loading...
Clicked something you shouldn't have? Don't panic. The first 60 minutes matter most — here's exactly what to do, in order.
Five calm, ordered actions to limit damage, plus how to walk a parent or grandparent through it on the phone.
193K+ — Phishing complaints filed with the FBI in 2024 (FBI IC3, 2024)
60 min — The window that matters most after a click
43% — Of people who think they can spot a scam still got caught (F-Secure, 2025)
A phishing link is a fake web address a scammer sends hoping you'll tap it. It looks like it leads somewhere you trust. Your bank, Netflix, the post office.
It doesn't.
Instead it drops you on a copycat website built to grab your password or card number, or it quietly tries to load harmful software onto your device. That's the whole trick. A real-looking door with a thief waiting behind it.
Most people have never seen a phishing link pulled apart next to the real thing. So here's one. Look at the web address, not the friendly text sitting on top of it.
Real link: https://www.netflix.com/account — Single "l" in netflix, ends in .com, no extra words.
Phishing link: https://netfllix-billing.com/login — Doubled "l", glued to -billing, and the real domain never lives before a dash.
See the doubled letter and the odd ending? That's the tell. Scammers can copy a logo perfectly, but they can't use the real company's actual web address, so they get close and hope you don't squint. If you want the full breakdown, here's our guide on how to spot phishing links.
Okay. Deep breath. Knowing what to do if you clicked a phishing link is mostly about moving in the right order during the first hour. These steps work whether you're doing them yourself or walking your mom through them over the phone. Go top to bottom. Don't skip.
If the link opened a page asking you to log in, pay, or "confirm" your details, close it. Don't enter a single thing. A surprising amount of the time, clicking by itself does nothing at all. The damage usually starts the moment you hand over information.
Glance at the address bar before you go. If it says something almost-but-not-quite right (paypa1.com instead of paypal.com), you've confirmed it's fake. Close the tab. Don't "just check" anything on that page.
If a download started, or the page tried to install something, cut the connection. Some phishing links try to load harmful software (the kind called malware) that quietly phones home to the scammer. No internet, no phone call. It buys you time to clean up before anything ships your data out the door.
On a phone: Turn on Airplane mode (ON). On a computer: Switch off Wi-Fi (OFF).
This is the step people skip because it feels dramatic. It isn't. Thirty seconds offline is a lot cheaper than a drained account.
Run your security software and let it do a full scan. Most phones and computers already have something built in, and a free, well-known scanner does the job if yours doesn't. The point is to catch anything that may have slipped on while the page was open.
If you entered a password on that fake page, change it right now on the real site. Type the real web address yourself. Don't click any link from the message. And if you reuse that password anywhere else (most of us do, no judgment), change it there too. Scammers count on the reuse. One stolen password becomes five hijacked accounts.
While you're in there, switch on two-step login (sometimes called two-factor authentication). It sends a code to your phone before anyone can get in, so a stolen password alone isn't enough. It's the best ten-minute upgrade you can make today.
Did you enter card details or bank logins, or send a payment? Call your bank now. Use the number on the back of your card, not one from the message. Tell them what happened. They can freeze the card, watch for strange charges, and send a new one, usually in minutes.
If you handed over something bigger, like a Social Security number, ask the bank about a fraud alert and consider freezing your credit so nobody can open accounts in your name. None of this means you've lost money yet. It means you're closing doors before anyone walks through them.
Here's a question we get a lot. "Can I just check a link before I click it?" Yes. And it's a great habit, especially for anything that lands in your inbox out of the blue.
A phishing link online checker lets you paste a suspicious web address into a box and get a read on whether it's dodgy before you ever open it. Newer AI tools for phishing link analysis go further, scanning the wording of the whole message for the pushy, panicky language scammers love. They're not perfect. Treat them as a smart second opinion, not a guarantee.
A phishing link is never the goal. It's the doorway. What's behind it is your money, your logins, or your identity, which scammers sell off or use to drain accounts and open new ones in your name.
Not because anyone's foolish. Because scammers deliberately target people with savings and a lifetime of trusting that a message from "the bank" is really the bank. The fix isn't fear. It's recognizing the patterns, which is exactly what our Scam prevention course for parents and grandparents was built to teach.
Maybe you didn't catch it in time. Maybe your dad typed the password, or the card number, and now he feels a bit sick about it. Tell him to stop right there. This happens to careful, smart people every single day. The link is built to fool him. That's its entire job.
A password Change it everywhere you used it, then turn on two-factor authentication.
Card or bank details Call your bank using the number on the back of your card.
A transfer or gift card Call your bank and the gift card company immediately — a fast call can sometimes stop a transfer before it lands.
A downloaded file or app Delete it, then run a full security scan again.
Reporting takes two minutes and helps shut these down for everyone else. Here's the short version.
Federal Trade Commission Plain form, no account needed. Every report feeds a database investigators use to go after scammers. (reportfraud.ftc.gov)
FBI Internet Crime Complaint Center File here if any money or personal information was involved. (ic3.gov)
The company being impersonated Most banks and big brands have a "report phishing" address. Forward the message there. (phishing@theircompany.com)
Inside your email app One tap on "Report phishing" teaches the filter to block the next one. (Gmail · Outlook · Apple Mail)
Want the longer walkthrough with screenshots? Here's our full guide on How to report phishing emails.
Clicking a bad link doesn't make you a target. It makes you human. The people most at risk are the ones who never had this explained to them, so forward this to your mom before she needs it.