Skip to content
← All guides

Urgent Action

I clicked a suspicious link. What now?

What clicking actually does, what it does not do, and how to tell the difference between a scare and a real problem.

3 min read

First, the reassuring part: clicking a link is usually not the moment something goes wrong. What matters far more is what happened next.

Work out what actually happened

  1. If you only clicked and closed it, you are probably fine

    A page loading is rarely enough on its own. Watch your accounts for a few days, but do not panic.

  2. If you typed anything in, treat it as stolen

    Change that password immediately, and change it anywhere else you have used it. Assume they already have what you entered.

  3. If you downloaded or ran a file, scan the device

    Run a full scan with your usual security software. This is the path that leads to real trouble.

  4. If you approved a login prompt or entered a code, act now

    That is someone getting into an account in real time. Change the password and sign out of all sessions straight away.

  5. Check for new sign-ins

    Most services list recent activity in their security settings. Look for locations and devices you do not recognise.

What a link can and cannot do

The fear after clicking is usually much larger than the actual risk, so it helps to be precise about it.

  • A link can take you to a convincing fake page. This is by far the most common goal. It only works if you type something in.
  • A link can start a download. On a phone that still needs you to approve an install, and on a desktop it needs you to open the file.
  • A link can confirm your address is real, which means more attempts will follow.
  • A link can very rarely exploit an unpatched browser. This is why keeping your browser and phone updated matters more than almost any other habit.

How to recognise the next one

The message is usually built to make you act before you think. The reliable signals are not spelling mistakes, which have mostly disappeared:

  • It creates urgency. Your account will close, your parcel will be returned, your payment failed.
  • It arrives about something you were half expecting anyway, like a delivery.
  • The link text and the actual address do not match. Hold your finger on it, or hover, to see where it really goes.
  • It asks you to confirm something the real company already knows.
  • It moves you to a different channel, such as an email that asks you to continue on WhatsApp.
I clicked but did not enter anything. Am I safe?

Almost certainly. The page cannot take your password if you never typed it. Keep an eye on the account it referred to for a week or so, make sure your browser and operating system are up to date, and get on with your day.

It was a text about a parcel. How did they know I was expecting one?

They did not. These are sent to enormous lists of numbers at once, and at any given moment a decent share of people are expecting a delivery. It feels targeted because it landed at the right moment, but it is pure volume.

Should I reply to tell them to stop?

No. Replying confirms your number or address belongs to a real person who reads messages, which makes it more valuable and gets it used more. Block and report the sender instead.

Need to report this?

Where to report cyber crime in your country, and where to find support.

Get help

This happened to them too

First-hand accounts from people who went through the same thing.

Related guides