JustPhishing.org

I clicked a phishing link — now what?

First: don't panic. Clicking a link is often harmless on its own — the real risk is what you did next. Work through this checklist in order.

Did you only click, or did you enter something?

If you just opened the page and closed it, your risk is low. If you typed a password, card number, or a code, or downloaded a file, act on the steps below right away.

If you entered a password

  • Change that password immediately — and anywhere else you reused it.
  • Turn on two-factor authentication (2FA) on that account. This blocks most takeovers even if the password leaked.
  • Check recent activity / active sessions and sign out unknown devices.

If you entered card or bank details

  • Call your bank using the number on your card and tell them. They can watch for or block fraud.
  • Freeze or replace the card if they advise it.
  • Watch statements closely for the next few weeks — even tiny “test” charges.

If you gave a one-time code

The scammer may be trying to log in right now. Go straight to that account, change the password, and remove any unrecognized devices or phone numbers.

If you downloaded or opened a file

  • Disconnect from the internet if you suspect malware, then run a full antivirus scan.
  • On a work device, tell your IT/security team — quickly and honestly. They'd far rather know early.

Then, going forward

  • Use a password manager so every account has a unique password.
  • Turn on 2FA everywhere it's offered, especially email and banking.
  • Report it — forward phishing emails to your provider and, in the US, to reportphishing@apwg.org.
Clicking is common — recovering well is what matters. Changing the exposed password and turning on 2FA closes the door on the vast majority of attacks.

Stay a step ahead

Get a short weekly email on the scams going around right now.