Skip to main content

What to do now

I clicked a phishing link: what to do now

Last checked

What matters is what happened after you clicked the phishing link: whether you typed something, downloaded something or allowed something. Go down the list in order and skip the steps that do not apply.

Do this now

  1. Close the page and type nothing more

    Close the tab or the app without filling in anything else, and do not use the page’s buttons.
  2. If something downloaded or installed, disconnect and scan

    Do not open the file. Disconnect the device from the internet, run a full antivirus scan, and do not sign in to your accounts from it until the scan comes back clean.
  3. If you entered card or bank details, call your bank

    Ask it to block the card and stop what can still be stopped. Find the number yourself, in your banking app, on your bank’s website or on the back of your card, never in the message. In the UK, 159 connects you to your bank.
  4. If you typed a password, change it from another device

    Change it on the real site, which you open yourself, from a device you trust, and on every account that uses the same password. The full checklist after a password typed on a phishing site.
  5. If you allowed notifications or an app, remove it

    • Notifications you accepted: on a computer, in Chrome, block the site in Settings › Privacy and security › Site Settings › Notifications. On an Android phone, turn notifications off for every site, so you do not open the page again: in Chrome, More › Settings › Site settings › Notifications, then turn off the setting at the top.
    • An app you let into your Google account: on the account’s linked apps page (see Google’s help), choose Access to your Google Account › the app › See details › Remove access › Confirm.
    • A profile installed on an iPhone: Settings › General › VPN & Device Management, then the profile, then Delete Profile; on a work phone, ask your IT team first.
  6. Watch your accounts for the next few weeks

    Look out for payments you did not make, sign-in alerts you did not trigger and messages your accounts sent without you.
  7. Report the message and the page

    The services below use reports to have phishing pages blocked or taken down. Keep the message until you have reported it.
On this page07

Check it with isMalicious

isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.

URL scanner

Copy the link from the message rather than opening it again, and paste it into the URL scanner. The report shows whether threat intelligence sources list the URL or its host.

What it does not mean
Not listed is not proof of safety: a new or targeted phishing page is often unlisted at first. And a listing tells you the link is known to be malicious, not what happened on your device.
  • Malicious URL database: the malicious and phishing URLs with enough threat intelligence for a report, shown as text, never as clickable links.

Report it

Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.

In the United States

In the United Kingdom

Wherever you are

Somewhere else? Report to your national police or your country’s cybercrime reporting service.

In France? The French version of this guide lists the French services.

How to spot the next one

  • The link text and the address it opens are different. On a computer, hover over the link and read the address before you click.
  • The address looks like the real one but is not: an extra word, a swapped letter, or the brand at the start of a longer address such as paypal.com.account-check.example.
  • The message pushes you to act now: an account about to be closed, a parcel held, a fine to pay today.
  • It asks you to sign in or pay through the link instead of the app or the site you normally use.

Questions

I only clicked the link and typed nothing. Am I at risk?

If you did not enter any information, download a file or install anything, the UK’s National Cyber Security Centre says further action is unlikely to be needed. Stay alert to unusual emails and account notifications for a while.

The link came from a friend’s account. What does that mean?

Their account has probably been hacked. Tell them through another channel, a call or a different app, so they can change their password and warn their contacts.

Should I reply to the message to say I know it is a scam?

No. A reply confirms that your address or number is in use. Report the message instead, then delete it.

Is the URL scanner enough to know whether a link is safe?

No. It tells you whether threat intelligence sources already list the link or its host. A new or targeted page is often unlisted at first, so treat any unexpected link that asks you to sign in or pay as suspicious, listed or not.

Sources

Free account

Keep checking with a free account

Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.

Create free account

No credit card required