I clicked a phishing link: what to do now

It happens to careful people too. What matters now is speed: most of the damage is prevented in the first hour. Find what happened below and follow those steps.

Updated 24 September 2026 · 5 min read

The short version

  • Only opened the page? Close it. The risk is usually low.
  • Typed a password? Change it now, everywhere you reused it, and turn on two-step sign-in.
  • Gave card or bank details? Call your bank on the number on your card.
  • At work? Tell IT straight away. Speed helps more than anything else.

You only opened the page

  • Close the tab. Do not type anything into it.
  • Make sure your browser and operating system are up to date, since that closes most of what a page alone could use.
  • Scan the link with the box below to see what the page was.

You typed a password

  1. Change the password now

    Open the real site by typing its address or using its app, never through the link. Choose a new password you have not used anywhere else.

  2. Change it wherever you reused it

    Scammers try the same email and password on other sites within hours.

  3. Turn on two-step sign-in

    An authenticator app or a security key stops most sign-ins with a stolen password.

  4. Sign out every other session

    Most services have a sign out everywhere or devices option in security settings.

  5. Check what may have been changed

    For email accounts, look for forwarding rules, filters, new recovery addresses or phone numbers, and connected apps you do not recognise, and remove them.

You gave a one-time code or approved a sign-in

Treat the account as taken over. Follow the password steps above immediately, sign out all sessions, and remove any unknown devices or security keys. If you cannot get in, use the service's account recovery page.

You entered card or bank details

  • Call your bank now, using the number on the back of your card or in its official app, and tell them what happened.
  • Block or freeze the card in the banking app if it offers that.
  • Watch your statements for the next weeks. Scammers often test with a small payment first.
  • Never share a code the bank sends you with anyone who calls you, including someone who says they are from the bank.

You downloaded or opened a file

  • Disconnect the device from the internet (Wi-Fi off, cable out).
  • Do not type passwords on that device until it has been checked.
  • At work, call IT now and leave the device as it is. At home, run a full scan with your security software.
  • If anything looks wrong afterwards, change important passwords from a different, clean device.

If it happened on a work account

Tell IT or security at once, even if you are not sure. They can reset access, block the site for everyone and check whether others received the same message. A quick report is worth far more than a perfect one, and no good security team blames the person who reports.

Report it

  • If you lost money, report it to the police and your bank.
  • Report the scam to your national cybersecurity authority. In Romania this is DNSC, on the 1911 phone line.
  • Report the email or text to your provider, which helps them block it for others.

Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.

Live product launcher
Paste a suspicious URL or domain, then continue in the live platform

Questions people ask

Can a phishing link hack my phone just by opening it?
It is rare on an up-to-date phone. Most phishing needs you to type something, approve something or install something. Keep your phone updated, and treat any unexpected request to install an app or profile as a red flag.
I changed my password. Am I safe now?
Mostly, if you also signed out other sessions, turned on two-step sign-in and checked for forwarding rules or new recovery details. Those are how attackers keep access after a password change.