Respond to the action, not just the click
Clicked a Phishing Link? What to Do Next
What to do after clicking a phishing link depends on what happened next: whether you only opened the page, entered credentials, downloaded a file, approved MFA or shared financial information.
'I clicked it' is not one incident. Opening a page, typing a password, downloading a file and approving a login request create different risks. The fastest useful response is to identify which action happened and contain that specific exposure.
Choose the response that matches what happened
| What happened | Main concern | Immediate priority |
|---|---|---|
| You only opened the page | Browser exploit or tracking is possible but credential theft has not been confirmed | Close it, update security software and investigate anything unusual |
| You entered a password | The attacker may now know the credential | Change that password from a trusted device and protect every account where it was reused |
| You approved MFA or a login prompt | An active session or attacker login may have been authorized | Review sessions/devices, sign out broadly and contact the provider if needed |
| You downloaded or opened a file | Malware may have executed or been stored | Update security software, run a scan and follow organizational incident procedures |
| You entered bank, card or identity data | Fraud or identity theft risk | Contact the relevant financial institution and use the appropriate identity-theft recovery process |
If you entered a password
- 1
Go to the real service independently
Do not use another link from the suspicious message. Open a known app, bookmark or typed address.
- 2
Change the exposed password
Use a new unique password that has not been used on another service.
- 3
Find every reused credential
If the same password was used elsewhere, assume those accounts are now candidates for credential stuffing and change them too.
- 4
Review active sessions and devices
Sign out sessions you do not recognize and, when practical, sign out all sessions before signing back in.
- 5
Check recovery and MFA settings
Confirm that recovery email, phone numbers and authentication methods still belong to you.
If you downloaded something
The FTC advises people who think a phishing link or attachment downloaded harmful software to update their security software, run a scan and remove anything identified as a problem. In a workplace, stop improvising and follow the organization's incident-response process because security teams may need device, log or mailbox evidence.
Do not assume that deleting the downloaded file reverses everything if you already opened or executed it. The relevant question is whether code ran or credentials were captured, not whether the file is still visible in Downloads.
If you shared financial or identity information
Contact the institution that can actually stop the consequence: the bank or card issuer for payment data, the service provider for account access, or the appropriate identity-theft service for government identifiers and broader identity exposure.
The FTC directs people who believe a scammer obtained sensitive identity or financial information to IdentityTheft.gov for steps tailored to the information lost. That is more useful than one generic checklist for every type of data.
After containment
- Report the phishing message through your provider or organization.
- Check the affected account for forwarding rules, changed recovery details and unfamiliar sessions.
- Warn contacts if the attacker may have sent messages from your account.
- Watch for follow-up scams that reference the original incident.
- Do not keep using an exposed password just because the phishing page later disappeared.
The click starts the investigation; the action after the click determines the response. Identify what you exposed, contain that exposure, then review the account or device for persistence.
Put this threat in context
Sources and further reading
Need a separate inbox for a short-lived interaction?
Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.
Create temporary email