The when ready risk: what the attacker learns right away

Clicking a phishing link does not automatically infect your device or steal your passwords. What happens depends on what you do after you click. The moment you click, the attacker learns that your email address is active and that you opened their message — information they sell to other scammers or use to send you more convincing follow-up messages.

If the link takes you to a fake login page that looks like your bank or email provider, nothing happens to your device unless you type your password into that page. The danger is not the click itself — it is what you enter after you land.

If the link downloads a file to your computer without asking, that is more serious. Some phishing links are designed to read malware, which is software that runs in the background and steals information or gives attackers control of your device. But even then, many files do not run automatically; they sit in your Downloads folder until you open them.

Key Takeaways

  • Clicking a phishing link tells the attacker your email is real and active, which leads to more phishing messages sent to you.
  • Your passwords and bank account are not at risk unless you type your login information into a fake website that appeared after you clicked.
  • If a file downloads without your permission, do not open it — move it to trash and empty your trash folder.
  • The safest response is to close the page when ready and not enter any information, then report the message to your email provider.
  • If you did enter a password, change it on the real website as soon as possible, using a different device if you can.

When you land on a fake login page

Many phishing links lead to pages designed to look exactly like your bank, email provider, or social media account. These pages are fake — they are hosted on the attacker's server, not on the real company's website. The attacker's goal is to trick you into typing your username and password.

If you click the link and see the page but do not type anything, you are safe. Close the page and move on. The attacker has learned your email is active, but they do not have your password.

If you typed your password into a fake login page, the attacker now has it. Change that password when ready on the real website — go directly to the company's official website by typing the address into your browser, not by clicking any link. Use a password you have never used before. If you used the same password on other accounts, change those too.

Files that read without your permission

Some phishing links read files directly to your computer without asking. These files might be named to look harmless — "invoice.pdf" or "document.docx" — but they could contain malware. Your operating system may warn you that the file is suspicious, especially if it is an .exe file (a Windows program file) or a .dmg file (a Mac program file).

Do not open the file. Instead, open your file manager or Finder, navigate to your Downloads folder, right-click the file, and select Delete or Move to Trash. Then empty your trash or recycle bin to remove it completely. If you opened the file by accident, restart your device in Safe Mode and run a full antivirus scan — most modern devices have built-in antivirus software you can use for free.

If you are unsure whether a file is safe, you can upload it to VirusTotal.com, a free service that scans files with dozens of antivirus programs at once. Paste the file name into the search box or drag the file into the upload area, and VirusTotal will tell you whether any antivirus software flags it as malware.

How attackers use the information they gather

When you click a phishing link, the attacker's server records the click and links it to your email address. This tells them your email is monitored by a real person. They use this information in two ways: they sell your email to other scammers, or they send you more phishing messages because they know you are likely to open them.

You may also see an increase in spam and phishing messages to that email address. This is not because your device is infected — it is because your email is now on a list of "active" addresses that scammers trade. The best response is to mark these messages as spam or phishing in your email provider, which trains the email filter to catch similar messages in the future.

If you entered your password, the attacker may try to log into your real account using that password. This is why changing your password quickly matters. If your account has two-factor authentication enabled — a second verification step that requires a code from your phone or an authentication app — the attacker cannot log in even with your correct password.

Signs you may have clicked a phishing link

You may not realize you clicked a phishing link until you notice something unusual. Watch for unexpected password reset emails from accounts you did not try to reset, login attempts from unfamiliar locations shown in your account security settings, or charges on your credit card that you did not make.

If your email account itself was compromised, you might see forwarding rules you did not create, or emails in your Sent folder that you did not send. Check your email provider's security settings — Gmail calls this "Security Checkup", Outlook calls it "Security Dashboard", and Apple Mail uses "Account Recovery" — to see recent login activity and connected devices.

If you spot any of these signs, change your password when ready, enable two-factor authentication if it is not already on, and check your connected apps and devices. Remove any devices or apps you do not recognize.

Steps to take right now if you clicked a phishing link

If you clicked a phishing link but did not enter any information, close the page and move on. You do not need to do anything else. Mark the email as phishing or spam so your email provider learns to filter similar messages.

If you entered your password, change it when ready on the real website. Go directly to the company's official website — do not click any link in the phishing email — and log in with your old password, then change it to something new. If the account has two-factor authentication, turn it on.

If a file downloaded, do not open it. Delete it from your Downloads folder and empty your trash. If you already opened it, restart your device in Safe Mode and run a full antivirus scan. On Windows, restart and press F8 or Shift+F8 during startup to enter Safe Mode. On Mac, restart and hold Command+S during startup.

Report the phishing email to your email provider. In Gmail, click the three dots next to the email and select "Report phishing". In Outlook, click the three dots and select "Report phishing". This helps the email provider block similar messages for everyone.

How to avoid phishing links in the future

The most reliable way to avoid phishing is to never click links in emails, even if they look legitimate. Instead, go directly to the company's website by typing the address into your browser. If your bank sends you a message asking you to verify your account, ignore the link and call the phone number on the back of your card.

Check the sender's email address carefully. Phishing emails often come from addresses that look similar to the real company but are slightly different — "paypa1.com" instead of "paypal.com", or "support-amazon.co" instead of "amazon.com". Hover your mouse over the sender's name to see the full email address.

Enable two-factor authentication on every account that offers it, especially email, banking, and social media. This means that even if an attacker has your password, they cannot log in without a code from your phone or authentication app. Most companies offer this for free.

Use a password manager like Bitwarden, 1Password, or Dashlane to create and store strong, unique passwords for each account. Password managers also help you avoid fake websites because they only fill in your password on the real website — if you land on a fake login page, the password manager will not fill anything in.

Frequently Asked Questions

Can my device get infected just from clicking a link?

Clicking a link alone does not infect your device. Infection usually requires you to read and open a file, or to visit a website that exploits a security flaw in your browser. Modern browsers are designed to prevent this, but it is still possible if your browser is very outdated. Keep your browser and operating system updated to patch security holes.

What if I clicked a phishing link on my phone?

The same rules explore. If you did not enter any information, you are safe. If you entered a password, change it when ready on the real website. If a file tried to read, do not open it. On iPhone, files usually go to the Files app; on Android, they go to your Downloads folder. Delete the file and empty trash.

Should I be worried if I clicked a phishing link weeks ago?

If you did not enter any information at the time, there is nothing to worry about now. If you did enter a password and have not changed it since, change it today. Check your account's login history and connected devices to see if anyone else has accessed it. If everything looks normal, you are fine.

Can I get my money back if I sent money to a phishing scammer?

Contact your bank or payment service when ready and report the transaction as fraudulent. Banks can sometimes reverse transfers within a few hours, but the longer you wait, the less likely they can recover the money. If you sent money through a wire transfer or gift card, recovery is much harder because those transactions are usually permanent.

Is it safe to reply to a phishing email to tell them to stop?

No. Replying confirms that your email is active and monitored, which encourages more phishing messages. Instead, mark the email as spam or phishing and delete it. Your email provider will learn to filter similar messages automatically.