← Back to all posts

What to Do If You Clicked a Phishing Link

If you clicked a phishing link, stop interacting with the page, tell whoever handles IT for your business, disconnect the device if anything downloaded, run a malware scan, and reset any passwords you entered. What you should do next depends on what happened after the click: a click alone, a download, and a typed password each call for different responses. Speed matters more than embarrassment.

Use this quick triage to see which steps below apply to you:

What happened Your priority
You clicked, saw a page, and closed it without typing anything Steps 1 and 3: report it internally and scan the device
A file downloaded, or the page told you to run a command Steps 1–3: disconnect and scan before doing anything else
You entered a username and password Steps 1, 3, and 4: scan, then reset that password everywhere it is reused
You entered payment details, banking logins, or your Social Security number Steps 1, 3, 4, and 5: include your bank and a credit freeze

1. Tell your IT contact immediately

If you have an IT team, or one person who handles IT for your business, tell them now. It can be embarrassing to admit you weren't paying close attention, but attackers count on that hesitation: the median time between a phishing click and credential misuse is measured in minutes to hours, not days. IT can force a password reset, revoke active sessions, and watch for suspicious sign-ins faster than you can work through it alone.

If you are the IT contact for your business, work through the rest of this list and keep notes on what you find. Times, screenshots, and the original message all help if you later need to involve your bank, your insurer, or law enforcement.

2. Disconnect the device if anything downloaded

If a file downloaded, an installer launched, or the page instructed you to copy and paste a command, disconnect the device from the internet: turn off Wi‑Fi or unplug the network cable. This limits malware's ability to fetch additional components or send data out. If a download is still in progress, interrupting it before it completes is preferred; if a file finished downloading, delete it without opening it.

Pages that instruct you to press keyboard shortcuts or paste a command into a terminal or the Windows Run dialog are a known attack pattern — see our write-up on fake CAPTCHA ClickFix attacks. If you ran a command like that, treat the device as compromised and get help before using it for anything sensitive.

If you only viewed a page and typed nothing, disconnecting is usually unnecessary — but the scan in the next step still is. A modern, updated browser makes silent drive-by infections uncommon, not impossible.

3. Run a malware scan

Scan the device you were using when you clicked, even if you didn't see anything download. Free options that cover most situations:

  • Windows: Microsoft Defender is built in. Run a full scan, or use Microsoft Defender Offline scan for suspected infections that resist removal. Microsoft's scanning instructions cover both.
  • A free second opinion: Malwarebytes and ESET Online Scanner both offer free on-demand scans that run alongside your existing antivirus. A second scanner is useful precisely because no single engine catches everything.
  • Mac: macOS checks apps with its built-in XProtect protections, as Apple's platform security guide describes, but offers no on-demand scan of an arbitrary file. Use a reputable third-party scanner if you downloaded something.
  • A specific downloaded file: if you want evidence about one file rather than the whole device, follow our guide to checking whether a downloaded file is safe before opening it.

Follow your security software's guidance if it finds something. Do not restore a quarantined file because a website insists the detection is a false positive.

4. Reset any passwords you entered

If the page asked you to sign in, assume the attacker has whatever you typed. Reset that password now, from a different device than the one you clicked on if you suspect malware. Change it everywhere you reused it — credential reuse is exactly what attackers test first. If the account offers an option to sign out all other sessions or devices, use it; a password change alone doesn't always end sessions the attacker already opened. If you're someone who has re-used passwords for multiple accounts, consider leveraging a password manager in the future.

Then confirm multi-factor authentication is enabled on the affected account and on your email account in particular. Email is the recovery path for everything else, which makes it the account attackers want most. MFA seriously inhibits an attacker's ability to use a stolen password — our guide to checking MFA coverage in Google Workspace and Microsoft 365 shows how to verify it across a whole team rather than one account at a time.

Watch the affected account for the next few weeks: unexpected password-reset emails, new mail-forwarding rules, and sign-in alerts from unfamiliar locations are all signs the credential is being used.

5. If financial or identity information is involved

If you entered payment card details, banking credentials, or personal identifiers such as a Social Security number:

  • Contact your bank or card issuer using the number on the back of your card — not a number from the suspicious page or any follow-up message. They can watch for fraud or reissue the card.
  • Consider a credit freeze with the three bureaus. The FTC's credit freeze guidance explains the process; freezes are free and don't affect your credit score.
  • Report identity theft at the FTC's IdentityTheft.gov if personal identifiers were exposed, and file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov — especially for business losses, where a fast IC3 report can sometimes help recover wire transfers.

6. Report the phish so it gets taken down

Reporting takes two minutes and protects the next target. Report the message with your mail client's built-in phishing report button if it has one, and forward phishing emails to the Anti-Phishing Working Group at [email protected]. Phishing text messages can be forwarded to 7726 (SPAM) in the US. CISA's phishing guidance covers reporting channels in more detail.

Find out what the link actually did — without opening it again

Once the immediate response is done, the most useful thing you can learn is what the link was built to do, because that tells you whether you're finished or not. A credential-harvesting page means passwords were the target; a page that pushed a download means the device is the concern. Do not revisit the link in your browser to check.

Blue Lantern Security's free tools can gather that evidence for you:

Free accounts include 30 tool runs per day shared across the URL, email, and file analyzers. No credit card required.

Analyze the link free

Be ready before the next click

Someone in your business will click a phishing link again — across a whole team, that's a statistical certainty, not a character flaw. The difference between an incident and a near-miss is usually what was already in place before the click:

  • MFA coverage monitoring. MFA is the single control that most limits the damage of a stolen password, but coverage quietly erodes as people join, change roles, or enroll new devices. Identity monitoring flags accounts in Google Workspace or Microsoft 365 that are missing MFA before an attacker finds them.
  • Account takeover signals. Impossible-travel sign-ins, new mail-forwarding rules, and dormant accounts that suddenly wake up are the fingerprints of a credential being used by someone else. Continuous identity monitoring surfaces these without anyone writing detection rules — start by reviewing dormant accounts, which are a favorite quiet entry point.
  • Device monitoring. If a click does lead to a download, what matters is whether the device's defenses were actually on. Device monitoring reports on protection status across your team's machines — our device security posture report guide shows what that looks like in practice.
  • Email monitoring. Catching phishing before anyone clicks beats every step on this page. Email monitoring analyzes what lands in your team's inboxes so suspicious messages are flagged early.

All of it reports to one Monitoring Hub, priced per seat with no added cost per tool — built for teams of five to fifty without a security department. For the bigger picture, see how a small business can approach security.

Frequently asked questions

Can clicking a link infect my device by itself? It's uncommon with an up-to-date browser and operating system. Most phishing links lead to fake sign-in pages that need you to type something, or to downloads that need you to run them. Uncommon is not impossible, though — which is why the scan in step 3 applies even to a click with no download.

I clicked but didn't enter anything. Am I safe? Probably, after a clean malware scan. The click did confirm to the attacker that your address is live, so expect follow-up attempts and be pickier with that inbox for a while.

I clicked on my phone. Is that different? The same steps apply, but drive-by malware is rarer on phones. Prioritize the password resets if you typed anything, check for apps you didn't install, and keep the phone's OS updated.

How do I know if the link was actually malicious? Analyze it in isolation rather than guessing from the URL. The URL Threat Analyzer shows what the page does when it loads — redirects, downloads, and credential prompts — without your browser ever touching it again.