I Clicked a Phishing Link: What to Do Now
Clicked a phishing link by mistake? A calm, step-by-step fix: disconnect the device, scan for malware, change passwords from a clean phone, and report it.

Clicking a phishing link is usually recoverable, especially if you didn’t type anything or download a file. Move fast on three fronts: disconnect from the internet, scan the device for malware, and change the passwords for any account the page mentioned — ideally from a second device you trust. Work the list in order. If all you did was tap the link on an up-to-date iPhone or Android and then close it, with no login typed, no file opened, and no app installed, the realistic risk is low, because mobile systems will not install software without your say-so — so the password step below matters far more than the malware scan in that case.
First, cut the connection
Don’t type anything into the page, and don’t “log in to check.” Close the tab and disconnect: turn off Wi-Fi, unplug the ethernet cable, or switch a phone to airplane mode. That stops any file that slipped through from reaching the attacker or pulling down more. Treat the device as untrusted until it’s scanned.
Scan for malware
On Windows, the built-in Microsoft Defender handles this. Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan, and select Scan now. That option restarts your PC and scans before Windows loads, catching malware a normal scan misses. If it won’t run, start it in Safe Mode first. On Android, uninstall any app you were prompted to sideload, then run Play Protect.
Change passwords from a clean device
If the page asked for a login, assume that password is burned. Change it from a phone or computer you didn’t click on — start with your email, since it resets everything else, then banking and any site that reused the password. Turn on two-step verification wherever it’s offered. A good password manager makes unique logins painless, and it’s the moment to build stronger ones.
If you entered real details, report it
Typed a Social Security or card number? The FTC’s IdentityTheft.gov builds a recovery plan for what you lost, and your bank can flag the card. Then report the message itself:
| What you received | Where to send it |
|---|---|
| Phishing email | Forward to [email protected] |
| Phishing text | Forward to 7726 (SPAM) |
| Any scam attempt | Report at ReportFraud.ftc.gov |
Most “I clicked it” moments end with a clean scan and a couple of fresh passwords. Watch your bank and email for unfamiliar logins over the next few weeks, and if something looks off, change that password again from a safe device.
Common questions
I clicked the link but never typed anything or downloaded a file. Am I safe?
Very likely, yes. On a current iPhone or Android, opening a phishing page rarely installs anything on its own, because the system asks before it installs an app. Watch for anything the page prompted you to download or “allow,” and if you are unsure, run a scan and change the password for whatever account the page was imitating.
I entered my password but caught it right away. What now?
Change that password immediately from a different device you trust, starting with your email, and turn on two-factor verification or a passkey there. If you reused that same password anywhere else, change it on those accounts too, since attackers feed stolen email-and-password pairs into other sites automatically.
It happened on my work computer. Should I tell IT?
Yes, report it to your IT or security team right away rather than trying to quietly clean it up. They can check for account misuse, often have tools you do not, and would far rather hear about a click that turned out harmless than find out later. Do it even if you think nothing happened.
Do I need to factory reset my phone after clicking a link?
Almost never for a click alone. A reset is only worth considering if you installed an app or a configuration profile the page pushed on you, and even then, removing that item and running a security scan usually settles it.