Security Scams: how they work and what to do if you fall for one
I clicked a phishing link: what to do in the next ten minutes
A calm, ordered response to clicking a bad link: what actually happens at each stage, what to change first, and how to tell whether anything was really compromised.
The short answer
- If you clicked and closed the page without typing anything, the risk is low and you mainly need to close the tab and carry on.
- What decides the next hour is what you typed: a password, a one time code, card details, or an approval on a permission screen.
- Change the password and then end all sessions, because a password change on its own can leave an attacker signed in.
- An approved app permission survives a password change, so it has to be revoked separately in your account security settings.
- Check for mail forwarding rules, new recovery addresses and extra second factor methods; that is where quiet access hides.
- If a file downloaded and ran, disconnect that device and change passwords from a different one.
Start with what you typed, not with what you clicked. If you opened the link, saw the page and closed it without entering anything, you are very probably fine, and the rest of this is a ten minute check rather than an emergency. If you typed a password, entered a code, opened a downloaded file or approved a permission prompt, act now and work through the steps in order. Order matters more than speed here, because changing a password before you sign out the attacker's session can leave them signed in with the new one unaffected.
Find your case in this table
Find the line that describes you. If more than one applies, start with the most serious.
| What you did | What is actually at risk | First move | How urgent |
|---|---|---|---|
| Clicked, looked, closed | Very little; your address is now known to be live | Close the tab, decline session restore, block the site's notifications | No rush |
| Typed an email address only | More targeted messages later | Nothing technical; expect follow up attempts | No rush |
| Typed a password | That account, plus anywhere you reused it | Change the password, then sign out all sessions | Next few minutes |
| Typed a one time code | The account, probably right now | Assume they are already inside; revoke sessions and check recovery settings | Immediately |
| Opened a download or ran an installer | Everything stored on or typed into that device | Disconnect it from the network, then scan | Immediately |
| Approved an app or a permission screen | Ongoing access that a password change does not remove | Revoke the app in your account security settings | Next few minutes |
| Entered card details | The card, not the account | Call the number on the card, freeze or replace it | Within the hour |
If you only clicked the link
A web page that you merely load cannot read your files, see your other tabs or take your passwords. Attacks that infect a device purely from loading a page do exist, but they are rare, expensive, and mostly patched on software that is up to date. The overwhelming majority of phishing pages are just a form waiting for you to fill it in.
So do three small things and move on. Close the tab, and if the browser offers to restore your previous session later, decline it, or the page comes straight back. Check your downloads folder for anything that arrived without you asking. And if the site asked to send you notifications and you clicked allow, remove that permission in your browser settings, because a stream of fake alerts later is a common follow up.
The one real consequence is that whoever sent it now knows your address is live and that you engage with it. Expect more, and expect the next one to be better. Marking the message as phishing in your mail app helps a little.
If you typed a password
This is the common case, and it is recoverable if you move now. Do it in this order.
- If a file also downloaded or you were asked to install anything, use a different device for the rest of these steps. If all that happened was typing into a web form, the device you are on is fine.
- Go to the real service yourself. Type the address or open the app. Never use a link from the message, and if you search for the site, read the address before you trust the first result.
- Change the password to something new that is not a variation of the old one. Adding a digit does not help, because the attacker has the pattern.
- Find the option called sign out of all devices, sign out everywhere, or end all sessions, and use it. This is the step people skip, and it is the one that actually evicts an attacker who is already signed in.
- Check that a second factor is switched on, and that the methods listed are ones you recognize. If two-factor authentication was already on, the stolen password on its own is much less useful.
- Change the same password anywhere else you used it, starting with anything holding money. This is the step that turns one bad minute into a long week, and the reason is explained in why reusing one password is so expensive.
If you entered a code, approved a prompt or opened a file
A one time code
Modern phishing kits sit between you and the real site and use the code within seconds, so assume the sign in succeeded. Change the password and end all sessions in the same few minutes, then check whether the attacker added their own way back in: a new authenticator app, an extra phone number, a different recovery email, or a backup code set that you did not generate. Removing those matters as much as the password.
An approval or permission screen
If you approved a screen asking to let an app read your mail, your files or your contacts, that permission is a separate key. It keeps working after a password change and after you sign out every session, which is why it is a favorite. Open your account's security or privacy page, find the list called connected apps, third party access or app permissions, and remove anything you do not recognize. While you are there, delete any app specific passwords you did not create.
A downloaded file or installer
Disconnect that device from the network first: turn off wifi or unplug the cable. Then run a full scan with the security software already on the machine. Assume that anything saved in the browser on that device is gone, which includes saved logins and the cookies that keep you signed in, a risk covered in passwords saved in your browser. Change those passwords from a different device, not the affected one, and work through the fuller cleanup in how to clean an infected computer.
The checks that show whether someone got in
An attacker who reaches an inbox usually spends the first minute setting up quiet persistence, not reading your mail. These are the places to look, and most people never check any of them.
- Forwarding and filter rules. The classic move is a rule that forwards everything to an outside address, or one that deletes messages containing the word bank or invoice so you never see the alerts. Check both forwarding and filters.
- Recovery email and phone number. A changed recovery address locks you out later even after you fix the password.
- Sign in activity. Most large services list recent sessions with rough location and device. Unfamiliar entries are worth acting on; familiar ones are not proof of safety.
- The sent and deleted folders. Messages you did not send, especially to your own contacts, mean the account was used rather than just opened.
- On banking and shopping accounts. New saved payees, a changed delivery address, a changed phone number, or statements quietly switched to paperless.
If your password turned up in one of these attacks, it is worth finding out where else it has already circulated, which is what a breach lookup does; the method is in how to check whether your password has leaked.
Work accounts and phones
If it was a work account or a work device, tell your IT or security team now, before you finish your own cleanup. They can end sessions centrally, see from the logs what was actually accessed, and warn colleagues who got the same message. The only thing that makes this worse is delay, and reporting quickly is treated as the right behavior at any competent organization. Say plainly what you typed. Vague reports waste the first hour.
On a phone, tapping a phishing link is far less likely to install anything, because apps come from a store and pages are heavily restricted. The real phone risks are different: being walked through installing a configuration profile, being talked into sideloading an app, or simply typing your password into a convincing page. If you installed a profile or an app you did not go looking for, remove it, then change the passwords you used on that phone.
The next few weeks
Once the immediate steps are done, the job is monitoring rather than repair. Watch statements and account alerts for a few weeks, and treat an unexpected password reset email as a signal that someone is trying, not as spam. A stolen password is often sold before it is used, so a quiet fortnight does not mean nothing happened.
Two things are worth doing while it is fresh. Set up account recovery properly on the accounts that matter, so a future lockout is survivable; the details are in setting up account recovery before you need it. And if money moved, or you gave card or bank details and a payment followed, the clock is much shorter and the steps are in what to do in the first hour after sending money to a scammer.
One last thing. Clicking proves nothing about your judgment. These messages are built to arrive when you are busy and to look exactly like the ones you get every day, which is the whole point of how phishing gets past careful people. You noticed, and you are dealing with it, which is the part that actually decides the outcome.
Common questions
I clicked a phishing link but did not enter anything, am I hacked?
Almost certainly not. Loading a page does not give anyone your files or your passwords, and infections from simply visiting a site are rare on software that is up to date. Close the tab, decline any offer to restore the session, and check that nothing downloaded. The main consequence is that you will get more attempts.
Will changing my password kick the attacker out?
Not always on its own. Many services keep existing sign ins alive after a password change, so someone already inside stays inside. Use the sign out everywhere or end all sessions option straight after changing the password. If an app permission was granted, that has to be revoked separately too.
How long before a stolen password gets used?
It varies from minutes to months. Automated kits sometimes sign in within seconds of you typing, especially when a one time code was captured. Other credentials sit in a list and are sold on before anyone tries them. A quiet week is not evidence that nothing was taken, which is why the monitoring step matters.
Do I need to factory reset my phone or computer?
Rarely, and not for a click alone. A reset is worth considering if you ran an installer, gave someone remote access, or a scan keeps finding the same thing after removal. For most cases a full scan, removal of anything you did not install deliberately, and password changes from a clean device are enough.
Should I tell my bank?
Yes if you entered card or account details, or if the fake page was pretending to be your bank. Call the number printed on your card, not one from the message, and ask them to flag the account. If you only clicked a link with nothing typed, there is nothing for them to act on.