Clicked a Phishing Link? Here's Exactly What to Do Right Now

Key Takeaways
It happens in a split second. You're scanning your inbox, a text message, or a social media feed, and you click. Then your stomach drops. Something feels wrong. Maybe the page that loaded looked off, maybe nothing happened at all, or maybe you realized mid-click that the sender wasn't who they claimed to be.
If you've just clicked a phishing link, here's the most important thing to know first: don't panic. Clicking a link alone doesn't always mean your device or accounts are instantly compromised. What you do in the next few minutes, however, makes all the difference.
This guide walks you through exactly what to do, step by step, so you can contain any potential damage fast.
What actually happens when you click a phishing link?
Before we get into the response steps, it helps to understand what's actually at risk.
Phishing links generally try to do one of three things:
- Steal your credentials by sending you to a fake login page that mimics a real site (your bank, Google, Microsoft, PayPal, etc.). If you enter your username and password, the attacker captures them instantly.
- Install malware by silently triggering a file download or exploiting a vulnerability in your browser, installing spyware, ransomware, or a keylogger on your device.
- Harvest your data because even without any interaction, a malicious page can collect your IP address, browser fingerprint, device type, and approximate location the moment it loads.
The severity depends on what you did after clicking. Did you just land on a page and immediately close it? Or did you enter information? Did something download? Your answers shape which steps below are most urgent for you.
Step 1: don't enter any information and close the tab immediately
If the phishing page is still open, stop interacting with it right now. Don't click any buttons, don't fill in any fields, and don't download anything it prompts you to.
Close the tab (or the entire browser if you're unsure). If a file download started automatically, don't open it.
The sooner you disengage from the page, the less exposure you have.
Step 2: disconnect from the internet
This step matters most if you suspect malware may have been deployed. For example, if a download happened automatically, or if your device started behaving unusually (pop-ups, slowness, webcam light flickering).
Disconnect your device from Wi-Fi or unplug your ethernet cable. This cuts off any active communication channel between your device and the attacker's server, stopping data from being exfiltrated in real time.
- On a phone: switch on Airplane Mode.
- On a laptop or desktop: turn off Wi-Fi or disconnect the cable.
You can reconnect once you've run a security scan (Step 4).
Step 3: check the URL carefully
Phishing sites are built to mimic real ones. Before you assume you're safe, look closely at the URL in your address bar:
- Is the domain spelled correctly? (e.g., `paypa1.com` vs. `paypal.com`)
- Is there an unexpected subdomain? (e.g., `paypal.com.verify-login.net`)
- Is the connection secure (`https://`) and is the certificate valid?
A site looking legitimate does not make it legitimate. Attackers invest in convincing fakes. If the URL looks suspicious in any way, treat it as confirmed malicious.
Step 4: run a full malware scan
Even if you didn't notice a file download, run a comprehensive security scan on your device immediately. Some drive-by downloads are silent. They exploit browser or OS vulnerabilities to install malware without any visible prompt.
Use a reputable security tool to scan your device thoroughly. Guardio works across your browser and phone, scanning for malicious pages in real time and alerting you before a phishing site can do damage, flagging threats the moment they appear.
If you're on a computer, also check your Downloads folder for any files you don't recognize and delete them before opening.
Step 5: change your passwords, starting with the most critical accounts
If there's any chance you entered credentials on the phishing page, or even if you didn't but the link was in an email tied to an important account, change your passwords now.
Prioritize in this order:
- Email accounts (attackers use email access to reset everything else)
- Banking and financial accounts
- Work accounts and corporate logins
- Social media accounts
- Any account that uses the same password as one you may have exposed
Use strong, unique passwords for each account. A password manager makes this far easier to manage. And don't reuse the compromised password anywhere.
Step 6: enable two-factor authentication (2FA) everywhere
If 2FA wasn't already enabled on your key accounts, now is the time. Even if an attacker captured your password, 2FA adds a second lock they can't bypass without physical access to your phone or authenticator app.
Enable 2FA on:
- Your email provider
- Your bank and financial apps
- Your work tools (Slack, Microsoft 365, Google Workspace, etc.)
- Social media platforms
Authenticator apps (like Google Authenticator or Authy) are more secure than SMS-based 2FA, though SMS is still better than nothing.
Step 7: check for suspicious account activity
Log into your key accounts from a clean, trusted device and look for signs of unauthorized access:
- Email: Check sent mail, forwarding rules, and any connected apps you don't recognize.
- Bank accounts: Review recent transactions for anything you didn't authorize.
- Social media: Check for posts, messages, or login sessions you didn't initiate.
- Work accounts: Alert your IT or security team. A compromised work login can expose your entire organization.
Many platforms list recent login activity with device type and location. If you see a session you don't recognize, terminate it immediately and change your password again.
Step 8: report the phishing link
Reporting isn't just about protecting yourself. It helps protect everyone else the attacker may target next.
Here's where to report:
- If it came via email: Use your email client's "Report Phishing" button, or forward it to reportphishing@apwg.org (the Anti-Phishing Working Group).
- If it came via text (smishing): Forward the message to 7726 (SPAM), which works across most US carriers.
- If it impersonated a real company: Go to that company's official website and report it through their fraud or security team.
- If you lost money or data: File a report with the FTC at reportfraud.ftc.gov or the FBI's IC3 at ic3.gov.
- In the workplace: Immediately notify your IT security team and follow your organization's incident response protocol.
Step 9: monitor your identity for the next several weeks
Phishing attacks don't always yield immediate, obvious results. Sometimes stolen credentials or personal data are held and used days, weeks, or even months later, sold on the dark web, used in credential stuffing attacks, or applied to identity fraud.
This is where ongoing monitoring becomes essential. Guardio's Identity Breach Monitoring continuously scans for your personal information across dark web databases and data breach leaks, alerting you the moment your email address, passwords, or personal data appear where they shouldn't. If your information surfaces after an incident, you'll know and you'll have time to act before serious damage is done.
Step 10: prevent it from happening again
Once the immediate crisis is handled, take a moment to close the door on future phishing attempts.
Technical protections:
- Install security protection that actively blocks malicious and phishing sites before they load. Guardio does this in real time, across your browser and phone.
- Enable your email provider's built-in phishing filters and review your spam settings.
- Keep your browser, OS, and apps fully updated. Patches close the vulnerabilities phishing links try to exploit.
Behavioral habits:
- Hover before you click. Always hover over a link to see the actual destination URL before clicking.
- Be suspicious of urgency. Phishing messages are designed to make you act fast before you think. "Your account will be closed in 24 hours" is a red flag, not a deadline.
- Verify unexpected requests. If a message asks you to log in, reset a password, or confirm payment, go directly to the company's official website instead of clicking the link.
- Don't trust display names alone. The sender's display name can say anything. Always check the actual email address behind it.
What if you're on a phone?
Phishing via SMS (smishing) and social media DMs is on the rise. The same core steps apply, but here are a few phone-specific notes:
- iPhone: iOS is generally more sandboxed, but credential phishing sites still work. If you didn't enter data and nothing downloaded, the risk is lower. Change passwords and enable 2FA on any accounts tied to the link.
- Android: Android is more susceptible to sideloaded malware. If you were prompted to install an app or "enable" something, run a security scan immediately and check your installed apps for anything unfamiliar.
- In both cases: report the SMS to 7726 and block the sender.
A quick reference: what to do after clicking a phishing link
Stay protected before the click, not just after
The best time to catch a phishing link is before you ever click it. Guardio works quietly in the background across your browser and phone, blocking malicious sites, neutralizing harmful downloads, and flagging suspicious pages in real time.
Phishing attacks are getting more convincing every year. According to the FBI's Internet Crime Complaint Center, phishing and spoofing were the number-one cybercrime by complaint volume in 2024. AI-generated emails, deepfake sender profiles, and lookalike domains are now standard tools in an attacker's arsenal. The gap between a real message and a fake one is shrinking fast.
Human instincts alone aren't enough anymore. A layer of automated, real-time protection running 24/7 across your browsing is no longer optional. It's essential.
Conclusion
Clicking a phishing link is more common than most people admit. Attackers are skilled at making their lures look legitimate, and with AI now generating polished, convincing attacks at scale, even cautious people get caught. What separates a near-miss from a serious incident is how fast you respond. Follow the steps above, change your credentials, notify the right people, and report the attack. Then use the moment as a prompt to lock down your digital security before the next attempt arrives.
Because there will be a next attempt. And now you'll be ready.
FAQs
What should I do first if I clicked a phishing link?
Close the tab immediately and stop interacting with the page. Don't enter any personal information, don't click any buttons on the page, and don't open any files that may have downloaded. If your device behaved strangely after clicking, disconnect from the internet right away.
Can clicking a phishing link infect my phone or computer without downloading anything?
Yes. Some phishing links exploit browser or operating system vulnerabilities to silently install malware the moment the page loads, without requiring any interaction. This is called a drive-by download. It's less common than credential-harvesting pages but is a real risk, especially on unpatched devices.
I clicked a phishing link but didn't enter anything. Am I safe?
Probably, but not guaranteed. If you didn't enter any information and nothing appeared to download, your risk is relatively low. That said, check your Downloads folder for unexpected files, monitor your device for unusual behavior, and run a security scan to be sure.
What if I entered my password on a phishing site?
Go to the real website immediately (type the URL directly, don't click another link) and change your password right away. Force a logout of all active sessions through the account's security settings. Enable two-factor authentication if you haven't already, and check for any other accounts that use the same password.
How do I report a phishing link?
Forward phishing emails to reportphishing@apwg.org or use your email client's built-in report button. For phishing texts, forward the message to 7726 (SPAM). If you lost money or data, file a report with the FTC at reportfraud.ftc.gov or the FBI's IC3 at ic3.gov.
Does clicking a phishing link on iPhone put me at risk?
iOS is more sandboxed than Android, which reduces (but doesn't eliminate) the risk of malware from a phishing link. The bigger threat on iPhone is credential phishing: fake login pages designed to steal your Apple ID, email, or banking passwords. If you didn't enter any data, the risk is low. If you did, change those passwords immediately.
How long after clicking a phishing link can damage occur?
Damage can happen within seconds if you entered credentials, since attackers often use automated tools to test stolen logins in real time. If your data was harvested without you noticing, it may be sold and used weeks or months later. This is why monitoring your accounts and identity in the weeks following an incident is important.
What's the difference between a fraud alert and a credit freeze?
A fraud alert tells lenders to verify your identity before opening new credit in your name and lasts one year. A credit freeze goes further, blocking all new credit applications entirely until you lift it. Both are free at Equifax, Experian, and TransUnion. If you shared financial or personal information with a phishing site, consider placing both.
Phishing ScamsOzempic Scams: Protect Your Wallet & Health from Fraud





