What To Do If You Clicked a Phishing Link: Act Fast (October 2026)

If you clicked a phishing link, close the page, switch to a device you trust, and work out exactly what you did before you panic. Clicking a link on its own is usually low risk, but entering a password, approving a one-time code, or downloading a file is a different situation entirely. Most of the recovery work takes under an hour if you start now.

What trips most people up is that the right response changes completely depending on whether you only loaded the page or handed over credentials. This guide branches by what you actually did, then walks through the response for each case on Mac, Windows, iPhone, and Android.

Last reviewed for October 2026.

What You Need

What You Need

You do not need a technician, a new laptop, or a paid product to handle this. You need a second device and about ten quiet minutes.

  • A different, trusted device. A second laptop, or your phone when the compromised machine is a laptop. Do not use the device that opened the suspicious page until it has been checked.
  • The suspicious URL. Screenshot the address bar before you close the tab, or copy the full address including every character before the first single slash.
  • Access to your accounts. Make sure you can sign in to your email, bank, and password manager from the clean device, and that you still hold your recovery codes.
  • Your password manager. If you use one, its browser extension and autofill are the fastest way to find every account that shares a password.
  • Device details. The make, model, and operating system version, plus the date and rough time of the click. You will need these if the click happened on a work machine or a bank dispute follows.
  • A written record. A notes file with the sender address, the URL, the time, and what you did after the page opened. This is the evidence a bank, an employer, or a report to law enforcement will ask for later.

If the link came from an email or text, keep the message itself. Do not forward it, and do not reply to it.

Step-by-Step

Disconnect from the Suspicious Site and Assess the Click

Close the tab or the app window. Do not click anything else on that page, including buttons, cookie banners, fake virus warnings, and anything that looks like a download prompt. On a phone, close the browser tab and dismiss the page rather than tapping around it.

Then classify what actually happened, because each situation has a different response.

What you didHow worried to beWhat to do first
Opened the page and closed it, or accepted only a cookie bannerLowClear browsing data, run a quick scan, and report the message
Downloaded a file but did not open itLow to moderateDelete the file, empty the downloads folder, then scan
Opened a file or installed an app the site offeredHighDisconnect the device from the network, scan offline, and rotate every password
Typed a username and password on the pageHighChange that password first, from a different device, then the accounts that share it
Entered card or bank detailsHighCall your bank fraud line now, then secure email and passwords
Approved a push prompt or entered a one-time codeHighChange the password and review MFA devices and active sessions immediately
Were already signed in on that site when you clickedHighRevoke active sessions and sign out everywhere for that account

Members of r/cybersecurity_help and r/antivirus get this question constantly, and the consensus answer is the same one: most phishing links exist to harvest credentials or to push an install. If you did neither, you are very probably fine.

Change Exposed Passwords from a Trusted Device

Change passwords on the clean device, not on the machine that opened the page. Work in this order, because each step assumes the previous one is secure.

  1. Your email account. Email resets passwords everywhere else. An attacker holding your inbox can lock you out of every other service.
  2. Banking and payment accounts. These have the fastest path to real loss.
  3. Your primary identity account. The one that resets everything else, whether that is a Google or Microsoft account.
  4. Work, cloud storage, and password manager. Ordering matters here too.
  5. Every account that reused a password. Search your password manager for the old password, or use a breach-checking tool to find where it was reused, and give each one a unique replacement.

Use a password manager to generate a fresh, unique password for each account. If you turned on two-factor authentication, prefer an authenticator app over SMS codes, since a SIM swap defeats text-based 2FA but does nothing against an app.

Review the account’s security settings while you are there: remove MFA devices you do not recognize, rotate backup codes, and sign out of all other sessions. The phrase forum users keep repeating is simple: change your passwords from another device, and revoke every active sign-in session.

Check for Downloads, Extensions, and Device Changes

A page that only loaded leaves very little behind. Knowing what normal looks like on your device is what separates real trouble from anxiety.

On Windows: open your browser’s downloads list (Ctrl+J in Chrome and Edge) and check the folder itself. Then open Settings, Apps, Installed apps and sort by date added.

On macOS: check Downloads in Finder, then open System Settings, General, Login Items and Extensions to see what starts at login. macOS also prompts before installing anything outside the App Store, which is one reason a bare click is less dangerous here.

On iPhone: an iOS app cannot quietly read your other data or your password manager without your approval. Check Settings, General, VPN and Device Management for configuration profiles you did not install.

On Android: open the Play Store, your profile icon, then Manage apps, and sort by recently installed. Remove anything you do not recognise, revoke unknown accessibility permissions in Settings, Security, and check for apps installed from outside the Play Store.

Also look at your browser extensions. A page cannot install one on its own in current browsers, but a fake browser update page absolutely can talk you into installing one.

Scan or Remove Malware If the Device Is at Risk

Start with the tools already on the machine. On Windows, run Microsoft Defender Offline Scan from Windows Security, Virus and threat protection, Scan options. On macOS, update the system, then use Quick Scan in System Settings, Privacy and Security, Security.

If you downloaded and opened a file, or installed something the page offered, disconnect the device from the network first, including unplugging Ethernet. Then run a full scan with reputable software that can work without a connection. If you have no security software, download the installer on the clean device, transfer it by USB, and do not reconnect the machine to the network first.

Remove anything flagged, then restart and scan again. If the device still behaves oddly, or a scan cannot remove the problem, a clean reinstall is the last step rather than the first one. Community consensus strongly rejects wiping a machine as an opening move.

One honest caveat: scanners catch known malware signatures, not everything. A missed detection is not proof a device is infected either.

Report the Phishing Attempt and Monitor for Abuse

Reporting does not recover your data, but it does stop other people from clicking the same link and it is what makes your bank dispute easier.

  • Email phishing: forward the message as an attachment to [email protected], and use your provider’s report button, which is built into Gmail and Outlook.
  • Text message phishing (smishing):strong> forward the message to 7726, which is free on US carriers, and report it from the messaging app.
  • Consumer protection: file at reportfraud.ftc.gov, and report criminal activity at ic3.gov.
  • Work device or work email: tell your IT or security team before you change anything. Personal antivirus software and factory resets on a managed machine can break employer controls and make your situation worse.
  • Bank or card involved: call the number printed on the back of your card, not a number from the message or the page you opened.

Then monitor. Check login activity and connected apps on your accounts once a week for several weeks, and put a fraud alert or credit freeze in place with Equifax, Experian, or TransUnion if financial details were entered.

Expect more scam messages afterwards. People who clicked report exactly that: the follow-up flood arrives because the click proved the address is live.

Common Mistakes

Clearing your browser history right away. It removes evidence you will need for a bank dispute or an employer report, and it does nothing about your accounts. Screenshot the URL, the sender, and the time first.

Continuing to use the same device. If a file was opened or an app was installed, staying online lets whatever is installed reach out. Disconnect first, then investigate.

Forwarding the phishing message to friends or colleagues as a warning. It spreads the link and tips off the sender. Report it instead, and warn people through a channel that does not carry the link itself.

Paying a ransom, or paying a pop-up. Fake virus warnings and fake tech-support pop-ups demand money to make the warning go away. Payment buys nothing. Disconnect, scan, and confirm the threat independently.

Signing in through the suspicious page to “check” your account. The page exists to catch exactly that. Sign in from a bookmarked app or by typing the address yourself.

Assuming a closed tab fixed it. Closing the tab ends the moment. It does nothing about a credential you typed, an app you installed, or a session that is still active.

A few habits shrink the next one’s damage: a password manager with unique generated passwords, an authenticator app instead of SMS codes, browser and OS updates on schedule, and hovering over a link on a desktop to read the real destination before clicking.

Frequently Asked Questions

Usually not for the site you landed on, because a page cannot read what you never typed into it. Change passwords for accounts you use elsewhere if you were already signed in to something when you clicked, since the page may have stolen that active session. Changing your email password is a cheap precaution either way, and it takes two minutes.

Check for specific signs rather than guessing: a file in your downloads folder you do not recognise, an app with a recent install date, a browser extension you did not add, or a security warning you did not trigger. A page that only loaded and closed leaves none of these. If nothing appears in those lists after a scan, you almost certainly have nothing installed.

What should I do first if my bank or payment account was involved?

Call your bank fraud line using the number on the back of your card, and say plainly that you entered details on a phishing page. Ask them to flag the account and explain their chargeback timeline, because that window is short. Then secure your email account, since email can reset banking passwords, and file a report at reportfraud.ftc.gov.

Should I delete the phishing email or browser history?

Not yet. Capture what you need first: the sender address, the full URL, the date and time, and a screenshot of the page. Those details support a bank dispute, an employer incident report, and a law enforcement report. Once the record exists, deleting the message and clearing history is fine and does reduce future distraction.

How long should I monitor my accounts after a suspected phishing click?

Watch closely for the first two weeks, because a captured password is often tested against your real accounts within hours. After that, check login activity and connected apps monthly for several months, since stolen credentials are also sold and replayed later through credential stuffing. If financial details were entered, keep credit monitoring in place for at least a year.

No. That is the whole mechanism of the attack. Navigate independently: type the address yourself, use a bookmarked app, or call a number printed on your card or statement. Search engines and sponsored ads from a compromised account are also unsafe, since attackers buy ads for the brand they just impersonated.

Conclusion

Stop interacting with the page, move to a device you trust, and write down the URL, the sender, and the time before you close anything. Secure your email first, then banking, then anything that reused that password, and scan the device only if a file was opened or an app was installed. If financial details were entered, a download happened, or accounts show changes you cannot explain, call your bank or your IT team directly using a number you already trust.

Leave a Comment