Reader-supported: we earn a commission on some links, at no extra cost to you. How this works
Security & PrivacyGuide

What to Do If You Clicked on a Phishing Link

Clicked a phishing link? Do not enter details, disconnect if you downloaded anything, change passwords, enable two-factor authentication, and scan your device. Steps here.

If you clicked a phishing link, do not enter any information on the page, and close it. If you typed a password or downloaded a file, act quickly: change that account's password from a different device, turn on two-factor authentication, disconnect from the internet if a file downloaded, and run a security scan. Then watch your accounts for unusual activity.

Why this happens

Phishing links are designed to look like real login pages or downloads so you hand over information or install malware. What happens next depends on what you did:

  • If you only clicked and did nothing else, the risk is usually low. Simply loading a page rarely infects a modern, updated phone or computer.
  • If you entered a username and password, the attacker may now have those credentials.
  • If you entered card or bank details, that payment information may be exposed.
  • If you downloaded and opened a file or app, malware may have been installed.

Is this normal?

Clicking a convincing phishing link is extremely common and happens to careful people too. It is a mistake, not a disaster, and quick action usually prevents harm.

Does it cause any problems?

It can, if you entered details or installed something. Possible problems include a stolen account, fraudulent charges, spam sent from your address, or malware. Acting within the first hour greatly reduces the damage.

How to fix or check it

  1. Stop and close the page. Do not enter or submit anything else.
  2. If a file downloaded, disconnect from Wi-Fi and mobile data to limit any malware, then delete the file.
  3. Change your password for the affected account from a device you trust, not the one that may be infected. If you reuse that password elsewhere, change it there too.
  4. Turn on two-factor authentication for that account so a stolen password alone is not enough.
  5. Run a malware scan. On Windows, open Windows Security and run a full scan. On Mac, keep macOS updated, which includes built-in protection. On Android, run Play Protect. On iPhone, malware is rare, but install any pending updates.
  6. If you entered bank or card details, contact your bank, watch for unknown charges, and ask about freezing or reissuing the card.
  7. Check for signs of takeover, such as password reset emails you did not request, and review the account's active sessions and connected devices.

Frequently asked questions

I clicked but did not enter anything. Am I in trouble?

Usually not. On an updated device, loading a page alone rarely causes harm. Close the page, avoid entering anything, and you are almost always fine. Keep an eye on the account anyway.

Can a phishing link install a virus just by clicking?

It is uncommon on modern, patched phones and computers. Most damage requires you to enter details or open a downloaded file. Keeping your software updated closes the rare gaps that allow drive-by installs.

Should I do a factory reset?

Only if you downloaded and ran something and scans show an infection you cannot remove. For a simple click with no download, changing passwords and running a scan is enough.

More in this topic

More in Security & Privacy

See the full guide →