I clicked a phishing link: what to do now
It happens to careful people too. What matters now is speed: most of the damage is prevented in the first hour. Find what happened below and follow those steps.
The short version
- Only opened the page? Close it. The risk is usually low.
- Typed a password? Change it now, everywhere you reused it, and turn on two-step sign-in.
- Gave card or bank details? Call your bank on the number on your card.
- At work? Tell IT straight away. Speed helps more than anything else.
You only opened the page
- Close the tab. Do not type anything into it.
- Make sure your browser and operating system are up to date, since that closes most of what a page alone could use.
- Scan the link with the box below to see what the page was.
You typed a password
Change the password now
Open the real site by typing its address or using its app, never through the link. Choose a new password you have not used anywhere else.
Change it wherever you reused it
Scammers try the same email and password on other sites within hours.
Turn on two-step sign-in
An authenticator app or a security key stops most sign-ins with a stolen password.
Sign out every other session
Most services have a sign out everywhere or devices option in security settings.
Check what may have been changed
For email accounts, look for forwarding rules, filters, new recovery addresses or phone numbers, and connected apps you do not recognise, and remove them.
You gave a one-time code or approved a sign-in
Treat the account as taken over. Follow the password steps above immediately, sign out all sessions, and remove any unknown devices or security keys. If you cannot get in, use the service's account recovery page.
You entered card or bank details
- Call your bank now, using the number on the back of your card or in its official app, and tell them what happened.
- Block or freeze the card in the banking app if it offers that.
- Watch your statements for the next weeks. Scammers often test with a small payment first.
- Never share a code the bank sends you with anyone who calls you, including someone who says they are from the bank.
You downloaded or opened a file
- Disconnect the device from the internet (Wi-Fi off, cable out).
- Do not type passwords on that device until it has been checked.
- At work, call IT now and leave the device as it is. At home, run a full scan with your security software.
- If anything looks wrong afterwards, change important passwords from a different, clean device.
If it happened on a work account
Tell IT or security at once, even if you are not sure. They can reset access, block the site for everyone and check whether others received the same message. A quick report is worth far more than a perfect one, and no good security team blames the person who reports.
Report it
- If you lost money, report it to the police and your bank.
- Report the scam to your national cybersecurity authority. In Romania this is DNSC, on the 1911 phone line.
- Report the email or text to your provider, which helps them block it for others.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- Can a phishing link hack my phone just by opening it?
- It is rare on an up-to-date phone. Most phishing needs you to type something, approve something or install something. Keep your phone updated, and treat any unexpected request to install an app or profile as a red flag.
- I changed my password. Am I safe now?
- Mostly, if you also signed out other sessions, turned on two-step sign-in and checked for forwarding rules or new recovery details. Those are how attackers keep access after a password change.
More guides
The few settings that stop most account takeovers: a password manager, unique passwords, passkeys or two-step sign-in, and checking your recovery details.
A 30-second checklist for suspicious emails: the real sender, the pressure, the links, the attachments and the request. Plus what to do when you find one.
Eight quick checks to tell a real link from a phishing link: see the real address, read the domain the right way, spot lookalikes, and scan it for free.