What should I do if I clicked on a phishing link?

Updated October 2026 · How we answer

Short answerDon't panic. Disconnect from the internet, change passwords on any accounts you entered, run a security scan, and monitor for fraud. If you gave financial info, contact your bank immediately.

Immediate steps to take

If you clicked a phishing link but didn't enter any information, the risk is usually low. Still, close the page and run a malware scan on your device. If you did enter login details or personal information, act quickly: disconnect from Wi-Fi or unplug your ethernet cable to limit any data transfer.

Next, change the password for the account you exposed, and any other accounts that use the same password. Turn on two-factor authentication (2FA) wherever possible. Then run a full antivirus or anti-malware scan on your device to check for any downloaded threats.

  • Disconnect from the internet immediately
  • Change passwords for compromised accounts
  • Enable two-factor authentication
  • Run a full security scan
  • Contact your bank if financial info was shared
  • Monitor accounts for unusual activity

If you shared financial or personal data

If you entered credit card numbers, bank details, or your Social Security number, call your bank or card issuer right away. Ask them to freeze or monitor the account for fraudulent charges. You can also place a free fraud alert or credit freeze with the major credit bureaus (Equifax, Experian, TransUnion) to prevent new accounts from being opened in your name.

In the U.S., you can report phishing to the FTC at ReportFraud.ftc.gov and to the Anti-Phishing Working Group at reportphishing@apwg.org. If you're outside the U.S., check your country's national cyber security center for reporting guidance.

What happens after you click

Simply clicking a link rarely installs malware by itself, but it can confirm your email address is active, leading to more phishing attempts. If the link led to a fake login page, your credentials could be stolen within minutes. That's why speed matters when changing passwords.

Some phishing links download malicious files automatically, especially if your browser or plugins are out of date. Keeping your software updated reduces this risk. If you notice new browser toolbars, pop-ups, or strange behavior, your device may be infected.

Common mistakes

  • Thinking that just clicking a link always infects your device—usually the real danger is entering information.
  • Waiting days to change passwords, giving attackers time to use stolen credentials.
  • Only changing the one password you entered, while ignoring other accounts that share the same password.
From our shopsPhoneCasesForAll: 50,000+ aesthetic cases — Y2K, coquette, cottagecore and more.