What to Do If You Clicked a Phishing Link (Step-by-Step Recovery Guide)


It happens in a split second.

You’re moving through your inbox quickly, half-distracted, and you click before you’ve fully processed what you’re looking at. The moment your finger lifts off the mouse button — or your thumb leaves the screen — you feel it. That immediate, stomach-dropping recognition that something isn’t right.

Maybe the page that loaded looks wrong. Maybe nothing loaded at all. Maybe your antivirus flashed a warning you dismissed before reading it. Maybe you went further — entered a password, typed in your card number, filled out a form — before realizing the site wasn’t what it claimed to be.

Whatever happened, the next few minutes matter more than you might think.

Here’s the most important thing to understand right now: clicking a phishing link is not automatically a disaster. What happens next — how quickly you act and what steps you take — determines whether this becomes a minor scare or a serious problem. People who respond quickly and correctly limit the damage dramatically. People who freeze, panic, or do nothing often don’t.

This guide walks you through exactly what to do, in the right order, depending on how far the interaction went. Read through to find your situation, then follow the steps that apply to you. Clear, practical, no technical background required.


First: Understand What Actually Just Happened

Before doing anything, take fifteen seconds to think clearly about what occurred. The appropriate response depends heavily on what actually happened — and panic leads to mistakes.

Ask yourself three questions:

Did the page load at all? Sometimes phishing links go to dead pages, misconfigured servers, or sites that have already been taken down. If nothing loaded, your risk is significantly lower.

Did you interact with whatever loaded? There’s a meaningful difference between a link loading a suspicious page and you then entering information on that page. Simply having a phishing page open in your browser is far less serious than submitting a form on it.

What did you do on the page if it loaded? Did you just look at it? Did you click something? Did you enter a username, password, email address, phone number, credit card number, or other personal information? Did you download anything? Did you accept any prompts?

Your answers determine which sections of this guide are most relevant. We’ll work through responses from least serious to most serious, so you can identify your situation and act accordingly.

One more thing before the steps: do not click back into the suspicious page, do not call any number displayed on it, and do not download anything it’s prompting you to download. Some phishing pages display alarming warnings designed to get you to take additional harmful actions. Ignore everything on the page and focus on the steps below.


Assess Your Situation: Which Scenario Are You In?

Scenario A: You clicked the link but the page didn’t load, loaded blank, or you closed it immediately without interacting.

Scenario B: The page loaded and you looked at it, but you didn’t enter any information, click any buttons, or download anything.

Scenario C: You entered information — a password, email, personal details — into a form on the page.

Scenario D: You entered financial information — credit card numbers, bank account details, or similar.

Scenario E: You downloaded a file from the link, or accepted a prompt to install something.

Scenario F: The link came through a work account or device, or you clicked it on a work network.

Most of the steps below apply across all scenarios — the difference is in urgency and what you prioritize first. We’ll cover all of them.


Step 1: Don’t Panic — But Don’t Wait Either

These two instructions sound contradictory. They’re not.

Panic causes bad decisions. People who panic after clicking phishing links sometimes call the phone number displayed on the fake page — handing themselves directly to the attacker. They click through additional prompts trying to “undo” what happened. They freeze entirely and do nothing for hours, during which time attackers are acting on whatever they captured.

But waiting is equally dangerous. If you entered credentials, an attacker may be logging into your accounts right now. If you downloaded something, it may be installing in the background. Every minute matters.

The right state of mind is calm urgency. You’re not catastrophizing, but you’re moving through the steps below without unnecessary delay. Put down whatever else you were doing. This takes priority.


Step 2: Disconnect From the Internet

This step applies regardless of which scenario you’re in, and it should happen within the first minute.

Disconnecting your device from the internet does several important things simultaneously. It stops any malware that may have started downloading from completing its installation. It cuts off communication between any malicious code that landed on your device and the attacker’s servers. It prevents any additional data from being transmitted if something is already running.

How to disconnect:

On a laptop or desktop: unplug the ethernet cable if you’re on a wired connection. For Wi-Fi, click the network icon in your taskbar and disconnect, or switch your device to airplane mode. On Windows, you can also press Windows Key + A to open the Action Center and toggle airplane mode on.

On a phone or tablet: enable airplane mode immediately. Swipe down from the top of your screen (Android) or top-right corner (iPhone) to access quick settings.

If you need internet access to follow the steps in this guide — looking up information, changing passwords — use a different device. Your phone if you clicked on a computer. A family member’s device. Keep the potentially affected device disconnected while you work through your response.

One important exception: if you’re going to run an antivirus scan (Step 4), you may need to reconnect briefly to update virus definitions before scanning. We’ll cover that when we get there.


Step 3: Don’t Enter Any More Information — Close the Page

If the phishing page is still open in your browser, close it now. Don’t click anything on it first. Don’t read the warnings it’s displaying. Don’t call any number it shows. Just close the tab or the browser entirely.

If your browser is frozen or won’t close normally — a common tactic used by tech support scam pages that run deliberate JavaScript loops — force-close it:

On Windows: Press Ctrl + Shift + Esc to open Task Manager. Find your browser in the list, right-click it, and select “End Task.”

On Mac: Press Command + Option + Escape to open Force Quit. Select your browser and click Force Quit.

On mobile: Swipe up from the bottom of the screen (iPhone) or use your recent apps button (Android) to see open apps, then swipe the browser away to close it.

After force-closing, don’t reopen the browser and navigate back to the page. When you do reopen your browser, if it asks whether to restore your previous session, decline. You don’t want that page reloading.


Step 4: Run a Full Antivirus Scan

Regardless of which scenario applies to you, run a full system scan now. This is the fastest way to determine whether anything malicious was delivered to your device through the link.

If your antivirus definitions haven’t been updated recently, reconnect to the internet briefly — just long enough to update — then disconnect again before running the scan. Up-to-date definitions give the scan the best possible chance of catching recent threats.

Run a full scan, not a quick scan. Quick scans check the most common malware locations. A full scan checks your entire system. It takes longer — anywhere from 30 minutes to a few hours depending on your storage size — but after a potential exposure, thoroughness matters more than speed.

If your existing antivirus comes back clean but you’re still concerned — particularly if you downloaded a file or if symptoms appear after the fact — run a second-opinion scan with a different tool. Malwarebytes is widely recommended for this purpose and offers a free version that’s effective for post-incident scanning. Different tools use different detection logic, and threats missed by one scanner are sometimes caught by another.

While the scan runs, continue through the remaining steps on a separate device where possible.


Hand point to form with password and red padlock. Concept of digital data security, access, privacy protection with finger click on secure code, 3d render illustration isolated on white background

Step 5: Change Your Passwords — Starting With Email

This step is critical if you’re in Scenario C (you entered a password on the phishing page) — but it’s strongly recommended for everyone regardless.

Here’s the priority order for password changes:

Change your email password first. Your email account is the master key to your digital life. Password reset links for every other service go to your email. If an attacker gains access to your email, they can reset passwords on your bank, your social media, your shopping accounts — everything. Securing your email account immediately limits the blast radius of anything else that happens.

When changing your email password, use a strong, unique passphrase — our password guide covers exactly how to create one you can actually remember. Don’t reuse any password you’ve used before, and don’t use a variation of the password you may have just compromised.

After email, change passwords in this order:

  • Banking and financial accounts
  • Any account whose password you entered on the phishing page
  • Any other account where you reuse that same password — and if you do reuse passwords across accounts, now is the time to stop permanently
  • Social media accounts
  • Shopping accounts with stored payment information

Do your password changes from a device you’re confident isn’t compromised — ideally not the device you clicked the link on, until after that device’s scan comes back clean. If you don’t have another device, change passwords on the affected device after the antivirus scan has completed and come back clean.

Enable two-factor authentication on every account where you change a password. If 2FA is already enabled on the account whose password was phished, the attacker likely can’t access it even if they have your password — they’d need your physical device too. This is the clearest possible demonstration of why 2FA matters.


Step 6: Check Whether Unauthorized Access Has Already Occurred

Changing your passwords is forward-looking — it protects against future access. But if an attacker already got into an account in the time between when you clicked and when you’re reading this, they may have already done damage that needs addressing separately.

Check the security and activity logs of your most important accounts before, not after, changing passwords where possible. Here’s what to look for:

Email accounts: Most email providers maintain a recent login history. In Gmail, scroll to the bottom of your inbox and click “Details” next to “Last account activity.” In Outlook, go to your Microsoft account security settings. Look for logins from unfamiliar locations, devices, or at times when you weren’t using the account.

Also check: your Sent folder (for emails sent without your knowledge), your trash (for emails deleted to cover tracks), filters and forwarding rules (attackers sometimes set up forwarding to copy your emails to themselves), and your recovery email and phone number settings (to make sure they haven’t been changed to attacker-controlled values).

Financial accounts: Log in from a clean device and review recent transactions. Look for any transaction you don’t recognize, however small. Some attackers make small “test” transactions before attempting larger ones — a $1 charge from an unfamiliar source warrants investigation.

Social media accounts: Check recent login activity, posts you didn’t make, messages sent from your account, and any changes to your profile information, linked email, or phone number.

If you find evidence of unauthorized access: Document it with screenshots before changing anything. You’ll need this documentation if you contact the service’s support team, law enforcement, or your bank. Then proceed with securing the account — change the password, revoke access for any unfamiliar devices or sessions, and contact the service’s fraud or security team.


Step 7: If You Entered Financial Information, Act Now

If you’re in Scenario D — you entered credit card numbers, bank account details, or other financial information — the steps above apply, but you need to add immediate action on the financial side.

Contact your bank or card issuer directly. Call the number on the back of your card or on your bank’s official website — not any number from the suspicious email or page. Tell them you may have entered your card details on a fraudulent website. Ask them to:

  • Flag your account for potential fraud
  • Cancel and reissue the affected card
  • Place a temporary hold if they offer it
  • Review recent transactions for anything suspicious

Banks and card issuers deal with this constantly. Their fraud teams are equipped for it, the process is straightforward, and most card providers offer zero-liability protection for fraudulent charges reported promptly. The sooner you call, the better your protection.

Consider a fraud alert or credit freeze. If you provided information beyond card details — your Social Security Number, date of birth, full address — you’re at risk of identity theft, not just payment fraud. Contact one of the three major credit bureaus (Equifax, Experian, or TransUnion) to place a fraud alert. A fraud alert requires lenders to take extra steps to verify your identity before extending credit in your name.

A credit freeze is stronger — it prevents new credit from being opened in your name entirely until you lift it. It’s free, it’s reversible, and it’s the most powerful tool available for preventing identity theft from escalating.

File a report with the FTC at reportfraud.ftc.gov. This creates an official record, may be required for insurance claims, and contributes to enforcement efforts against the phishing operation.


Step 8: If You Downloaded a File or Installed Something

If you’re in Scenario E — you downloaded a file from the phishing link, or accepted a prompt to install something — treat this as a potential active malware infection and respond accordingly.

Do not open the downloaded file if you haven’t already. Delete it immediately from your downloads folder and empty the trash.

If you already opened the file or installed something, the antivirus scan from Step 4 is your most immediate tool. But as we covered in our article on signs your computer has malware, antivirus doesn’t catch everything — particularly rootkits and fileless malware that evade standard scanning.

Watch for the symptoms we detailed in that article: unexpected slowdowns, CPU usage spikes, browser changes, security software being disabled, unusual network activity. These are signs that something landed on your system even if the antivirus scan came back clean.

If you have any reason to believe something was installed on your system and your scans aren’t resolving your concern, the safest course is a clean wipe and reinstall of your operating system — particularly if the device contains sensitive work or financial data. Our ransomware recovery guide covers the reinstall process in detail, and the same approach applies here.

For mobile devices: If you accepted a download prompt on a phone, go to your app settings and look for any apps you don’t recognize that were recently installed. On Android, check Settings → Apps → sort by install date. Remove anything unfamiliar. On iPhone, Apple’s sandboxing makes drive-by installations significantly harder — if you didn’t explicitly approve and install an app through the App Store, it almost certainly didn’t install.


Step 9: Report the Phishing Link

Once you’ve secured your accounts and addressed any malware risk, report the phishing attempt. This matters more than most people think — reporting contributes to takedowns that protect others from clicking the same link.

Where to report:

  • The FTC: reportfraud.ftc.gov — the primary US consumer fraud reporting body
  • The Anti-Phishing Working Group: forward phishing emails to reportphishing@apwg.org
  • Google Safe Browsing: safebrowsing.google.com/safebrowsing/report_phish — flags the URL for Chrome and other Google-integrated browsers
  • Your email provider: Use the “Report phishing” option in Gmail, Outlook, or your provider of choice — this helps train spam filters
  • The impersonated company: If the phishing email pretended to be from your bank, PayPal, Amazon, or another specific company, forward it to their official abuse or security team. Most major companies have dedicated phishing report addresses — typically abuse@companyname.com or security@companyname.com
  • The FBI’s IC3: ic3.gov — particularly relevant if you suffered financial loss
  • If on a work device: Report to your IT or security team immediately — this is a professional obligation, not optional

Reporting takes five minutes and genuinely helps. Phishing operations rely on their infrastructure staying up long enough to harvest credentials at scale. Reports accelerate takedowns.


Step 10: Monitor Your Accounts and Credit in the Weeks Ahead

Phishing attacks don’t always produce immediate, obvious consequences. Some attackers harvest credentials and sell them. The buyer may not use them for days, weeks, or months. Some identity theft schemes unfold slowly — a fraudulent credit application here, a change of address there — in ways designed not to trigger immediate alerts.

Set up monitoring that catches activity as it happens rather than when you notice it.

Account alerts: Enable email or text notifications for every significant action on your financial and email accounts — logins from new devices, password changes, large transactions, new payees added. Most banks and major services offer these and they’re free.

Credit monitoring: Several services offer free credit monitoring that alerts you when new accounts are opened in your name, when your credit is pulled, or when significant changes appear on your credit report. Checking your free annual credit reports at AnnualCreditReport.com is a baseline — active monitoring services provide more timely alerts.

Check your breach status: If your email address was involved in the phishing attempt and you may have submitted it to the phishing page, check whether it subsequently appears in breach databases. Our guide to checking your breach exposure explains how to do this and what to do if you find your information there.

Set a calendar reminder to check your credit report and account activity logs one month from now, and again at three months. This catches slow-moving identity theft that immediate monitoring might miss.


Special Situations Worth Addressing Separately

If You Clicked on a Work Device or Work Network

This changes the response significantly. A phishing click on a work device isn’t just your problem — it’s potentially your employer’s problem, and in many industries it carries legal and compliance implications.

Report it to your IT or security team immediately. Don’t wait to see if anything bad happens. Don’t try to handle it yourself first and then tell them. Tell them now.

Most organizations have incident response procedures specifically for this situation. Your IT team needs to know as soon as possible so they can assess whether the network was exposed, whether other devices are at risk, and whether any compliance reporting obligations have been triggered.

You may feel embarrassed. Report it anyway. Security teams deal with this constantly — from all levels of an organization, including technical staff — and the professional consequences of not reporting are generally far worse than reporting promptly.

If Someone Else — a Child, Elderly Parent, or Less Technical Family Member — Clicked the Link

Walk them through the steps above calmly and without making them feel blamed. The psychological damage of feeling stupid for clicking a phishing link can cause people to hide what happened — which is far more dangerous than the click itself.

Check their accounts alongside them. If they don’t use a password manager, use this as an opportunity to set one up. If they don’t have antivirus on their device, install one. See our recommendations for the best antivirus software for options that are genuinely easy to use for non-technical people.

If they’re elderly and potentially targeted for financial fraud specifically, consider setting up account alerts together and identifying a trusted contact arrangement with their bank — many banks offer this as a fraud protection measure for vulnerable customers.

If You’re Not Sure Whether the Link Was Legitimate

Sometimes you click a link and the destination looks slightly off — not obviously fake, but not obviously right either. You’re not sure whether you just clicked something phishing or a legitimate but poorly designed page.

In this case, treat it as a potential phishing click and run through the steps above. The cost of running a precautionary scan and updating a password you were going to update anyway is minimal. The cost of assuming everything is fine when it isn’t is potentially substantial.

When in genuine doubt, contact the company the email claimed to be from — through their official website, not any contact information in the email — and ask whether the communication was legitimate.


How to Avoid Being in This Position Again

Once you’ve worked through the immediate response, it’s worth spending a few minutes on prevention. Not because you were careless — phishing attacks fool careful, intelligent people constantly — but because the defenses available to you now are significantly better than they were even a few years ago.

Slow down with email. The single most effective behavioral change is building the habit of pausing before clicking any link in any email, however legitimate it looks. The seven warning signs we covered in our phishing identification guide give you a mental checklist that takes under a minute to run through. Making that pause automatic closes the majority of phishing risk.

Use antivirus with real-time web protection. A good antivirus doesn’t just scan files — it checks URLs against known phishing databases in real time and blocks access to flagged pages before they load. This provides a safety net during exactly the kind of momentary inattention that leads to phishing clicks. We’ve tested how leading antivirus solutions handle phishing URL blocking — the differences between products are meaningful and worth reviewing.

Enable two-factor authentication everywhere that offers it. As we covered in our password guide, 2FA means that even a successfully phished password is insufficient for an attacker to access your account. This is the single most impactful technical change available to you.

Use a password manager with unique passwords for every account. If each account has a unique password, a phished credential on one account doesn’t compromise any other. Containment is built into the architecture.

Check your breach exposure periodically. Knowing which of your credentials are already in breach databases helps you prioritize which passwords need changing before attackers use them.


The Honest Bottom Line

Clicking a phishing link is one of the most common mistakes people make online. It’s not a reflection of intelligence or tech-savviness — it’s a reflection of how sophisticated modern phishing has become, and how effectively it’s engineered to bypass human judgment in unguarded moments.

What matters is the response.

Act quickly. Disconnect first. Run a scan. Change your email password. Work through your financial accounts. Enable 2FA everywhere. Monitor for the weeks ahead.

Most people who click phishing links and respond promptly avoid serious consequences. Most people who ignore the warning signs or delay their response don’t. The steps above are the difference — and now you have them.

If you want to make sure your protection is strong enough to catch phishing links before you click them in the future, our antivirus comparison guide shows exactly how leading security tools handle phishing URL detection. And if you haven’t set up two-factor authentication on your most important accounts yet, do that before you close this tab. It takes ten minutes and provides protection that no phishing attack can easily overcome.


Frequently Asked Questions

What happens if you click a phishing link but don’t enter any information? Your risk is significantly lower but not zero. Simply loading a phishing page can in rare cases trigger drive-by downloads that exploit unpatched browser vulnerabilities — though this is less common with modern, updated browsers. More practically, the page may have confirmed to the attacker that your email address is active and monitored. Disconnect from the internet, run an antivirus scan, and watch for any unusual behavior. No information entered generally means no credential theft, but treating it cautiously is still the right call.

Can you get a virus just from clicking a phishing link? Yes, in specific circumstances. Drive-by download attacks can deliver malware simply by loading a page, particularly if your browser or its plugins have unpatched vulnerabilities. This is more common on outdated systems and less common on fully updated browsers. If a phishing page prompted a download — or if a download started automatically — treat the device as potentially infected and run a thorough scan. Keeping your browser and operating system updated significantly reduces this risk.

How quickly do phishing attackers act on stolen credentials? It varies by attacker and attack type. Automated credential stuffing attacks can begin testing stolen credentials against other services within minutes of capture. Manual attackers targeting financial accounts typically move within hours. Some credential harvesting operations sell stolen data rather than using it directly, in which case the buyer’s timeline is unpredictable — which is why changing passwords promptly matters even if nothing seems wrong immediately.

Should I factory reset my phone if I clicked a phishing link on it? Not automatically. For most phishing clicks on a phone — particularly on iPhone, where sandboxing makes unauthorized installation extremely difficult — a factory reset isn’t necessary. Run a scan with a reputable mobile security app, check your installed apps for anything unfamiliar, change passwords on affected accounts from a separate device, and monitor for unusual behavior. Reserve factory reset for situations where you downloaded and installed something from the phishing link, or where symptoms of compromise appear that scanning doesn’t resolve.

What if I entered my Social Security Number on a phishing page? This is among the more serious outcomes because SSN exposure enables identity theft rather than just account compromise. Act immediately: place a fraud alert with one of the three major credit bureaus (which automatically notifies the other two), consider a credit freeze to prevent new accounts from being opened in your name, file a report with the FTC at IdentityTheft.gov, and monitor your credit reports closely over the coming months. The FTC’s identity theft recovery portal provides a personalized recovery plan and tracks your progress through resolution steps.

Can phishing links work through text messages and social media, not just email? Absolutely. Phishing through SMS text messages — called smishing — has grown significantly and follows the same principles as email phishing. Phishing links also arrive through social media direct messages, WhatsApp, and even legitimate platforms like LinkedIn. The same evaluation principles apply regardless of channel: check where the link actually goes before clicking, be skeptical of urgency, and verify unexpected communications through official channels. The steps in this guide apply equally regardless of how the link arrived.

How do I know if my identity has been stolen after a phishing click? Signs of identity theft include unfamiliar accounts appearing on your credit report, collection notices for debts you don’t recognize, being denied credit unexpectedly, receiving bills or statements for accounts you didn’t open, or notifications from services about account changes you didn’t make. Checking your credit report and setting up credit monitoring in the weeks after a phishing incident provides early warning. The FTC’s IdentityTheft.gov resource provides step-by-step guidance if identity theft is confirmed.

Leave a Reply

Your email address will not be published. Required fields are marked *