What To Do After a Scam

I Clicked a Phishing Link — What Should I Do?

Clicking a phishing link is usually recoverable — especially if you did not type anything on the page that opened. Work through these steps in order.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

If you clicked but did not enter anything, close the page, do not go back to it, and run a full antivirus scan — the risk is low. If you typed a password, card number, or verification code, act now: change that password from a different device, starting with your email account, turn on two-factor authentication, and call your bank if payment details were involved. If you downloaded or installed anything, disconnect the device from the internet and treat it as compromised until it has been scanned or checked by a professional.

Warning signs to look for

  • The page that opened asked you to log in, 'verify', or re-enter card details
  • A file downloaded automatically when the page loaded
  • You were prompted to install an app, extension, or 'security update'
  • A pop-up claimed your device was infected and gave a phone number to call
  • The page asked for a one-time code that had just been texted to you

First: work out what actually happened

The severity depends entirely on what you did after the click. Clicking alone rarely installs anything on an up-to-date phone or computer — most phishing links simply open a fake login page and wait for you to type. So ask yourself three questions: did I type anything, did anything download, and did I approve any prompt? The answers decide which of the sections below apply to you. If you are unsure whether you typed something, assume you did and follow the credential steps; it costs you a password change and nothing more.

If you only clicked and closed the page

Close the tab and do not return to it. Do not enter anything if the page is still open. Clear your browser's recent history for that site if you like, though it is not essential. Run a full scan with the security software you already have — Windows Security on Windows, or a reputable on-demand scanner such as Malwarebytes on either platform. Then keep an eye on your inbox for password-reset messages you did not request. In the great majority of these cases nothing further happens.

If you entered a password

Change that password immediately, and do it from a device you trust rather than the one you may have compromised. Start with your primary email account, because whoever controls your email can reset everything else. Then change the password on the account the fake page imitated, and anywhere else you reused the same password — reuse is what turns one stolen password into five stolen accounts. Turn on two-factor authentication as you go. Finally, check the account's security settings for unfamiliar devices, forwarding rules, or recovery addresses the attacker may have added.

If you entered card or bank details

Call your bank or card issuer using the number on the back of the card and tell them the details were entered on a phishing site. They can block the card, watch for fraudulent charges, and reissue it. Check recent transactions yourself, including small test charges of a dollar or two, which fraudsters use to confirm a card works. In the United States you can also place a free fraud alert or credit freeze with the three credit bureaus, and IdentityTheft.gov will generate a personalised recovery plan.

If you entered a one-time code

A verification code handed to a criminal usually means they were logging in at that exact moment. Change the password on that account straight away, sign out all other sessions from the account's security settings, and review any changes made to recovery phone numbers or email addresses. Then contact the company's fraud line. Remember for next time: no legitimate company will ever ask you to read out or type a code into a page they sent you a link to.

If something downloaded or installed

Disconnect the device from Wi-Fi and unplug any network cable, then run a full antivirus scan before reconnecting. Do not install any software the page recommended, and never call a phone number shown in a pop-up warning — those numbers lead to fake support operations. If the scan finds something it cannot remove, or you use the device for banking or work, take it to a trusted repair shop or your IT team rather than continuing to use it.

Then report it and watch for follow-ups

Report the message to the FTC at reportfraud.ftc.gov and forward it to reportphishing@apwg.org. Tell the impersonated company through their published fraud contact. Expect follow-up attempts: people who click once are often targeted again, sometimes by a 'recovery' scam offering to get your money back for a fee. If another suspicious message arrives, forward it to check@spamcheck.com before you touch it.

Frequently asked questions

Can clicking a link alone infect my phone?
It is uncommon. Phones and modern browsers are heavily sandboxed, and most phishing links simply load a fake page. Infection almost always requires you to approve an install or open a downloaded file. Keeping your operating system updated closes the rare exceptions.
How will I know if my information was actually used?
Watch for password-reset emails you did not request, logins from unfamiliar places in your account security page, small unexplained charges, mail or statements that stop arriving, and friends receiving odd messages from your address.
Should I factory-reset my device to be safe?
Usually not. A full antivirus scan and a round of password changes handle the overwhelming majority of cases. Reserve a reset for situations where scanning finds something it cannot remove or you granted someone remote access.
I clicked a link from my work email. What should I do?
Tell your IT or security team immediately, even if you think nothing happened. They can check whether credentials were used and contain the problem quickly. Reporting early is treated as good practice, not a mistake.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides