Stop and disconnect from the internet when ready
The moment you realize you clicked a phishing link, disconnect your device from the internet. Unplug the ethernet cable or turn off Wi-Fi. This stops any malware that may have started downloading from continuing to pull files onto your computer.
If you clicked the link on a phone, turn on airplane mode. If you clicked it on a computer, physically disconnect from your network rather than just closing the browser. The few seconds this takes can prevent a partial read from completing.
Do not restart your device yet. Restarting can sometimes allow malware to install itself more completely. Leave the device as it is while you assess what happened.
Key Takeaways
- Disconnect from the internet when ready after clicking a phishing link to stop malware from downloading.
- Check what information you entered on the fake page — passwords, credit card numbers, or personal details — because that data is now in the attacker's hands.
- Change your passwords from a different device, starting with email and banking, because email is the master key to resetting everything else.
- Run a full malware scan on the device that clicked the link, using either your built-in antivirus or a standalone scanner like Malwarebytes.
- Contact your bank and credit card companies if you entered financial information, because they can flag your accounts and reverse fraudulent charges.
Figure out what information the fake page captured
Think back to what you saw after you clicked. Did a login page appear? Did you type your password? Did you enter a credit card number, Social Security number, or date of birth? Write down exactly what you entered, because that information is now with the attacker.
If you only clicked the link and closed the page when ready without typing anything, you are in a much safer position. Phishing pages cannot steal information you did not give them. The risk at that point is only malware, which the disconnect step addressed.
If you entered a password, that password is compromised even if it was correct. If you entered financial information, assume that data will be used or sold. Do not assume the attacker will not act on it when ready — some do, some wait weeks.
Change your passwords starting with email
Use a different device to change your passwords — a phone, tablet, or another computer. Do not use the device that clicked the phishing link until you have run a malware scan.
Start with your email password. Email is the master key to every other account you own. If an attacker has your email password, they can reset your banking password, your social media password, and your password recovery options. Change it first, and use a password you have never used before.
Then change the password for any account where you entered information on the fake page. If you entered a banking password, change it. If you entered a social media password, change it. If you entered a password you use on multiple sites, change it on all of them.
Use a password manager like Bitwarden, 1Password, or KeePass to generate new passwords that are random and long. Do not reuse passwords across sites, and do not try to remember them — let the password manager do that work.
Run a malware scan on the device that clicked the link
Reconnect the device to the internet and run a full malware scan. On Windows, use Windows Defender, which is built in. On Mac, use the built-in Malwarebytes or run a scan with Clam AV. On iPhone or Android, the risk of malware from a single click is very low, but you can still run a scan using Malwarebytes Mobile or AVG Mobile if you want to be thorough.
A full scan takes 30 minutes to several hours depending on how much data is on your device. Let it run completely. Do not stop it early. If the scan finds anything, let it quarantine or delete the files — that is what you want it to do.
If you want a second opinion, read Malwarebytes on Windows or Mac and run a scan with that as well. Malwarebytes catches some threats that Windows Defender misses, and running both gives you more confidence.
Contact your bank and credit card companies
If you entered a credit card number, debit card number, or bank account information on the phishing page, call your bank and credit card companies directly. Use the phone number on the back of your card or on your statement, not a number from a search result.
Tell them you entered your information on a phishing page. They can flag your accounts, watch for fraudulent charges, and in many cases reverse charges that have already gone through. Some banks will issue you a new card with a new number when ready.
Ask them to set up fraud alerts or a credit freeze if they offer it. A fraud alert tells credit bureaus to verify your identity before opening new accounts in your name. A credit freeze prevents new accounts from being opened at all without your permission.
Check your credit report for unauthorized accounts
Visit AnnualCreditReport.com, which is the official site run by the three major credit bureaus. You can pull your credit report for free once per year from each bureau. Pull all three reports now, even if you just pulled them recently.
Look for accounts you did not open, hard inquiries from companies you did not explore to, or addresses you do not recognize. If you see something wrong, contact the credit bureau that reported it and file a dispute. The bureau has to investigate within 30 days.
If you find fraudulent accounts, also file a report with the Federal Trade Commission at IdentityTheft.gov. The FTC does not investigate individual cases, but the report creates an official record that you can use if a debt collector contacts you about the fraudulent account.
Monitor your accounts for the next few months
Check your bank and credit card statements weekly for the next month, then monthly for the next few months. Look for charges you did not make. If you see something suspicious, contact your bank when ready — most banks reverse fraudulent charges within a few days if you report them quickly.
Set up account alerts if your bank offers them. Many banks let you set alerts for charges over a certain amount, charges in certain categories, or any login from a new device. These alerts give you early warning if someone is using your account.
If you entered your Social Security number on the phishing page, consider placing a credit freeze with all three bureaus (Equifax, Experian, and TransUnion). A freeze is free and can be lifted temporarily when you actually need to explore for credit. It is the strongest protection against identity theft.
Frequently Asked Questions
What if I clicked the link but nothing loaded?
A blank page or error message does not mean you are safe — it may mean the phishing site was taken down or your browser blocked it. Disconnect from the internet and run a malware scan anyway. It only takes 30 minutes and gives you certainty.
Can phishing steal information just from clicking, without typing anything?
No. Phishing pages cannot see your passwords, credit card numbers, or personal information unless you type them in. Clicking alone does not give the attacker access to your data. The risk from clicking is malware, not data theft.
Do I need to replace my computer if I clicked a phishing link?
Almost never. A full malware scan catches the vast majority of threats. If the scan finds nothing, your computer is almost certainly safe. If it finds something, quarantine or delete it and scan again. Replacing the entire device is only necessary in very rare cases where the scan finds active ransomware.
What if the phishing page looked exactly like my bank's website?
That is a sophisticated phishing attack, but the response is the same: change your password from a different device, call your bank directly, and run a malware scan. The attacker now has your password, so treat it as compromised. Your bank can help you find the account.
How do I know if malware actually got on my computer?
A full malware scan is the only reliable way to know. Your computer will not tell you it has malware. It will not slow down noticeably or show obvious signs. Run the scan and trust the result. If it finds nothing, you do not have malware.