Inbox
Email security

Respond to the action, not just the click

Clicked a Phishing Link? What to Do Next

What to do after clicking a phishing link depends on what happened next: whether you only opened the page, entered credentials, downloaded a file, approved MFA or shared financial information.

9 min read

'I clicked it' is not one incident. Opening a page, typing a password, downloading a file and approving a login request create different risks. The fastest useful response is to identify which action happened and contain that specific exposure.

Choose the response that matches what happened

What happenedMain concernImmediate priority
You only opened the pageBrowser exploit or tracking is possible but credential theft has not been confirmedClose it, update security software and investigate anything unusual
You entered a passwordThe attacker may now know the credentialChange that password from a trusted device and protect every account where it was reused
You approved MFA or a login promptAn active session or attacker login may have been authorizedReview sessions/devices, sign out broadly and contact the provider if needed
You downloaded or opened a fileMalware may have executed or been storedUpdate security software, run a scan and follow organizational incident procedures
You entered bank, card or identity dataFraud or identity theft riskContact the relevant financial institution and use the appropriate identity-theft recovery process

If you entered a password

  1. 1

    Go to the real service independently

    Do not use another link from the suspicious message. Open a known app, bookmark or typed address.

  2. 2

    Change the exposed password

    Use a new unique password that has not been used on another service.

  3. 3

    Find every reused credential

    If the same password was used elsewhere, assume those accounts are now candidates for credential stuffing and change them too.

  4. 4

    Review active sessions and devices

    Sign out sessions you do not recognize and, when practical, sign out all sessions before signing back in.

  5. 5

    Check recovery and MFA settings

    Confirm that recovery email, phone numbers and authentication methods still belong to you.

If you downloaded something

The FTC advises people who think a phishing link or attachment downloaded harmful software to update their security software, run a scan and remove anything identified as a problem. In a workplace, stop improvising and follow the organization's incident-response process because security teams may need device, log or mailbox evidence.

Do not assume that deleting the downloaded file reverses everything if you already opened or executed it. The relevant question is whether code ran or credentials were captured, not whether the file is still visible in Downloads.

If you shared financial or identity information

Contact the institution that can actually stop the consequence: the bank or card issuer for payment data, the service provider for account access, or the appropriate identity-theft service for government identifiers and broader identity exposure.

The FTC directs people who believe a scammer obtained sensitive identity or financial information to IdentityTheft.gov for steps tailored to the information lost. That is more useful than one generic checklist for every type of data.

After containment

  • Report the phishing message through your provider or organization.
  • Check the affected account for forwarding rules, changed recovery details and unfamiliar sessions.
  • Warn contacts if the attacker may have sent messages from your account.
  • Watch for follow-up scams that reference the original incident.
  • Do not keep using an exposed password just because the phishing page later disappeared.

The click starts the investigation; the action after the click determines the response. Identify what you exposed, contain that exposure, then review the account or device for persistence.

Put this threat in context

Sources and further reading

Need a separate inbox for a short-lived interaction?

Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.

Create temporary email

Related security guides