You clicked the link. Now the useful question is not “Was that bad?” but “What happened after the click?” The right response depends on whether you only opened a webpage, typed a password, downloaded or opened a file, or shared financial or personal information. Acting quickly can limit the damage, but there is no need to panic or take random steps that do not match what actually happened.
First, stop interacting with the suspicious page
Close the page and do not click any more buttons, approve notifications, call phone numbers shown on the site, or download anything it offers. If the page asked you to install a browser extension, profile, app, or “security update,” do not proceed.
If this happened on a work device or involved a work account, report the incident to your IT or security team as soon as possible. They may need to check sign-in logs, block the malicious link, or inspect the device.
If you only clicked the phishing link
If you opened a malicious link but did not enter information, download a file, approve a login, or install anything, the risk is generally lower than if you handed over credentials. Still, treat the event seriously.
Update your browser, operating system, and security software if updates are available, then run a reputable malware scan. Modern browsers and operating systems include protections against many known threats, but keeping them current matters because malicious sites can sometimes try to exploit unpatched vulnerabilities.
If you entered a username or password
A compromised password requires a faster phishing response. Go directly to the real service from a trusted device and change the password immediately. Use a new, unique password that you have never used elsewhere.
Then sign out of other active sessions if the service provides that option. Turn on multi-factor authentication, preferably using an authenticator app, passkey, security key, or another strong method available for the account.
If you reused that password anywhere else, change those accounts too. Prioritize your email account because access to email can let an attacker reset passwords for many other services. Check recovery email addresses, phone numbers, forwarding rules, filters, and recent sign-in activity for changes you did not make.
For example, imagine you clicked a fake Microsoft 365 login page and entered your email password. Changing only the Microsoft password may not be enough if that same password protects a shopping account or social network. The safer move is to replace every reused copy and secure the email account first.
If you downloaded or opened a file
If the malicious link downloaded a file but you did not open it, delete the file without running it and empty it from your downloads or trash as appropriate. Then update your security software and scan the device.
If you opened the file, installed an app, enabled macros, added an extension, or granted unusual permissions, the risk is higher. Stop using the device for sensitive activity until it has been checked. If you notice suspicious pop-ups, new software, disabled security tools, unexpected browser behavior, or unexplained account activity, disconnect the device from the network and seek qualified technical help. A business device should be handed to the organization’s IT or security team rather than “cleaned up” casually.
If you shared payment or banking information
Contact the bank, card issuer, or payment provider immediately using the phone number on your card, official app, or a trusted website. Explain that the information may have been exposed through phishing. Ask what protective action they recommend, which may include replacing a card, blocking transactions, changing account credentials, or adding extra monitoring.
Review recent transactions and keep checking the account for activity you do not recognize. If an unauthorized transaction appears, report it promptly. Do not call a number shown on the phishing page or in the original message.
If you shared sensitive personal information
If you provided information that could be used for identity theft, such as a government identification number, date of birth, or other high-value personal data, use the identity-theft protection and reporting options available in your country. Depending on where you live, that may include placing a fraud alert or credit freeze and monitoring your credit reports.
Secure the device and accounts without overreacting
One common mistake after clicking a phishing link is changing every password before checking whether the device itself might be compromised. If you actually installed suspicious software, use a known-clean device for important password changes. Otherwise, malware with credential-stealing capability could capture the new password as well.
Another mistake is assuming that a password change ends the problem. Review recent account activity, connected devices, app permissions, recovery methods, and security alerts. Watch for follow-up phishing messages too; scammers sometimes reuse information from one incident to make the next message more convincing.
Related reading opportunities for this topic include password security basics, how to spot phishing emails, and identity theft recovery steps.
Report and delete the phishing message
Use the phishing or spam reporting feature in your email or messaging service. If the scam impersonated a bank, employer, retailer, or other organization, you can also report it through that organization’s official fraud channel. After preserving anything you may need as evidence, delete the message so you do not accidentally open it again.
FAQ
Should I change my password if I clicked a phishing link but entered nothing?
Usually, a password change is most urgent when you typed or submitted credentials, approved an unexpected login, or have evidence the account was accessed. If you only opened the page, focus on closing it, updating your device, scanning for malware, and monitoring the relevant account.
Can clicking a phishing link infect my phone or computer?
It can, although simply opening a page does not automatically mean the device is infected. Risk increases if you downloaded or opened a file, installed software or a profile, granted permissions, or the device had an exploitable security flaw. Keep the system updated and run appropriate security checks.
What if I entered my password but changed it immediately?
Changing it quickly is the right first move. Also sign out other sessions, enable multi-factor authentication, check recovery settings and recent logins, and replace the password anywhere else you reused it.
What should I do if I entered my card details?
Contact the card issuer or bank immediately through a trusted channel, explain that the details may be compromised, and follow its instructions. Monitor transactions closely and report any unauthorized charges promptly.
Act based on what happened after the click
The safest response is specific, not dramatic. A click with no further interaction calls for updates, scanning, and monitoring. A submitted password calls for immediate credential changes and account review. A downloaded or opened file may require deeper device checks, while exposed financial or identity information should be reported to the relevant institution quickly. The sooner you match your response to what you actually did after the malicious link, the better your chances of containing the problem.