untrappable.Check

Clicked a phishing link? What to do next

Close the page and don’t go back to it. What to do next depends on what happened after the click: you only opened the page, you typed a password or code, you entered card or bank details, you shared personal information, or something downloaded. Find your situation below. If money may have moved, contact your bank or card issuer first.

Find what happened after you clicked

Pick every row that applies. If you’re not sure whether you typed or autofilled something, use the rows that could apply.

Scroll the table sideways to compare all columns.

What happened Do this first Then
Opened the page, entered nothing Close it. Don’t return to it to investigate. Update your security software and run a scan. Report the message.
Typed a password or one-time code Open the real site or app yourself and change that password, plus anywhere you reused it. Turn on two-factor authentication. If you can’t sign in, use the service’s account-recovery steps.
Entered card or bank details Call your card issuer or bank using the number on the back of your card. Ask about stopping charges and a replacement card. Watch your statements.
Shared your Social Security number or other ID details Go to IdentityTheft.gov for steps based on what you shared. Consider a free credit freeze.
Downloaded a file or installed an app Stop signing in to accounts on that device. Update security software, scan, remove what it finds, then change passwords.

Each row is explained below with the official source.

I clicked but didn’t enter anything

Close the tab and don’t reopen the link to see what it was. The FTC’s phishing guidance says that if you think you clicked a link or opened an attachment that downloaded harmful software, update your computer’s security software, run a scan, and remove anything it identifies as a problem.

If the message was about a package and your card might be involved, the U.S. Postal Inspection Service asks people who interacted with a scam link, even without pressing submit, to notify their financial institution.

Then report the message (see how to report it) and delete it. If you entered or autofilled anything, use the matching section below too.

I entered my password or a verification code

The FTC says that if scammers get your passwords or account numbers, they could get into your email, bank, or other accounts, or sell your information to other scammers.

If you can still sign in, the FTC’s recovery steps are to create a new, strong password for that account, change it anywhere else you used the same password, and turn on two-factor authentication. Open the site or app yourself; don’t use the link from the message.

If you can’t sign in, use the FTC’s hacked-account guide, which links to recovery pages for popular services. A shared one-time code may have approved a sign-in or payment, so contact the affected service, and your bank if money is involved. Our lost-account steps cover what to check after you get back in.

I entered my card or bank details

Call the bank or card issuer now. For a credit card, the FTC says to report it to the issuer immediately, using the number on the back of the card or the issuer’s app, and ask them to refund your money. For a debit card, report it to your bank or credit union the same way.

Ask whether the card should be replaced even if no charge has appeared yet. CISA also advises watching for any unexplained charges. Keep the message and any receipts. If you paid another way, see payment-specific steps.

I entered my Social Security number or other personal details

If you think a scammer has your Social Security, credit card, or bank account number, the FTC points you to IdentityTheft.gov, which gives steps based on the information exposed. To decide between a free credit freeze and a fraud alert, see credit freeze vs fraud alert. For a fuller identity checklist, use our identity-recovery guide.

I downloaded something or installed an app

The FTC’s malware guidance says to:

  1. Stop signing in to online accounts, such as shopping or banking, with your usernames, passwords, or other sensitive information.
  2. Update your security software so it has the latest protections.
  3. Run a security scan to remove the malware.
  4. Change your passwords and turn on two-factor authentication, in case the malware gave someone access to your accounts.

If someone is controlling the device remotely or you approved access to an account, follow the access section of our recovery guide.

Report the phishing message

Reporting won’t reverse a charge. Forwarding a text to 7726 helps your wireless provider spot and block similar messages. The FTC lists three routes:

If you lost money, the CISA guidance also suggests a police report.

What can happen after you click a phishing link

The FTC says phishing messages try to steal your passwords, account numbers, or Social Security numbers. With that information, scammers could get into your email, bank, or other accounts, or sell it to other scammers. Some links aim to install harmful software: the FTC also says scammers send phishing emails that trick you into clicking a link or opening an attachment that downloads malware.

A click alone doesn’t tell you what was exposed. That’s why the steps above depend on what you did next. If you still have the message, paste it into the checker to see which known pattern it matches.

Frequently asked

I clicked a phishing link on my phone but didn’t enter anything. Am I OK?
Close the page and don’t revisit it. The FTC says to update your security software, run a scan, and remove anything it flags if you think a link downloaded harmful software. If the message was about a payment or package, it’s reasonable to tell your bank or card issuer; the U.S. Postal Inspection Service asks people who interacted with a scam link to do that. Then report and delete the message.
I clicked a phishing link and entered my password. What now?
Open the real site or app yourself and change that password, then change it anywhere you reused it, and turn on two-factor authentication. If you can’t sign in, use the service’s official account-recovery process. If you also shared a one-time code, contact the service, and your bank if money is involved.
I clicked a link in a text and entered my card number. Should I cancel the card?
Call your card issuer using the number on the back of the card. The FTC says to report it right away and ask for a refund of any charges. Ask whether to replace the card even if nothing has been charged yet, and watch your statements.
Where do I report a phishing text or email?
Forward texts to 7726 (SPAM) or use your phone’s report-junk option. Forward emails to reportphishing@apwg.org. You can report either at ReportFraud.ftc.gov.

Sources

  1. 01How To Recognize and Avoid Phishing Scams— Federal Trade Commission
  2. 02What To Do if You Were Scammed— Federal Trade Commission
  3. 03How To Recognize, Remove, and Avoid Malware— Federal Trade Commission
  4. 04How To Recover Your Hacked Email or Social Media Account— Federal Trade Commission
  5. 05Avoiding Social Engineering and Phishing Attacks— Cybersecurity and Infrastructure Security Agency
  6. 06Smishing: Package Tracking Text Scams— U.S. Postal Inspection Service

Got a message like this?