Skip to content
← All guides

Urgent Action

You Clicked a Suspicious Link — Now What?

Actions to take if you suspect you have clicked a potential phishing link.

5 min read

It happens. You were busy, distracted, or it just looked legit. You clicked a link and now you've got that sinking feeling. Let's sort this out — the faster you act, the less likely it is that anything serious happens.

## What this guide covers

- What to do right now depending on what happened after you clicked - How to check if any damage was done - How to clean up and protect yourself going forward

---

## Right Now (The Next 5 Minutes)

### 1. Don't interact with whatever opened

If a webpage opened, don't enter any information. Don't type your password, email, credit card details, or anything else. Just close the tab or browser window.

If it asked you to download something, don't open the download. If it asked for permission to access something on your phone or computer, don't grant it.

The click itself isn't always the problem — it's what happens after that matters.

### 2. Disconnect from the internet (if something downloaded or installed)

If something downloaded automatically, or if your device started acting strangely — disconnect from WiFi or turn on airplane mode. This limits the ability of any malicious software to send your data somewhere or spread to other devices on your network.

This is a precaution. It doesn't mean you're definitely infected. But it's better to be safe for the next few minutes while you figure out what happened.

### 3. Figure out which scenario you're in

Not all suspicious links are equal. Here's how to assess what actually happened:

**Scenario A: You clicked but didn't enter any information and nothing downloaded.** You're probably fine. Close the page, clear your browser history and cache, and run a security scan to be safe. Skip ahead to the "Clean Up" section below.

**Scenario B: You entered your login details (email, password, etc.)** Act now. Go directly to that service (not through the link you clicked) and change your password immediately. If you use that same password anywhere else, change it there too. Turn on two-factor authentication.

> **Need help with 2FA?** See our guide: *Set Up 2FA in 5 Minutes (And Why You Should)*

**Scenario C: You entered payment or financial information.** Call your bank or card provider immediately. Tell them what happened and ask them to freeze or monitor your card. You'll find the number on the back of your card or in your banking app.

**Scenario D: Something downloaded or installed.** Don't open the file. Run a full antivirus scan. If you don't have antivirus software, your operating system likely has a built-in option — Windows Defender on Windows, XProtect on Mac. If the scan finds something, follow its instructions to quarantine or remove it.

---

## Clean Up

### Clear your browser data

Go to your browser settings and clear your browsing history, cookies, and cache. This removes any tracking cookies or session data the suspicious site may have dropped.

### Run a security scan

Even if you think you're fine, run a scan on the device you used when you clicked the link. Think of it like checking the locks after a scare — it takes two minutes and gives you peace of mind.

### Check your accounts

Over the next few days, keep an eye on:

- Your email for any password reset requests you didn't make - Your bank and payment apps for unfamiliar transactions - Your social media accounts for messages you didn't send

If you spot anything strange, act on it immediately — change passwords, contact your bank, and secure the account.

---

## How to Spot These Links Next Time

You don't need to become a cybersecurity expert. Just slow down when you see:

- Emails or messages that create urgency — "Your account will be locked in 24 hours!" or "You have an unclaimed package" - Links where the URL doesn't quite match the real thing — like "amaz0n.com" or "paypa1-security.com" - Messages from people you know that seem out of character — their account may have been compromised - Anything asking you to "verify your identity" or "confirm your details" through a link

When in doubt, don't click the link. Go directly to the website by typing the address yourself.

> **Want to understand the bigger picture?** Read our guide: *How Phishing Scams Actually Work*

---

## Should You Report It?

If the link came in an email, you can usually report it as phishing directly in your email app. This helps protect other people from the same scam.

If you lost money or personal information, it's worth reporting to your local cyber or fraud authority.

> **Ready to report?** Visit our [Resources page] to find the right contacts for your country.

### It's not your fault

Phishing links are designed to fool people. They're crafted by professionals whose entire job is making you click. The fact that you're here taking action is what matters.

> **Hear from others who've dealt with this.** Visit our [Stories page] — you're not the only one.

---

*This guide is part of the StillOnline.org emergency series. Written in plain language for real people dealing with real situations.*

Need help reporting or recovering?

Find where to report cyber crime in your country and where to get support.

Get help

More guides