10 Key Steps to Take Immediately After Clicking a Phishing Link
Clicking a phishing link is not the same as being compromised. What you do next depends entirely on what you did on the page , and one 2026 attack means changing your password won't help.
Clicking a phishing link is not the same thing as being compromised.
That distinction is where most advice goes wrong. Guides tell you to disconnect every device in the house, run scans for hours, and consider a factory reset, because that's the worst case, not the likely one. If you clicked a link, looked at a page that didn't load properly, and closed it, the honest answer is that there is probably nothing to do.
What you actually need to do depends on what happened after the click. Work that out first, then take the matching action. Everything below is organised around that.
First: what did you actually do?
- Just looked at the page, no forms filled in, nothing downloaded. There's very little to do. See step 1.
- Entered your password on the page, or a code from an authenticator app. See step 2.
- Entered card or banking details. See step 3.
- Downloaded or opened a file, or installed something. See step 4.
- Approved a permission or "sign in with…" request. See step 5, this one is different, and it's the newest attack in the set.
- Lost money already. See step 6.
1. If you only looked at the page
The UK's National Cyber Security Centre is direct about this: if you haven't entered personal information, downloaded files, or installed software, "it's unlikely you need to take further action."
Don't run a factory reset. Don't disconnect your household's internet. Do stay alert for a few weeks, watch for unexpected password-reset emails, login notifications, or messages referencing something the phishing page knew about you. If nothing arrives, nothing happened.
If the page prompted you to install a browser extension or download a "viewer" to see a document, that's not "just looking", go to step 4.
2. If you entered your password
Do these in order, because the order matters.
Change the password on that account immediately, and on any other account using the same password. Reuse is what turns one phished credential into ten compromised accounts.
Revoke active sessions. Changing a password often doesn't kick out a session the attacker already established. Most major services have a "sign out of all devices" or "active sessions" control in account security settings. Use it. Do this before you assume the password change was sufficient.
Turn on two-factor authentication, ideally a passkey or a hardware key rather than an app code.
That last point has changed and it matters. Codes from authenticator apps are phishable in real time: relay kits sit between you and the real site, pass your code through as you type it, and take the session that results. Microsoft profiled one such kit, Tycoon2FA, in March 2026, it didn't break anyone's authenticator app, it just relayed the code. A passkey or a FIDO2 key can't be relayed this way, because the credential is bound to the site's real domain. If you want the details, how to set up a YubiKey covers it, and why using a password manager matters covers getting your credentials unique in the first place.
Check your account's recent activity and login history for anything unfamiliar, and force a sign-out of anything you don't recognise.
3. If you entered card or banking details
Call your bank. Not email, not the app, call the number on the back of your card, and do it now. Fraudulent charges made minutes after a phished card number are the norm, not the exception.
Ask them to cancel the card and issue a new one, and to flag the account for unusual activity. If it's a payment service rather than a bank (PayPal, a crypto exchange) contact them through their own app or website, not through anything in the message you received.
Then watch your statements for anything you didn't authorise, and query it the moment it appears. Most banks have a window for disputing transactions that closes.
4. If you downloaded or opened a file
This is where scanning makes sense, and where the NCSC's advice is simply to run a full scan with your antivirus and let it clean up what it finds.
Two things the usual advice gets wrong:
- Don't back up the device to an external drive first. Attaching a drive to a machine that may be infected can let the malware spread to the backup. The common "back up before you scan" instruction has this backwards, if you have a recent backup already, you're covered; if you don't, don't create one from a suspect machine.
- A clean scan is not proof. Some malware evades detection, and a scan that finds nothing doesn't rule out a persistent implant. If you opened an executable from a phishing link, treat the machine as untrusted until you've verified it another way.
A factory reset is proportionate here, if the device is where you do banking, or it holds work credentials, reset it and restore from a backup you made before the incident. If you don't have one, that's the lesson to take away rather than a reason to plug a drive in now.
5. If you approved a permission or "sign in with…" request
This is the one where changing your password achieves nothing, and it's why the FBI issued a public alert about it in September 2026.
OAuth consent phishing doesn't need your password. The message links you to a genuine permission screen from a real provider (Google, Microsoft, or a communication platform) and asks you to authorise an application. If you approve, you've handed the attacker high-level access to your account. They can read your mail, watch your files, and keep doing it after you change your password, because they aren't logging in as you. They're an authorised application.
What to do:
- Revoke the application. In Google: Security → Third-party apps with account access. In Microsoft: Security → Permissions for apps and services. Find anything you don't recognise and remove it.
- Review the app's access before you revoke, so you know what was exposed.
- Then change your password if the same credentials were used elsewhere.
- Check for forwarding rules or filters you didn't create. A common follow-on is silent mail forwarding, which keeps working quietly long after the initial access.
If you want to know what the access looks like from the attacker's side, the IC3's alert on OAuth consent phishing is worth reading in full.
6. If you've already lost money
Report it. In the UK, that means your bank first, then Report Fraud (England, Wales and Northern Ireland) or Police Scotland. In the US, report to the FBI's Internet Crime Complaint Center at ic3.gov.
Do this even if the amount is small. These reports are what map the infrastructure and get domains taken down, and they're also what establishes your position if the loss grows.
Reporting the message itself
If you still have the phishing message, report it rather than deleting it. Forwarding a suspicious email to the NCSC's reporting service takes a minute, and it's one of the few consumer actions that measurably reduces scam volume, the NCSC can investigate and take down the domains involved.
If it arrived on a work device, tell your IT or security team before you do anything else. They may have other recipients to warn, and their incident process will likely supersede everything above.
What actually protects you next time
The steps above are damage control. The things that stop the next one working are less interesting and more effective:
- Use passkeys or hardware keys where you can. Phishing-resistant by design, and the only factor that survives a relay attack.
- Get your passwords unique. A password manager makes this automatic rather than a discipline problem.
- Know which account is your keystone. Your email account can reset almost everything else, so protect it best, a hardware key on your email account is worth more than two-factor on five others.
- Slow down on urgency. Every phishing message is engineered to make you act before you think. The single most effective control is noticing that pressure and pausing.
- Keep devices patched. Outdated endpoints are easier to compromise once a link is clicked. Keeping installed applications patched covers the habit.
If you're weighing up where your data lives, cloud storage and privacy is worth a read, where your backups live decides how bad a compromised device actually is.
The short version
Clicked a link and did nothing else? Probably nothing to do, and that's the honest answer most guides won't give you. Entered a password? Change it, revoke sessions, add a passkey. Entered card details? Call the bank. Opened a file? Scan, and don't back up to an external drive first. Approved a permission request? Revoke the app, a new password won't help.
Reporting matters more than it feels like it does, and passkeys are the only factor here that can't be relayed.