Your stomach drops the moment you realize it. The email looked like a shipping notice, or a bank alert, or a message from your boss. You tapped the link, a page loaded, and something felt wrong. Maybe it asked for your password. Maybe it just looked slightly off.

First, breathe. Clicking a link is not the same as handing over the keys, and the next 30 minutes matter far more than the click itself. Here is exactly what to do, in the order that keeps you safest.

Key takeaways

  • Clicking alone rarely hands over your accounts. Typing a password or downloading a file is where the real risk starts.
  • Disconnect from the internet first if you downloaded or ran anything.
  • Change the password on any account you may have exposed, then turn on two-factor login.
  • Watch your bank and email for a few weeks, and report the message so it stops others.

Did clicking actually do anything?

This is the question keeping you up, so let me answer it plainly. Most of the time, simply loading a phishing page does very little on its own. The danger comes from what you do next.

a cursor hovering over a suspicious web link
The click itself is rarely the disaster; what happens next decides the outcome.

There are three levels of “uh oh,” and knowing which one you are in tells you how hard to react.

What you did Risk level What to do
Clicked the link, saw a page, closed it Low Change the impersonated account’s password to be safe; stay alert.
Typed your username and password into the page High Change that password now, everywhere you reused it, and turn on two-factor.
Downloaded a file or ran an installer it offered High Disconnect from the internet and scan the device before anything else.

If you only clicked and closed, you are probably fine. If you entered information or downloaded something, keep reading and move quickly.

Do this in the first 30 minutes

Speed helps, but panic does not. Work through these steps calmly and in order.

1. Disconnect if you downloaded or ran anything

If the page pushed a file at you and you opened it, cut the device off from the internet right away. Turn off Wi-Fi or unplug the network cable. This stops many types of malware from talking to whoever sent them.

If you only saw a web page and typed nothing, you can skip this step.

2. Change the password for the account it impersonated

Say the email pretended to be your bank. Go to the bank’s real website (type the address yourself, do not use the email link) and change your password there. If you typed your old password into the fake page, assume the scammer has it.

Watch out

If you reused that same password anywhere else, change it on every one of those accounts too. Attackers try a stolen password across dozens of popular sites within hours. This is exactly why one password per account matters so much.

3. Turn on two-factor authentication

Even if the scammer grabbed your password, two-factor login (a code from an app or a physical key) blocks them from getting in. Turn it on for the exposed account and, honestly, for your email while you are at it. Your email is the master key to everything else.

4. Scan the device

If you downloaded anything, run a full scan with your built-in security tool. On Windows that is Microsoft Defender; on a Mac and on phones, a full restart plus updating the operating system clears most drive-by junk. Watching for the usual symptoms helps too, and the guide to spotting a phishing email before you click walks through what a bad page tries to pull off.

What to watch for over the next few weeks

Some damage shows up later, not right away. A stolen password might sit unused for a week before someone tries it. So keep a quiet eye out.

Check your bank and card statements for charges you do not recognize, even small ones. Scammers often test a card with a tiny purchase before a big one.

Watch your email inbox and sent folder. If you see password-reset emails you did not request, or messages you did not send, someone may be inside. That is your cue to move faster, and the full set of scam recovery steps for after you got tricked covers how to lock things back down.

Tip

When I helped a friend after she entered her details on a fake parcel page, the thing that saved her was a text alert from her bank about a $1 charge in another country. Turn on transaction alerts today so your bank tells you the second something looks off.

How to know it was phishing in the first place

Now that the fire is out, it helps to understand what tricked you, so the next one does not. Phishing pages lean on a few reliable tricks.

They create urgency: your account will be closed, a package is stuck, a payment failed. That pressure is designed to make you act before you think.

The web address is almost always the tell. A real bank login lives on the bank’s own domain, not something like secure-login-verify.com. Learning to read a link before you tap it is the single habit that prevents most of these moments.

Good to know

On a phone, you can press and hold a link (do not tap) to preview where it actually goes. On a computer, hover your mouse over it and read the address that appears in the corner of the screen.

When to worry more, and who to tell

Most cases end with a password change and some watchfulness. A few need more attention.

If you entered banking or card details, call your bank’s fraud line directly using the number on the back of your card. They can watch the account or issue a new card. If you gave up a government ID or Social Security number, report it at the U.S. government’s identity theft site, identitytheft.gov, which builds you a recovery plan.

You can also report the phishing message itself. In the U.S., forward phishing emails to [email protected] and report the scam at reportfraud.ftc.gov. It takes two minutes and helps get the fake site taken down. If you want the wider picture on how these scams work, the beginner guide to spotting scams and phishing ties it all together.

Your afternoon checklist

  • Figure out which level you are in: clicked only, entered details, or downloaded a file.
  • If you downloaded anything, disconnect from the internet and run a full security scan.
  • Change the password on the account the message impersonated, using the site’s real address.
  • Change that password anywhere else you reused it, and give each account its own password.
  • Turn on two-factor authentication for that account and for your main email.
  • Turn on transaction alerts with your bank and watch statements for a few weeks.
  • Report the phishing message to the FTC or your country’s equivalent so others are protected.

You caught it, you reacted, and that already puts you ahead of most people. The click that scared you tonight will, once you finish this checklist, become the reason your accounts are more locked down than they were yesterday.