Urgent Action
I clicked a suspicious link. What now?
What clicking actually does, what it does not do, and how to tell the difference between a scare and a real problem.
First, the reassuring part: clicking a link is usually not the moment something goes wrong. What matters far more is what happened next.
Work out what actually happened
If you only clicked and closed it, you are probably fine
A page loading is rarely enough on its own. Watch your accounts for a few days, but do not panic.
If you typed anything in, treat it as stolen
Change that password immediately, and change it anywhere else you have used it. Assume they already have what you entered.
If you downloaded or ran a file, scan the device
Run a full scan with your usual security software. This is the path that leads to real trouble.
If you approved a login prompt or entered a code, act now
That is someone getting into an account in real time. Change the password and sign out of all sessions straight away.
Check for new sign-ins
Most services list recent activity in their security settings. Look for locations and devices you do not recognise.
What a link can and cannot do
The fear after clicking is usually much larger than the actual risk, so it helps to be precise about it.
- A link can take you to a convincing fake page. This is by far the most common goal. It only works if you type something in.
- A link can start a download. On a phone that still needs you to approve an install, and on a desktop it needs you to open the file.
- A link can confirm your address is real, which means more attempts will follow.
- A link can very rarely exploit an unpatched browser. This is why keeping your browser and phone updated matters more than almost any other habit.
How to recognise the next one
The message is usually built to make you act before you think. The reliable signals are not spelling mistakes, which have mostly disappeared:
- It creates urgency. Your account will close, your parcel will be returned, your payment failed.
- It arrives about something you were half expecting anyway, like a delivery.
- The link text and the actual address do not match. Hold your finger on it, or hover, to see where it really goes.
- It asks you to confirm something the real company already knows.
- It moves you to a different channel, such as an email that asks you to continue on WhatsApp.
I clicked but did not enter anything. Am I safe?
Almost certainly. The page cannot take your password if you never typed it. Keep an eye on the account it referred to for a week or so, make sure your browser and operating system are up to date, and get on with your day.
It was a text about a parcel. How did they know I was expecting one?
They did not. These are sent to enormous lists of numbers at once, and at any given moment a decent share of people are expecting a delivery. It feels targeted because it landed at the right moment, but it is pure volume.
Should I reply to tell them to stop?
No. Replying confirms your number or address belongs to a real person who reads messages, which makes it more valuable and gets it used more. Block and report the sender instead.
This happened to them too
First-hand accounts from people who went through the same thing.
I lent my phone hotspot to a stranger at the airport
“I was sitting at Ngurah Rai airport in Bali, just killing time before my flight back. This guy walks up to me pretty…”
A fake alert inside my crypto app cost me $28,000
“I'm still reeling from this, but I need to get the story out there because it’s honestly terrifying how easily it…”
One dodgy download and someone was in my accounts by morning
“I’ll just come out and say it: I’m an idiot. I downloaded a file I knew was dodgy, and the internet gods punished me…”