What to Do If You Clicked a Phishing Link
Everyone slips up eventually, and clicking a phishing link is not the end of the world if you act quickly. What you do in the next few minutes matters more than the click itself.
If you only clicked the link
Clicking alone is often low-risk, but be safe:
- Do not enter any information on the page, close it.
- Do not download or open anything it offered.
- Run a scan with your security software.
- Watch for follow-up messages that try to continue the scam.
If you entered your password
This is the urgent case, move fast:
- Change the password for that account immediately.
- Change it anywhere else you reused the same password.
- Turn on multi-factor authentication (MFA) for that account.
- Sign out all active sessions and check for unfamiliar logins or rules (like new email forwarding).
If you shared payment or personal info
Contain the damage:
- Contact your bank or card issuer to flag fraud and, if needed, freeze the card.
- Watch statements for unauthorized charges.
- If it was work-related, report it to your IT/security team right away, speed helps them contain it.
- Consider a fraud alert or credit freeze if sensitive identity details were exposed.
How it plays out in the real world
Based on real, widely reported incident patterns; names and details are illustrative.
The ten minutes that saved an account
Mark clicked an email link and typed his password before the odd address bar registered. His stomach dropped, but instead of hoping for the best he acted: within ten minutes he had changed the password, signed out of all active sessions, and reported it to IT.
The attacker's login attempt came 40 minutes later, from overseas, and failed against the new password. IT's logs confirmed nothing else had been touched. The incident report was two lines long instead of two pages.
- Speed beats shame. The gap between your click and the attacker's login is your window. Minutes matter; embarrassment can wait.
- Change the password, then kill the sessions. A new password alone can leave the attacker's existing session alive. "Sign out everywhere" closes the door behind them.
- Reporting is protection, not confession. IT can block the domain and warn everyone else who got the same email. The person who reports fast is the hero of the incident.
Test yourself
Know how to react, test yourself free.
Frequently asked questions
I clicked but did not enter anything. Am I infected?
Usually not, clicking a link rarely infects you by itself. Close the page, avoid downloading anything, and run a security scan to be sure.
Should I tell my IT team even if nothing bad happened?
Yes. Reporting quickly lets them block the sender, warn others, and check for wider impact. You will never be in trouble for reporting, early reporting is exactly what they want.
How do I know if my account was actually accessed?
Check the account’s recent-activity or security page for unfamiliar logins, devices, or locations, and look for new rules like email forwarding or changed recovery details. If in doubt, reset the password and enable MFA.