Recovery guide

What to Do After Clicking a Phishing Link

Prioritize the next step based on whether you entered information or downloaded a file.

Published 2026-09-28 · Reviewed 2026-09-29

Close the page and do not enter anything else. The right response depends on whether you only opened a page, entered information, gave a verification code, or downloaded a file. A click alone does not tell you that an account was taken over, but it is a reason to stop using the suspicious page.

If you only opened the page

Do not sign in, pay, or approve a prompt on that page. Open the organization’s real app or type a known address yourself to check the claim. Keep your device and browser updated. If a file downloaded or the page asked you to install something, treat that as the separate download situation below. The FTC recommends contacting the organization through a number or site you already know.

If you entered a password

Go directly to the real service through its app or a known address and change the password. Change it anywhere else you reused it. Turn on multi-factor authentication and review account activity or signed-in devices where the service offers those controls. If the password was for your email account, act quickly because email access can affect password resets for other accounts.

If you entered a one-time verification code or approved a sign-in request, tell the service’s official support team what happened. A password change alone may not end an active unauthorized session; ask the service about its account recovery and session controls.

If you entered payment or identity details

Contact your bank or card issuer through the number on your card, statement, or official app. Say exactly what you supplied and ask whether any transaction can be stopped or disputed and whether the account needs a new card or other protection. For identity information, use IdentityTheft.gov to get steps matched to the information exposed. The FTC’s scam-recovery guide separates actions by payment method.

If something downloaded

Do not open the file or install the app. If it already ran, update your device’s security software and run a scan; remove anything it flags. The FTC’s phishing guide describes this response. If the affected device belongs to your employer, report the incident to its support or security team using its normal channel.

Report and keep useful evidence

Save the original message and the page address if you can do so without reopening it. In the US, a phishing text can be forwarded to 7726 (SPAM); you can also report a suspected scam to ReportFraud.ftc.gov. Do not publish private account details or the suspicious link as a clickable recommendation. Use the recovery selector if you are unsure which situation applies.

Need a quick check? Explore the free tools. OfficialAreaCode cannot identify a caller or determine whether a message is safe.

← All guides