scan with whatever security software the device already has. On a phone this is rarely necessary at all.
  5. Expect more messages. Your address is now known to be active, so the same or a related scam will likely arrive again in the coming weeks.

For a sense of what these messages typically look like so the next one is easier to spot, see phishing email examples.

If you entered a password

Assume the password is now in someone else's hands, and act as though they will try it within the hour. They usually do, because these pages are monitored in real time.

  1. Change the password on the real site - reached by typing the address yourself or through the app, never through the link in the message. Do this from a different device if you have one to hand.
  2. Sign out of all active sessions. Most services have a "sign out everywhere" or "active devices" option in security settings. This step matters: changing a password does not always end sessions that are already logged in.
  3. Turn on two-factor authentication if it is not already on.
  4. Change the password anywhere else you used the same one, or anything close to it.
  5. Check the account for changes someone else made: a new forwarding rule on your email, an added recovery address or phone number, or an unfamiliar connected app.
  6. Watch for a follow-up. If it was a work account, the attacker may now email your colleagues from your address.

If you also approved a login prompt or read out a code from a text message, treat the account as compromised even if you have since changed the password, and go through the session sign-out step carefully. Attackers who capture a login in real time end up holding a live session rather than just a password - which is explained in adversary-in-the-middle phishing - and a session survives a password change until you explicitly end it.

If you entered card details

  1. Call your bank now, on the number printed on the back of your card or in the official banking app. Do not use a number from the message, the website or any call you receive.
  2. Ask them to block the card. A blocked card cannot be charged, and a replacement takes days rather than the money taking months to recover.
  3. Check your recent transactions and report anything you do not recognise as fraudulent.
  4. Do not approve any payment confirmation that arrives afterwards. A confirmation always approves a payment - it never cancels one, whatever a caller tells you.

Expect a phone call. A very common follow-up is someone claiming to be from your bank's fraud department, who already knows your name and the amount of the suspicious transaction because they are the one who took it. They will ask you to confirm a code or approve something in your app in order to "stop" the payment. That confirmation is the payment. Hang up and call the bank yourself on the number from your card.

Small amounts deserve particular suspicion rather than less. A page asking for one or two euros to release a parcel is not after the fee - it is after the card details and the confirmation, which are then used for something much larger.

If this happened at work, tell IT immediately

This is the part people delay out of embarrassment, and the delay is far more damaging than the click. Reporting in the first hour usually means a password reset and a session revocation. Reporting the next morning can mean an incident.

  • Report it even if you are not sure it was phishing. A false alarm costs your IT team two minutes.
  • Report it even if you typed nothing. Knowing which staff received the message lets them find and remove it from everyone else's mailbox.
  • Say plainly what you entered and roughly when. Precision here is what lets them scope the response correctly.
  • Do not delete the message. It is the evidence they need to trace the campaign.
  • If you approved an MFA prompt afterwards, say so explicitly - see MFA fatigue for why that step matters so much.

No competent security team blames someone for reporting quickly. These messages are designed by people who do this full time, and the ones that work are the ones that arrive on a busy afternoon looking exactly like something you were expecting.

Frequently asked questions

Can I be hacked just by clicking a link?

It is possible but uncommon. The overwhelming majority of phishing links simply open a fake login page, which can only take what you type into it. Drive-by attacks that need no interaction do exist, but they rely on software that has not been updated in a long time. Keeping your device and browser current makes a plain click a very low risk.

I clicked but did not enter anything. Do I still need to change my password?

Generally no. If you did not type anything into the page and did not open a downloaded file, there is nothing for an attacker to have taken. Changing the password does no harm, but the more useful step is simply staying alert for follow-up messages, because your address is now known to be active.

Is it enough to change the password on the site I was phished on?

Not if you used that password anywhere else. Attackers automatically try a stolen email-and-password combination against many other services. Change it everywhere you reused it, and sign out of all active sessions on the affected account - a password change alone does not always end a session that is already logged in.

What if I entered a code from a text message?

Treat the account as compromised. A code handed over in real time lets an attacker complete a login or a payment there and then. Change the password, sign out of every session, check for new forwarding rules or connected apps, and if it was a bank code, call your bank on the number from your card immediately.

Should I tell my employer even if nothing seems to have happened?

Yes, and quickly. Your IT team can check whether anything was accessed, remove the same message from other people's mailboxes, and confirm nothing further is needed. Reporting in the first hour is routinely the difference between a password reset and a genuine incident.