Skip to content
All guides

Scams and phishing

What To Do If I Clicked a Phishing Link

Clicking is not the same as handing over a password. This guide ranks the next steps by what you typed, downloaded, or approved.

By the 4safer teamUpdated August 29, 20268 minutes read

Rank the damage before you pay anyone

You only opened the page. Close it. Do not click “enable notifications” or “download the viewer.” Check whether a file landed in Downloads. Update the phone or computer. That is often the whole job. You typed a password or a code. Treat that secret as burned. The FTC’s advice after you give a scammer account information is to create a new strong password on the real site and turn on two-factor authentication. If you cannot get in, use the provider’s official recovery page. You typed a card or bank detail. Call the number on the card. Ask about alerts, a replacement card, and charges you do not recognize. You typed an SSN or uploaded an ID. Use IdentityTheft.gov and consider a credit freeze. Do not type the number into another random form. You let someone remote into the computer. The FTC says to update security software, run a scan, change passwords, and turn on two-factor authentication. Get help from the manufacturer or a person you already know — not the caller who is still on the line.

Do the work on typed websites

What to do if I clicked a phishing link is mostly “leave the fake page.” CISA’s household rule is to think before you click the first time and to verify the sender before you surrender a secret the second time. Never:

The real company will still be at the domain you already know.

  • Re-enter the password on the page that just tricked you
  • Call the number displayed on that page
  • Install the “security tool” it offers
  • Read a new code to a chat agent who appeared after the click

After the urgent account work

If money already moved, stay with the bank. A consumer article cannot promise a refund. Speed and official channels still help. If the device now behaves strangely — new toolbars, blocked settings, a voice telling you not to hang up — take it off important accounts until a trusted technician or official support has looked at it.

  • Review login activity on official security pages
  • Remove unknown devices
  • Check email forwarding if the phish targeted mail
  • Replace reused copies of the same password
  • Report the scam at ReportFraud.ftc.gov
  • Forward phishing mail only through your provider’s “report phishing” control, not by Reply-All

Prevent the next click from mattering as much

Unique passwords limit the blast radius. MFA or a passkey stops many stolen secrets. Passkeys tied to the real domain refuse a look-alike page more often than a typed code does. Login alerts tell you if the stolen secret was used. Credit freezes help when the phish collected identity data, not only a password. Knowing what to do if I clicked a phishing link should leave you with a locked official account, not a subscription to a “breach removal” service.

Practical checklist

  • Close the fake tab. Do not type anything else there.
  • Decide whether you entered a password, a code, a card, or an ID.
  • Change affected passwords on typed official URLs.
  • Enable MFA or a passkey and sign out other sessions.
  • Call the bank on the card number if payment data was entered.
  • Use IdentityTheft.gov if identity data was entered.
  • Scan and update the device if a file or remote tool was involved.
  • Report the scam to the FTC.

Final safety check

After the immediate steps, keep monitoring the account and use only official recovery channels if new warnings appear.

Frequently asked questions

I clicked and immediately closed the page. Am I hacked?

Not automatically. Avoid extra clicks on that page, check Downloads, and update the device. Change a password only if you typed one.

Should I factory-reset the phone?

Not as a first move after a single click with no download. Reset becomes more reasonable if malware is confirmed or remote access was granted and official scans are not enough.

Does reporting get my money back?

Reporting helps agencies and may support a bank case. It is not a guarantee of reimbursement.

What should I do first?

Use the official account or service website, change affected credentials, review recent activity, and enable multifactor authentication where available.

Can a clean check guarantee that I am safe?

No. A clean result only means the available sources did not show a match. Continue using unique credentials and account security alerts.

Should I enter my password into a checker?

No. Use an identifier such as an email address or username, and never share a password or authentication code with an untrusted checker.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.