GuideHQ

What do I do if I clicked a suspicious link?

What actually happens when you click, the first ten minutes in order, and how to tell whether anything got through.

Difficulty
beginner
Time
30 min
Read
4 min
Safety
warning

Short answer

Clicking alone is usually survivable. What matters is whether you then entered anything or downloaded something. Disconnect from the network, do not enter any more details, change the password for the account it imitated from a different device, and turn on two-factor authentication.

The instinct after clicking is panic, followed by doing several things in the wrong order. In most cases nothing has happened yet — the damage comes from what you do in the next minute, which is why having the sequence in mind is worth more than any security software.

Safety

Speed matters, but order matters more. Change passwords from a device you trust, not from the one you are unsure about — if that device is compromised, the new password is captured too. If you entered banking details, call your bank before doing anything else. Never ring a phone number given on the suspicious page or in the message.

Step by step

  1. Stop and enter nothing more.Close the page. Do not type a password, card number, code or personal detail into it, and do not ring any number shown on it. A page that only loaded has usually achieved nothing.
  2. Disconnect if you downloaded or ran anything.Turn off wifi or unplug the network cable. This limits anything that did install from communicating out or reaching other devices, and costs nothing if it turns out to be unnecessary.
  3. Work out what actually happened.Three different situations: the page just loaded, you entered credentials, or a file downloaded and ran. The first is usually nothing; the other two need action.
  4. If you entered a password, change it from a trusted device.A different phone or computer. Change it on the real site, reached by typing the address yourself rather than following any link. Then change it anywhere you reused the same password — which is the part people skip and the part that matters.
  5. Turn on two-factor authentication while you are there.It makes a stolen password insufficient on its own. This is the highest-value five minutes available after any credential exposure.
  6. Sign out all other sessions.Most services have a security page listing active sessions with a sign-out-everywhere option. That ends any session an attacker already started.
  7. Call your bank if card or banking details went in.Use the number on your card. They can block the card and watch the account. Do this before anything else if money is involved.
  8. Run a full scan if anything downloaded.Use the built-in protection on the device — it is adequate for this. Let it complete rather than stopping at the first result, and reconnect only afterwards.
  9. Check for changes you did not make.New email forwarding rules, a changed recovery address or phone number, new devices on the account, unfamiliar sent mail. Forwarding rules are the classic one and are easy to miss.
  10. Watch the accounts for a few weeks.Small unfamiliar transactions are often a test before a larger one. Turn on transaction notifications if your bank offers them.
  11. Report it and warn anyone else who got it.Forward suspicious emails to report@phishing.gov.uk and texts to 7726, free. Tell colleagues or family if the message came through a shared channel.
  12. Do not wipe the device in a panic.Wiping destroys the evidence of what happened and is rarely necessary. Scan, check the accounts, and reserve reinstallation for a device that shows real signs of compromise.

Tips

  • Most phishing needs you to enter something. If you clicked, saw a login page and closed it, you are very probably fine — check the account anyway.
  • A password manager helps here twice: it will not autofill on a fake domain, which is a warning in itself, and it makes changing a reused password across sites straightforward.
  • Keep report@phishing.gov.uk and 7726 somewhere findable. Reporting takes seconds and is worth doing.

Common mistakes

  • Changing the password on the device you are unsure about — If anything is capturing keystrokes on that device, the new password goes straight to the same place. Use a device you trust.
  • Calling the number shown on the suspicious page — It reaches the people who sent it. Fake support numbers are a standard part of these pages. Always use a number from your card or the real website.

If it doesn't work

Clicked, page loaded, nothing entered

Cause: Usually a phishing page that needed input to achieve anything — Fix: Close it, check the imitated account for unexpected activity, and move on. Change the password if you are unsure.

Entered a password on the fake page

Cause: Credentials captured — Fix: From a different device, change that password and every reuse of it, enable two-factor, and sign out all sessions.

A file downloaded and opened

Cause: Possible malware execution — Fix: Disconnect from the network, run a full scan to completion, and change passwords from a different device afterwards.

Contacts report messages you did not send

Cause: Account taken over and being used to spread the same message — Fix: Change the password, sign out everywhere, check for forwarding rules and altered recovery details, then tell your contacts.

Questions people ask

Is it dangerous just to click a phishing link?

Usually not on its own — most phishing needs you to enter something or run a download. Close the page, enter nothing, and check the account it was imitating.

What should I do first after entering a password on a fake site?

Change that password from a different, trusted device, and change it anywhere you reused it. Then turn on two-factor authentication and sign out all other sessions.

Written and maintained by the GuideHQ editorial team. More in Technology.