Skip to Main Content
Phishing

I clicked a phishing link. What should I do?

Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.

Subash Poudel4 min read

The short answer

  1. If you only clicked and entered nothing, close the page. In almost all cases nothing further is required.
  2. If you entered a password, change it immediately - on that account first, then anywhere you reused it.
  3. If you approved a login prompt or read out a one-time code, someone may hold a live session. Sign out all devices as well as changing the password.
  4. If you entered card details, call your bank now. Card payments are among the few reversible ones.
  5. Speed matters more than thoroughness. A password changed within ten minutes usually ends the incident.

First, the reassurance most people actually need: clicking a link, on its own, is rarely the harmful step. On a reasonably current device, loading a page does not hand anything over. The damage comes from what happens after — typing something, approving something, or opening something.

So the right response depends on which of those you did. Find your situation.

If you only clicked and entered nothing

Close the tab. That is genuinely the whole response.

If you want additional reassurance, run a scan with the security software you already have, and make sure your browser and operating system are up to date. There is no need to change passwords, and no need to keep worrying about it.

If you entered a password

This is a real incident, and speed is what determines the outcome.

  1. Change the password on that account first. Go to the real site directly — type the address, do not use any link from the message.
  2. Change it anywhere you reused it. Be honest with yourself about how many places that is. Start with your email account, because email is the reset mechanism for everything else.
  3. Turn on two-factor authentication on the affected account and your email.
  4. Review recent activity — most services show recent sign-ins, devices and locations. Sign out anything you do not recognise.

A password changed within the first ten minutes usually ends the incident entirely.

If you approved a login prompt or read out a code

Treat this as more serious than a password alone, because it likely means someone completed a login rather than just collecting a secret.

Change the password, then — this is the step people miss — use the account's "sign out of all devices" or "revoke active sessions" option. Changing a password does not always terminate sessions that already exist, and a live session is what the attacker actually wanted.

Then check for changes they may have made to keep access:

  • New forwarding rules or filters in your email
  • Added recovery email addresses or phone numbers
  • New authenticator apps or trusted devices
  • Changed security questions

If you entered card details

Call your bank or card issuer now, using the number on the back of the card. Card payments are among the few genuinely reversible ones, and issuers handle this constantly — you will not be the first call today.

Ask them to block the card and issue a replacement. Then watch the account for small test transactions, which often precede larger ones.

If you downloaded or opened a file

Disconnect from the network, run a full scan with your security software, and change important passwords from a different device — if there is a keylogger on the affected machine, changing passwords on it hands over the new ones too.

If it is a work device, contact your IT team immediately rather than trying to resolve it yourself. Speed of disclosure matters more than looking careless, and IT teams greatly prefer an early report to a late one.

If you sent money

Contact your bank immediately — within hours, recall is sometimes possible for transfers. Report to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov in the US, or Action Fraud in the UK.

Recovery odds depend heavily on method:

How you paidRealistic chance of recovery
Credit or debit cardGood — chargeback rights apply
Bank transferPossible if reported within hours
Payment app to a strangerPoor
CryptocurrencyVery poor
Gift cardsVery poor, but report the numbers to the issuer anyway

Reporting it, even if nothing happened

It takes under a minute and it is genuinely useful. UK: forward to report@phishing.gov.uk. US: ReportFraud.ftc.gov and ic3.gov. Also report inside your mail client, which improves filtering for everyone.

Research cited by the FTC found that only around 4.8% of people who experienced mass-market consumer fraud reported it to a government body or the BBB. Patterns get identified because people bother.

Afterwards

Once things are stable, the changes that stop a repeat are unglamorous and effective: a password manager so nothing is reused, two-factor authentication everywhere, and passkeys wherever they are offered — because a passkey cannot be handed to a fake site at all.

Make the checks automatic

Our drills rehearse the recognition step under realistic time pressure, which is where it actually has to work.

Try it free

Frequently asked questions

What happens if you click a phishing link but do not enter anything?
Usually nothing. On an updated device, visiting a page does not itself hand over credentials or install software — that requires you to type something, approve a prompt, or open a downloaded file. Close the tab, and if you want reassurance run a malware scan. There is no need to change passwords for a click alone.
I entered my password on a phishing site. What now?
Change that password immediately, starting with the affected account. Then change it anywhere else you used the same or a similar password, prioritising your email account. Enable two-factor authentication, then review recent sign-in activity for sessions you do not recognise and sign them out.
I gave them the code from my phone. Is it too late?
Not necessarily, but act now. A relayed one-time code gives an attacker a live session, which persists even after you change your password. Change the password and then use the account's "sign out all devices" or "revoke sessions" option — that step is what actually ends their access.
Should I report a phishing attempt even if I did not fall for it?
Yes, and it takes under a minute. In the UK forward it to report@phishing.gov.uk; in the US report to ReportFraud.ftc.gov and ic3.gov. Only a small fraction of fraud is ever reported, so patterns like the surge in fake toll texts are identified largely through this reporting.

Sources

  1. 2025 Internet Crime Report FBI Internet Crime Complaint Center (IC3), 2026
  2. Paying to get paid: gamified job scams drive record losses Federal Trade Commission, 2024

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.