Global information guide

What to Do After Clicking a Phishing Link

If you suspect a phishing link was clicked, take measured actions to limit exposure, check the device involved, and follow up on accounts and recovery options.

Local context: Credit reporting, consumer rights, record-retention periods, score displays, lending decisions, products, taxes, and consumer protections vary by country and provider. This content is general information, not legal, financial, tax, debt, credit, insurance, investment, or personalised advice. Check the process and terms that apply where you live.

Immediate steps to limit exposure

If you realize you clicked a suspicious link, pause and stop interacting with the message or site. Disconnect the device from the internet or turn off wireless connections to reduce ongoing communication, and close the browser or app. Avoid entering any additional information or credentials, and do not open downloads attached to the message. Use a separate, known-secure device to check whether account passwords or other personal details may have been entered on the compromised device.

If you entered login details or other sensitive data, use the secure device to change those passwords and to sign out active sessions where possible. Enable multi-factor authentication on affected accounts if that option exists. Contact any institutions that hold financial or sensitive accounts using their official contact channels to report the potential exposure and follow their guidance. Keep notes about what happened, when, and which accounts might be affected, since a clear record can help with later recovery steps.

Device- and incident-specific checklists

For desktop and laptop computers, run an up-to-date malware and antivirus scan and apply any available system and application updates. Remove unfamiliar browser extensions, clear temporary files, and review saved passwords in password managers and browsers; consider exporting and checking entries for unexpected changes. If a file was downloaded and opened, treat the device as potentially compromised: disconnect, back up important data if safe, and consider professional remediation or reinstalling the operating system if malicious activity is detected.

For mobile devices, check recently installed apps and app permissions, uninstall any that look suspicious, and update the device operating system and apps. Revoke third-party access tokens and remove linked devices or sessions via account settings where possible. For public or shared devices, sign out of all accounts, clear browsing data and saved passwords, and avoid reusing that device until you are confident it is secure. In all cases, changing passwords from a different, trusted device reduces the risk that new credentials will be captured.

Follow-up monitoring, reporting, and recovery

After addressing the immediate device concerns, review account activity and transaction histories for unusual entries and set account alerts for new sign-ins and payments. Document suspicious activity and contact institutions or service providers through official channels if you see irregular transactions. Consider reporting the phishing attempt to the platform where it occurred and to appropriate consumer protection or cybercrime reporting bodies in your area. Keeping clear records of communications and actions taken supports any dispute or recovery process.

To reduce future risk, adopt preventative practices: use unique passwords for each account, enable multi-factor authentication where available, update devices and applications regularly, and be cautious when following links or opening attachments. Consider using a reputable password manager to generate and store complex passwords, and review connected apps and devices periodically. If the incident is complex or if significant financial or identity impacts are evident, consider consulting a professional who specializes in digital security or identity recovery.

A practical next step

Review and update passwords from a separate trusted device, and list any accounts that may need additional monitoring or contact with providers.