All guides

Clicked a phishing link? Do these 6 things right now

Take a breath. Clicking a phishing link is not automatically a disaster. In most cases, the click itself does not compromise your accounts or device. What matters is what happened in the seconds after you clicked — and what you do in the next few minutes.

This guide walks you through exactly that: triage, action steps, and how to make sure it never happens again.


First: what actually happened when you clicked?

Modern browsers and operating systems are built to contain threats. Simply landing on a malicious page rarely installs anything on its own. Real damage almost always requires you to take a further action — typing something, downloading something, or approving a prompt.

Ask yourself which of these branches fits your situation:

I just clicked, then closed the tab immediately. Low risk. Your device is very likely fine. Still run through steps 1 and 4 below, but don't panic.

I entered my password or username. High risk. Treat your credentials as compromised. Jump straight to step 2 and act fast — credential theft is the most common outcome of a phishing click.

I downloaded and opened a file. High risk. A downloaded file can run code. Step 4 — a malware scan — becomes your top priority alongside changing any passwords for accounts you accessed on that device.

I entered credit or debit card details. High risk. Contact your bank immediately (step 5) to freeze or monitor the card. Time matters here.

I approved an authentication prompt or gave an app permission. High risk. Attackers use "MFA fatigue" attacks and OAuth permission grants to take over accounts even without stealing your password. Go to your account's security settings and revoke any unfamiliar app permissions.

If you're still unsure what happened, work through all six steps in order. It takes under 20 minutes and covers every scenario.


The 6 steps to take right now

1. Disconnect from the page and don't enter anything else

Close the tab immediately if you haven't already. Do not go back to it, do not re-enter anything, and do not click any secondary pop-ups or "close" buttons inside the page itself — some phishing pages use those to trigger downloads.

If you are still on a page that feels suspicious, close the entire browser window rather than navigating away. On a phone, force-quit the app.

You do not need to disconnect your device from the internet. Phishing attacks rely on you providing information — they are not typically drive-by exploits that run silently in the background the moment a page loads.

2. Change the exposed password immediately — and everywhere it's reused

If you typed a password on the phishing site, assume that password is now in the hands of the attacker. Change it on the legitimate site right now, before finishing the rest of this list.

Then stop. Think about where else you use that same password. Every account that shares it is now vulnerable, because attackers run stolen credentials against dozens of popular sites automatically (this is called credential stuffing). Change the password on every reused account.

Use a unique, randomly generated password for each site. A password manager makes this practical.

3. Turn on two-factor authentication

Once you've changed the compromised password, enable two-factor authentication (2FA) on that account — and on any other important accounts that don't have it yet.

2FA means that even if an attacker has your new password tomorrow, they still cannot get in without your second factor. Use an authenticator app (like Google Authenticator or Authy) rather than SMS where possible — SMS codes can be intercepted, though they're still better than nothing.

4. Run a malware scan and watch your device's behavior

If you downloaded and opened a file from the phishing page, run a full malware scan with your security software. On Windows, Microsoft Defender (built-in) is a solid starting point. On Mac, Malwarebytes has a reputable free tier.

Even if you didn't download anything, keep an eye on your device for the next 48 hours:

  • Unexpected slowness or high CPU usage
  • New browser extensions or toolbars you didn't install
  • Password reset emails you didn't request
  • Unfamiliar login activity in your account history

If you see any of these, escalate — contact your IT team if this happened on a work device, or consider professional help.

5. Alert your bank if payment details were involved

If you entered a card number, expiry date, CVV, or banking credentials, call your bank or card provider now. Most have 24-hour fraud lines. Ask them to:

  • Flag the card for monitoring or issue a replacement
  • Review recent transactions for anything unfamiliar
  • Block any payments to unfamiliar merchants

Acting within hours dramatically increases the chance of stopping or reversing fraudulent charges. Don't wait until morning.

6. Report the phishing attempt

Reporting takes two minutes and genuinely helps protect others. Here's where to report:

  • Your email provider: Use the "Report phishing" button in Gmail, Outlook, or Apple Mail. This trains their filters to catch the same attack targeting others.
  • Your IT or security team (if this was a work account): They need to know so they can investigate whether others in your organisation were targeted.
  • The impersonated company: If the phishing email pretended to be from your bank, Netflix, PayPal, or any other brand, forward it to that company's abuse or security team (most publish a phishing report address, e.g. phishing@paypal.com). They can take action to get the site taken down.
  • National cybercrime agencies: In the US, report to the Anti-Phishing Working Group at reportphishing@apwg.org and forward the email to phishing-report@us-cert.gov. In the UK, use the National Cyber Security Centre's reporting tool.

A note if you clicked on your iPhone or Android

A lot of people search "clicked phishing link on iPhone" or "clicked phishing link on Android" in a panic. Here is the honest answer: modern mobile operating systems have strong sandboxing. A tap on a link — even a malicious one — very rarely results in automatic code execution or infection.

The real risk on mobile is identical to desktop: it's what you typed. Mobile screens are smaller, URLs are harder to inspect, and attackers know this — phishing sites are increasingly designed to look perfect on a phone. If you entered credentials or payment details on a mobile site, follow steps 2 and 5 above regardless of which device you used.

Factory resetting your phone after clicking a link (without downloading or installing anything) is almost never necessary. Save the factory reset for cases where you installed a suspicious app and cannot get it removed.


Prevention: check the link before you click next time

The single best way to avoid this situation is to verify a link before you open it on your real device.

Two options make this easy:

Learn to read the link first. Our safe link checker guide explains why static URL scanners miss brand-new phishing domains — and how to inspect a suspicious link safely instead. It takes minutes and costs nothing.

Open it in a browser that doesn't exist minutes from now. The Tempbrowser Analyzer opens the link inside a temporary cloud sandbox streamed to your screen. The page runs in an isolated environment — not on your device. When your session ends, the entire sandbox is wiped: no history, no cookies, no trace. If the page tries anything, it happens somewhere else entirely. The free plan requires no signup and no credit card — you get three launches per day, each up to 3 minutes. That's more than enough to inspect a suspicious link before deciding whether to trust it.

For more on evaluating suspicious links, see our guide: Is this link safe? How to check before you click.


FAQ

Can clicking a link alone hack my phone?

In almost all real-world cases, no. Clicking a link and loading a page does not by itself install malware or compromise your accounts. Sophisticated "zero-click" exploits exist but are rare, targeted, and quickly patched. The overwhelming majority of phishing attacks require you to enter something — a password, card number, or authentication code. If you clicked but typed nothing, your risk is very low.

What if I clicked but didn't enter anything?

You're most likely fine. Close the tab, run a quick malware scan if you downloaded any file, and keep an eye on your accounts for unusual activity over the next couple of days. No password changes are necessary unless you actually typed your credentials.

Should I factory reset after clicking a phishing link?

Almost certainly not — especially if all you did was click and close. Factory reset is a last resort for situations where a malicious app is installed and cannot be removed. For a phishing click where you didn't download or install anything, a factory reset would be massive overkill and would cause you to lose data unnecessarily.

How do I check a suspicious link without clicking it?

Two approaches work well. First, hover over the link (on desktop) to see the actual URL in your browser's status bar — look for misspellings of known brands or unusual domain extensions. Second, open it somewhere disposable: paste the URL into the Tempbrowser analyzer, where any malicious content runs in an isolated cloud environment that never touches your device. Our safe link checker guide explains why static scanners alone aren't enough.

What's the most common outcome after clicking a phishing link?

Credential theft is by far the most common outcome. Attackers build convincing fake login pages for banks, email providers, and popular apps, collect your username and password, then use those credentials immediately — often within minutes. This is why changing an exposed password fast is so critical.


If you're reading this after the fact, you now have a clear action list. Work through it in order, and you've done everything a reasonable person can do. Going forward, a two-second check before you click is all it takes to make phishing attacks dramatically less dangerous.

Open your next suspicious link safely — no signup needed: Tempbrowser Analyzer