oh HACK no!
oh HACK no!

loading...

Clicked a Phishing Link? Here's Exactly What to Do in the Next 60 Minutes

Clicked something you shouldn't have? Don't panic. The first 60 minutes matter most — here's exactly what to do, in order.

Five calm, ordered actions to limit damage, plus how to walk a parent or grandparent through it on the phone.

193K+ — Phishing complaints filed with the FBI in 2024 (FBI IC3, 2024)

60 min — The window that matters most after a click

43% — Of people who think they can spot a scam still got caught (F-Secure, 2025)

What Is a Phishing Link

A phishing link is a fake web address a scammer sends hoping you'll tap it. It looks like it leads somewhere you trust. Your bank, Netflix, the post office.

It doesn't.

Instead it drops you on a copycat website built to grab your password or card number, or it quietly tries to load harmful software onto your device. That's the whole trick. A real-looking door with a thief waiting behind it.

What a Phishing Link Looks Like

Most people have never seen a phishing link pulled apart next to the real thing. So here's one. Look at the web address, not the friendly text sitting on top of it.

Real link: https://www.netflix.com/account — Single "l" in netflix, ends in .com, no extra words.

Phishing link: https://netfllix-billing.com/login — Doubled "l", glued to -billing, and the real domain never lives before a dash.

See the doubled letter and the odd ending? That's the tell. Scammers can copy a logo perfectly, but they can't use the real company's actual web address, so they get close and hope you don't squint. If you want the full breakdown, here's our guide on how to spot phishing links.

What to Do If You Clicked a Phishing Link

Okay. Deep breath. Knowing what to do if you clicked a phishing link is mostly about moving in the right order during the first hour. These steps work whether you're doing them yourself or walking your mom through them over the phone. Go top to bottom. Don't skip.

Stop. Don't type anything.

If the link opened a page asking you to log in, pay, or "confirm" your details, close it. Don't enter a single thing. A surprising amount of the time, clicking by itself does nothing at all. The damage usually starts the moment you hand over information.

Glance at the address bar before you go. If it says something almost-but-not-quite right (paypa1.com instead of paypal.com), you've confirmed it's fake. Close the tab. Don't "just check" anything on that page.

Disconnect from the internet.

If a download started, or the page tried to install something, cut the connection. Some phishing links try to load harmful software (the kind called malware) that quietly phones home to the scammer. No internet, no phone call. It buys you time to clean up before anything ships your data out the door.

On a phone: Turn on Airplane mode (ON). On a computer: Switch off Wi-Fi (OFF).

This is the step people skip because it feels dramatic. It isn't. Thirty seconds offline is a lot cheaper than a drained account.

Scan your device.

Run your security software and let it do a full scan. Most phones and computers already have something built in, and a free, well-known scanner does the job if yours doesn't. The point is to catch anything that may have slipped on while the page was open.

Don't fall for the second scam. Don't download a "cleaner" that pops up promising to fix you. That's often the scam's second act.

Change the password on anything you touched.

If you entered a password on that fake page, change it right now on the real site. Type the real web address yourself. Don't click any link from the message. And if you reuse that password anywhere else (most of us do, no judgment), change it there too. Scammers count on the reuse. One stolen password becomes five hijacked accounts.

While you're in there, switch on two-step login (sometimes called two-factor authentication). It sends a code to your phone before anyone can get in, so a stolen password alone isn't enough. It's the best ten-minute upgrade you can make today.

Call your bank if money or cards were involved.

Did you enter card details or bank logins, or send a payment? Call your bank now. Use the number on the back of your card, not one from the message. Tell them what happened. They can freeze the card, watch for strange charges, and send a new one, usually in minutes.

If you handed over something bigger, like a Social Security number, ask the bank about a fraud alert and consider freezing your credit so nobody can open accounts in your name. None of this means you've lost money yet. It means you're closing doors before anyone walks through them.

Phishing Link Checkers: How to Check a Link Before You Click

Here's a question we get a lot. "Can I just check a link before I click it?" Yes. And it's a great habit, especially for anything that lands in your inbox out of the blue.

A phishing link online checker lets you paste a suspicious web address into a box and get a read on whether it's dodgy before you ever open it. Newer AI tools for phishing link analysis go further, scanning the wording of the whole message for the pushy, panicky language scammers love. They're not perfect. Treat them as a smart second opinion, not a guarantee.

Paste. Check. Breathe. Bookmark our Phishing email checker — built for exactly this. The real win is the habit: check first, click second.

What the Scammer Is Actually After

A phishing link is never the goal. It's the doorway. What's behind it is your money, your logins, or your identity, which scammers sell off or use to drain accounts and open new ones in your name.

$7.7B
Lost by Americans over 60 to online crime in 2025 — up 37% from the year before.
FBI IC3

Not because anyone's foolish. Because scammers deliberately target people with savings and a lifetime of trusting that a message from "the bank" is really the bank. The fix isn't fear. It's recognizing the patterns, which is exactly what our Scam prevention course for parents and grandparents was built to teach.

What to Do If You Already Entered Your Information

Maybe you didn't catch it in time. Maybe your dad typed the password, or the card number, and now he feels a bit sick about it. Tell him to stop right there. This happens to careful, smart people every single day. The link is built to fool him. That's its entire job.

A password Change it everywhere you used it, then turn on two-factor authentication.

Card or bank details Call your bank using the number on the back of your card.

A transfer or gift card Call your bank and the gift card company immediately — a fast call can sometimes stop a transfer before it lands.

A downloaded file or app Delete it, then run a full security scan again.

Tell someone. Out loud. Not because you did anything wrong, but because saying it out loud makes the next steps easier, and a second set of eyes catches what you'll miss while you're rattled.

How to Report a Phishing Link

Reporting takes two minutes and helps shut these down for everyone else. Here's the short version.

Federal Trade Commission Plain form, no account needed. Every report feeds a database investigators use to go after scammers. (reportfraud.ftc.gov)

FBI Internet Crime Complaint Center File here if any money or personal information was involved. (ic3.gov)

The company being impersonated Most banks and big brands have a "report phishing" address. Forward the message there. (phishing@theircompany.com)

Inside your email app One tap on "Report phishing" teaches the filter to block the next one. (Gmail · Outlook · Apple Mail)

Want the longer walkthrough with screenshots? Here's our full guide on How to report phishing emails.

Send This Before They Need It

Clicking a bad link doesn't make you a target. It makes you human. The people most at risk are the ones who never had this explained to them, so forward this to your mom before she needs it.

Want them to spot it before it ever gets clicked? Our 1-hour Scam-Savvy course turns these checks into instincts — built specifically for parents and grandparents. Gift it to someone you love