I clicked a phishing link. What should I do?
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
The short answer
- If you only clicked and entered nothing, close the page. In almost all cases nothing further is required.
- If you entered a password, change it immediately - on that account first, then anywhere you reused it.
- If you approved a login prompt or read out a one-time code, someone may hold a live session. Sign out all devices as well as changing the password.
- If you entered card details, call your bank now. Card payments are among the few reversible ones.
- Speed matters more than thoroughness. A password changed within ten minutes usually ends the incident.
First, the reassurance most people actually need: clicking a link, on its own, is rarely the harmful step. On a reasonably current device, loading a page does not hand anything over. The damage comes from what happens after — typing something, approving something, or opening something.
So the right response depends on which of those you did. Find your situation.
If you only clicked and entered nothing
Close the tab. That is genuinely the whole response.
If you want additional reassurance, run a scan with the security software you already have, and make sure your browser and operating system are up to date. There is no need to change passwords, and no need to keep worrying about it.
If you entered a password
This is a real incident, and speed is what determines the outcome.
- Change the password on that account first. Go to the real site directly — type the address, do not use any link from the message.
- Change it anywhere you reused it. Be honest with yourself about how many places that is. Start with your email account, because email is the reset mechanism for everything else.
- Turn on two-factor authentication on the affected account and your email.
- Review recent activity — most services show recent sign-ins, devices and locations. Sign out anything you do not recognise.
A password changed within the first ten minutes usually ends the incident entirely.
If you approved a login prompt or read out a code
Treat this as more serious than a password alone, because it likely means someone completed a login rather than just collecting a secret.
Change the password, then — this is the step people miss — use the account's "sign out of all devices" or "revoke active sessions" option. Changing a password does not always terminate sessions that already exist, and a live session is what the attacker actually wanted.
Then check for changes they may have made to keep access:
- New forwarding rules or filters in your email
- Added recovery email addresses or phone numbers
- New authenticator apps or trusted devices
- Changed security questions
If you entered card details
Call your bank or card issuer now, using the number on the back of the card. Card payments are among the few genuinely reversible ones, and issuers handle this constantly — you will not be the first call today.
Ask them to block the card and issue a replacement. Then watch the account for small test transactions, which often precede larger ones.
If you downloaded or opened a file
Disconnect from the network, run a full scan with your security software, and change important passwords from a different device — if there is a keylogger on the affected machine, changing passwords on it hands over the new ones too.
If it is a work device, contact your IT team immediately rather than trying to resolve it yourself. Speed of disclosure matters more than looking careless, and IT teams greatly prefer an early report to a late one.
If you sent money
Contact your bank immediately — within hours, recall is sometimes possible for transfers. Report to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov in the US, or Action Fraud in the UK.
Recovery odds depend heavily on method:
| How you paid | Realistic chance of recovery |
|---|---|
| Credit or debit card | Good — chargeback rights apply |
| Bank transfer | Possible if reported within hours |
| Payment app to a stranger | Poor |
| Cryptocurrency | Very poor |
| Gift cards | Very poor, but report the numbers to the issuer anyway |
Reporting it, even if nothing happened
It takes under a minute and it is genuinely useful. UK: forward to report@phishing.gov.uk. US: ReportFraud.ftc.gov and ic3.gov. Also report inside your mail client, which improves filtering for everyone.
Research cited by the FTC found that only around 4.8% of people who experienced mass-market consumer fraud reported it to a government body or the BBB. Patterns get identified because people bother.
Afterwards
Once things are stable, the changes that stop a repeat are unglamorous and effective: a password manager so nothing is reused, two-factor authentication everywhere, and passkeys wherever they are offered — because a passkey cannot be handed to a fake site at all.
Make the checks automatic
Our drills rehearse the recognition step under realistic time pressure, which is where it actually has to work.
Try it freeFrequently asked questions
- What happens if you click a phishing link but do not enter anything?
- Usually nothing. On an updated device, visiting a page does not itself hand over credentials or install software — that requires you to type something, approve a prompt, or open a downloaded file. Close the tab, and if you want reassurance run a malware scan. There is no need to change passwords for a click alone.
- I entered my password on a phishing site. What now?
- Change that password immediately, starting with the affected account. Then change it anywhere else you used the same or a similar password, prioritising your email account. Enable two-factor authentication, then review recent sign-in activity for sessions you do not recognise and sign them out.
- I gave them the code from my phone. Is it too late?
- Not necessarily, but act now. A relayed one-time code gives an attacker a live session, which persists even after you change your password. Change the password and then use the account's "sign out all devices" or "revoke sessions" option — that step is what actually ends their access.
- Should I report a phishing attempt even if I did not fall for it?
- Yes, and it takes under a minute. In the UK forward it to report@phishing.gov.uk; in the US report to ReportFraud.ftc.gov and ic3.gov. Only a small fraction of fraud is ever reported, so patterns like the surge in fake toll texts are identified largely through this reporting.
Sources
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center (IC3), 2026
- Paying to get paid: gamified job scams drive record losses — Federal Trade Commission, 2024
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
How to identify a phishing email in under ten seconds
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
- Phishing
What is phishing? How it works, and how to recognise it
Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.
- Phishing
Phishing vs spear phishing: what's the difference?
Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.