What to Do If You Clicked a Phishing Link: A Step-by-Step Recovery Guide
A step-by-step recovery guide for deciding what to do after clicking a phishing link, based on what happened next.
Updated July 2026Reviewed by Editorial TeamEditorial review
If you clicked a phishing link, pause before doing anything else. A click by itself does not automatically mean your account is hacked or your device is infected. The risk depends on what happened after the link opened.
The most important thing right now is to stop interacting with the suspicious page, message, popup, download, or person behind it. Do not enter more information. Do not call a phone number shown on the page. Do not download a "security tool" or "cleaner" from the suspicious site.
If this involved a work account, work email, company device, bank account, payment, or identity document, keep the message or details if you can do so safely. You may need them for your employer, bank, provider, or a fraud report.
Use this guide as a recovery path. Start with what happened after the click, then follow the branch that applies to you.
1. Immediate Reassurance and First Priorities
In the first few minutes, your goal is not to investigate the scam. Your goal is to stop the incident from getting worse.
Do this first:
| First priority | What to do |
|---|---|
| Stop interacting | Close the page or tab. Do not click more buttons or links. |
| Do not enter information | Do not type passwords, codes, card numbers, addresses, or identity details. |
| Do not call suspicious numbers | If the page shows a support number, do not use it. Go to the real company website or app instead. |
| Do not install anything from the page | Fake security alerts often push unsafe downloads. |
| Check what happened next | Decide whether you only clicked, entered something, downloaded something, approved something, or exposed money/identity data. |
| Preserve evidence when relevant | If it involved work, money, identity theft, or a report, keep the message, sender details, URL, or screenshot if safe. |
Sources: CISA: Recognize and Report Phishing; FTC: How to Recognize and Avoid Phishing Scams; NCSC UK: Phishing Guidance.
This is not about blame. Phishing messages are designed to rush people, imitate trusted brands, and make normal decisions feel urgent. Even careful users can click a convincing link.
What matters now is the recovery branch. Someone who only opened a page needs different steps from someone who entered a password, approved a sign-in prompt, installed software, or shared bank details.
2. Determine What Actually Happened
Choose every situation that applies. One phishing incident can involve more than one branch. A phishing link can come from an email, text message, messaging app, social post, fake ad, or QR code.
| What happened after you clicked? | What it usually means | Where to focus |
|---|---|---|
| You only opened the page and closed it | Lower risk, but not zero risk | Browser/download checks, account alerts, reporting |
| You entered a username or password | The password should be treated as compromised | Account recovery |
| You entered a one-time code | The attacker may have used the code in real time | Account and MFA recovery |
| You approved a login prompt | You may have authorized an attacker sign-in | Account recovery and possible work escalation |
| You allowed an app to access your account | A connected app may have persistent access | App permission and account review |
| A file downloaded but you did not open it | The file could become risky if opened later | Delete it, scan if appropriate, update browser/device |
| You opened a file or installed software | Malware or remote access is possible | Device recovery and trusted scanning |
| You allowed browser notifications or permissions | The site may send fake alerts or use browser permissions | Browser cleanup |
| You entered card, bank, or payment details | Financial fraud is possible | Bank/card/payment provider contact |
| You entered SSN, National ID, date of birth, address, or uploaded ID | Identity theft or new-account fraud may be possible | Identity recovery and monitoring |
| It involved a work account or company device | The risk may affect your organization | Report to IT/security immediately |
If you are unsure, follow the safer branch. For example, if you typed a password and also downloaded a file, handle both account recovery and device checks.
Credential Theft Protection Guide
Browser Security Settings You Should Change
3. Assess the Level of Risk
Not all phishing clicks create the same risk. The safest recovery plan is based on what the attacker may have received or what changed on your device.
Lower concern: you only clicked
If the page opened, you closed it, and you did not enter information, approve a prompt, download/open a file, install software, or allow permissions, the risk is usually lower.
You should still check:
- whether a file downloaded;
- whether the browser asked for notifications or other permissions;
- whether any account sent a security alert;
- whether the message should be reported.
Do not ignore it, but you usually do not need to treat every account and device as fully compromised from a click alone.
Higher concern: you entered credentials, codes, or approved access
If you entered a password, treat that password as compromised.
If you entered a one-time code or approved a login prompt, treat the account as possibly accessed. Some phishing attacks work in real time: the fake page collects the code or approval while the attacker tries to sign in.
If you allowed an app to access your account, the risk can continue even if you change your password. That kind of permission, often called OAuth consent, may let an app access email, files, contacts, or account data until you revoke it.
Sources: CISA: Implementing Phishing-Resistant MFA; NIST SP 800-63B: Authentication and Lifecycle Management; Microsoft: Phishing-Resistant MFA; Microsoft: Protect Against Consent Phishing.
Higher concern: you opened a file or installed software
If a file only downloaded and you did not open it, the risk is different from running it.
If you opened an attachment, ran a file, installed an app, entered administrator credentials, or saw signs of remote access, device compromise becomes a higher priority. Malware, spyware, or remote-control tools can affect what you do next.
Higher concern: you entered payment or identity information
If you entered card details, bank credentials, or sent money, contact the bank, card issuer, or payment provider through a trusted channel.
If you entered sensitive identity information, such as an SSN, National ID, date of birth, address, passport, driver's license, or uploaded ID document, identity recovery may be needed. For US readers, official identity-theft resources such as IdentityTheft.gov, credit freezes, and fraud alerts may be relevant.
Sources: FTC: ReportFraud.gov; FTC: IdentityTheft.gov; FTC: Credit Freezes and Fraud Alerts; FBI IC3: Internet Crime Complaint Center.
Highest priority: work accounts and company devices
If the link involved a work email, work login, Microsoft 365 account, Google Workspace account, company device, or customer data, report it to your employer's IT or security team quickly. Do not delete evidence or run unsanctioned cleanup tools unless your organization tells you to.
Sources: CISA: Phishing Guidance; NCSC UK: Phishing Guidance.
4. Immediate Containment
Before changing passwords or scanning devices, contain the incident.
| Do | Do not |
|---|---|
| Close the suspicious page or tab. | Do not keep clicking around the suspicious site. |
| Use the real website, bookmark, or official app to access accounts. | Do not use links from the suspicious message. |
| Check whether anything downloaded. | Do not open suspicious files "just to see what they are." |
| Save the message if work, fraud, or reporting is involved. | Do not delete evidence before reporting a work or fraud incident. |
| Contact providers through known channels. | Do not call numbers shown on the phishing page. |
| Disconnect if active malware or remote access seems possible. | Do not disconnect by default if the urgent issue is account recovery. |
Disconnecting from the internet can help if you opened a suspicious program, installed software, saw a remote-control session, or believe malware is actively running. It can also be the right step for a work device if company policy says so.
But disconnecting is not always the first priority. If you entered your email password or bank login on a fake page, account recovery and provider contact may be more urgent than turning off Wi-Fi. If you suspect your device itself is compromised, use a different trusted device to change important passwords.
Once you have stopped the immediate interaction, secure any affected accounts.
5. Secure Affected Accounts
If you entered a password, code, approved a prompt, or allowed an app, focus on account recovery. Do not use the phishing link to reach the account. Type the real address, use a saved bookmark, or open the official app.
Sources: FTC: How to Recover Your Hacked Email or Social Media Account; Google Account Security Checkup; Apple: If You Think Your Apple Account Has Been Compromised; Microsoft: Help with the Microsoft Account Recovery Form.
If you entered your password
Treat the password as compromised, even if the account still looks normal.
Do this:
- Go to the real website or official app.
- Change the password.
- Sign out of other sessions or devices if the service offers that option.
- Review recent login activity.
- Check recovery email, recovery phone, security questions, and trusted devices.
- Remove anything unfamiliar.
- Change the same or similar password anywhere else you used it.
- Turn on MFA if it is not already enabled.
If the phished account is your email account, prioritize it. Email accounts are often used to reset passwords on banking, shopping, social, cloud, and work accounts.
How to Create a Strong Password
If you entered a one-time code
A one-time code, sometimes called a 2FA code or MFA code, can be used by an attacker if they are trying to sign in at the same time.
Do not assume the account is safe because you had MFA enabled. Take the same steps as a password compromise:
- change the password;
- sign out of other sessions where possible;
- review login activity;
- remove unfamiliar devices;
- reset or review MFA methods;
- generate new backup codes if the account uses them.
Where available, consider stronger, phishing-resistant options such as passkeys or security keys. These are designed to reduce the risk of entering a reusable code into a fake page.
Sources: CISA: Implementing Phishing-Resistant MFA; NIST SP 800-63B: Authentication and Lifecycle Management; Microsoft: Phishing-Resistant MFA.
Are Passkeys Safer Than Passwords
If you approved an MFA prompt
If you approved a sign-in prompt you did not start, treat it like a possible account access event. A push approval can authorize the attacker even if you did not type a code.
Change the password, sign out of other sessions, review devices, and check MFA settings. If this was a work account, report it to IT or security immediately. They may need to check logs, mailbox rules, or other activity you cannot see.
How to Protect Your Online Accounts
If you allowed an app to access your account
Some phishing links do not ask for your password. Instead, they ask you to allow an app to access your account. This is often called OAuth consent. In plain English, it means you gave an app permission to access something, such as your email, files, profile, or contacts.
If that happened:
- go to the real account settings page;
- look for connected apps, third-party apps, app permissions, or account access;
- remove any app you do not recognize or did not intend to approve;
- review recent account activity;
- check email forwarding rules and filters if the account is email-related;
- report suspicious app access to the provider or your workplace if relevant.
Changing your password may not remove every app permission. The permission itself needs to be revoked.
Sources: Microsoft: Protect Against Consent Phishing; Microsoft: Detect and Remediate Illicit Consent Grants.
If you reused the same password elsewhere
Attackers often try stolen passwords on other sites. If you reused the same password on email, banking, shopping, social media, cloud storage, or work accounts, change those passwords too.
Use a unique password for each account. A password manager can help create and store unique passwords, but it is a prevention tool, not a replacement for recovering a compromised account.
6. Check Devices and Browsers
Device checks matter most if something downloaded, opened, installed, or changed in your browser. A phishing link can lead to malware, but not every phishing link infects a device.
If a file downloaded but you did not open it
Do not open the file. Delete it from your downloads folder. Then check your browser download history and make sure there are no other suspicious files.
If your security software offers a scan, you can run one. Keep your browser and operating system updated. Downloaded-only is generally less concerning than opening, running, or installing the file, but removing it prevents a later mistake.
If you opened a file or installed software
If you opened an attachment, ran an installer, installed an app, or entered administrator credentials, treat the device as higher risk.
Do this:
- stop using the suspicious file or app;
- disconnect from the internet if you suspect active malware or remote access;
- run a scan with trusted security software;
- on Windows, consider Microsoft Defender tools, including offline scanning for harder-to-remove threats;
- on Android, review recently installed apps and use Play Protect;
- change important passwords from a different trusted device if you think this device may be compromised;
- contact IT or professional support for work devices or serious symptoms.
Do not download random "cleaner" tools from search results or from the suspicious page. One scan is helpful, but it is not a universal guarantee that every possible threat is gone.
Sources: Microsoft Defender Safety Scanner; Microsoft Defender Offline; Google Play Protect.
If browser notifications or permissions were allowed
Some scam sites ask to send notifications. If you allow them, they can keep showing fake alerts even after you leave the site. That can look like a device infection when it is actually a browser permission problem.
Check your browser's site permissions and remove the suspicious site from notifications. Also review permissions such as camera, microphone, location, popups, and downloads if the browser asked for them. This applies across major browsers, although the exact menu names differ.
Sources: Google Chrome: Change Site Settings Permissions; Google Chrome: Change Notifications Settings; Microsoft Edge: Manage Website Notifications; Apple: About Pop-Ups and Fraudulent Website Warnings in Safari; Mozilla Firefox: Phishing and Malware Protection.
Browser Security Settings You Should Change
Windows
If you only opened a web page, start with browser checks, account security, downloads, and updates.
If you opened or ran a file, use trusted Windows security tools. Microsoft Defender Safety Scanner is an official Microsoft scanning tool, and Microsoft Defender Offline can scan outside the normal Windows environment for harder-to-remove threats. If this is a work computer, follow your organization's security process.
macOS
Do not assume a Mac is immune to phishing or malware. If Apple Account credentials were entered, use Apple's official account recovery path. Keep macOS and Safari updated, remove suspicious browser permissions, and treat unknown apps, unexpected password prompts, or configuration profiles as higher-risk signs.
Avoid unverified "Mac cleaner" tools.
Android
On Android, review recently installed apps, remove anything suspicious, check app permissions, and use Google Play Protect. If Google credentials were entered, review Google account security activity through the real Google account settings.
Play Protect can help with app risk, but it does not replace account recovery if you entered a password or code.
iPhone and iPad
If you only opened a page, did not enter data, did not install a profile or app, and did not approve permissions, device risk is often lower than a desktop executable scenario. But account and browser checks still matter.
If Apple Account credentials were entered, follow Apple's account recovery guidance. Keep iOS or iPadOS updated. Avoid interacting with persistent popups, and review Safari settings and website data where relevant.
Do not assume an iPhone cannot be affected by phishing. Also do not assume an antivirus-style app can scan the entire iPhone system like a desktop antivirus tool.
Chrome, Edge, Firefox, and Safari
Browsers include protections against known phishing or malware pages, but no browser catches every dangerous site immediately.
For Chrome, review Safe Browsing settings, site permissions, notifications, downloads, and extensions.
For Microsoft Edge, SmartScreen is relevant to phishing and malicious-site warnings. Also review notifications, site permissions, downloads, extensions, and Microsoft account activity if a Microsoft login was involved.
For Firefox, review downloads, extensions, saved passwords, site permissions, and notification permissions. Firefox phishing and malware protection can help warn about known dangerous pages, but the browser still needs permission cleanup if a site was allowed to send notifications.
For Safari, keep the browser and operating system updated, use fraudulent website warnings where available, avoid interacting with suspicious popups, and review website settings or website data if a suspicious site was granted permissions.
Sources: Google Safe Browsing; Google Chrome: Safe Browsing Protection; Microsoft Edge: SmartScreen Protection; Microsoft Edge: Manage Website Notifications; Mozilla Firefox: Phishing and Malware Protection; Apple: Safari Privacy and Fraudulent Website Warning; Apple: About Pop-Ups and Fraudulent Website Warnings in Safari.
7. Protect Money and Payment Accounts
If you entered card details, bank login information, payment-app details, or sent money, treat financial containment as urgent.
Do not call a number from the phishing page. Use the phone number on your card, the official banking app, the official payment app, or the real website typed directly into your browser.
Do this as soon as possible:
| If this happened | What to do |
|---|---|
| You entered credit or debit card details | Contact the card issuer. Ask whether to freeze, block, or replace the card. Monitor transactions. |
| You entered bank login details | Contact the bank through a trusted channel. Change the password through the real bank site/app. Review recent activity. |
| You sent money | Contact the bank, card issuer, or payment provider immediately. Ask whether the transaction can be stopped or disputed. |
| You entered shopping account details | Secure the shopping account, remove unknown addresses or payment methods, and review orders. |
| You see unauthorized transactions | Report them to the financial provider and follow its dispute process. |
Reporting fraud to an agency can be useful, but it does not replace contacting the financial institution. The bank, card issuer, or payment provider is the party that can freeze cards, dispute charges, secure accounts, or review transactions.
Sources: FTC: ReportFraud.gov; FBI IC3 FAQ; FTC: IdentityTheft.gov.
8. Protect Identity Information
If you entered sensitive personal information, the recovery path is different from changing a password or replacing a card.
Sensitive identity information can include:
- Social Security number or National ID;
- date of birth;
- home address;
- driver's license;
- passport;
- tax information;
- uploaded ID documents;
- answers to identity-verification questions.
If you shared this kind of information, monitor for new-account fraud and account changes. For US readers, IdentityTheft.gov can help create a recovery plan. Credit freezes and fraud alerts may also be relevant.
A credit freeze and a fraud alert are not the same thing. A credit freeze restricts access to your credit file, which can make it harder for someone to open new credit in your name. A fraud alert tells lenders to take extra steps to verify your identity before opening credit. These are US-specific credit system tools; readers outside the US should use local consumer protection, cybercrime, or identity-theft resources.
Sources: FTC: IdentityTheft.gov; FTC: Credit Freezes and Fraud Alerts; FTC: IdentityTheft.gov.
| If this was shared | Priority |
|---|---|
| Name and email only | Watch for follow-up scams and secure the affected account if needed. |
| Address and date of birth | Monitor accounts and be alert for impersonation or account recovery attempts. |
| SSN, National ID, passport, driver's license, or uploaded ID | Use official identity-theft recovery resources and consider credit actions where available. |
| Identity data plus bank/card data | Handle both identity recovery and financial containment. |
Identity theft protection services may help monitor and assist with recovery, but they cannot guarantee that identity theft will not happen. Official recovery steps still matter.
After urgent identity recovery is handled, reducing unnecessary public exposure of personal data may be a useful long-term privacy step.
Identity Theft Protection Guide
9. Report the Phishing Attack
Reporting helps providers, security teams, and authorities respond to scams. It does not replace account recovery, bank contact, device checks, or identity-theft steps.
Use the reporting channel that matches the incident:
| Incident type | Reporting path |
|---|---|
| Phishing email | Report it to the email provider. FTC guidance also points consumers to APWG for phishing emails. |
| Phishing text | Forward it to 7726 where supported by your carrier, and report it through the messaging provider if available. |
| Fraud or scam loss in the US | Use FTC ReportFraud.gov. |
| Cyber-enabled fraud or scam in the US | Use FBI IC3. If there is immediate danger or time-sensitive loss, contact local law enforcement or the affected provider directly. |
| Organization, work account, or cyber defense reporting | Report to your employer's IT or security team immediately. CISA reporting can also be relevant for organizations and cyber defense, but it does not replace employer, bank, account, or fraud recovery steps. |
| Apple impersonation | Use Apple's official reporting guidance. |
| UK reader | Use NCSC UK reporting resources where relevant. |
| Suspicious account activity | Report through the real account provider, such as the official Google, Microsoft, Apple, bank, or social platform recovery path. |
Sources: FTC: How to Recognize and Avoid Phishing Scams; FTC: ReportFraud.gov; FBI IC3: Internet Crime Complaint Center; FBI IC3 FAQ; CISA: Phishing Guidance; NCSC UK: Phishing Guidance; Apple: Recognize and Avoid Social Engineering Schemes.
If you still have the message, sender address, phone number, URL, screenshot, or payment details, keep them for reporting if it is safe. Do not revisit a dangerous link just to collect more evidence.
10. Prevent Future Incidents
Once the urgent recovery steps are handled, strengthen the areas the phishing attempt exposed.
Use unique passwords
If you reused the phished password anywhere, replace it with unique passwords. A password manager can help create and store them. It does not undo an account compromise, but it can reduce the damage if one password is stolen in the future.
Browser Password Manager vs Dedicated Password Manager
Improve MFA
MFA is still important, but not all MFA works the same way. SMS codes, email codes, authenticator codes, and push prompts can still be targeted by phishing. Where supported, passkeys or security keys offer stronger phishing resistance because they are tied to the legitimate site or service.
Sources: CISA: Implementing Phishing-Resistant MFA; NIST SP 800-63B: Authentication and Lifecycle Management; Microsoft: Phishing-Resistant MFA.
Are Passkeys Safer Than Passwords
Can Passkeys Replace Password Managers
Harden your browser
Review browser security settings, notifications, site permissions, downloads, and extensions. Keep the browser updated. Browser warnings such as Safe Browsing, SmartScreen, Firefox phishing protection, and Safari fraudulent website warnings help reduce risk, but they are not perfect.
Sources: Google Safe Browsing; Microsoft Edge: SmartScreen Protection; Mozilla Firefox: Phishing and Malware Protection; Apple: Safari Privacy and Fraudulent Website Warning.
Browser Security Settings You Should Change
Use security software where it fits
Antivirus or security software is relevant if you downloaded, opened, or installed something suspicious, or if your device shows symptoms. It does not recover stolen passwords, reverse a bank transfer, or remove an app permission from your account.
Use scam tools as prevention, not recovery
A scam checker or anti-scam tool may help evaluate future suspicious messages or links. It should not replace bank contact, account recovery, identity-theft steps, or reporting after something has already happened.
Understand what a VPN can and cannot do
A VPN can help with network privacy in some situations, such as public Wi-Fi, but it does not stop you from entering a password on a fake page. Do not treat a VPN as a phishing recovery tool.
The long-term goal is layered protection: unique passwords, stronger authentication, safer browser settings, updated devices, careful account recovery habits, and a clear plan if something goes wrong again.
11. Final Recovery Checklist
Use this checklist to confirm what applies to you. You do not need every step unless that branch happened.
Universal checks
- I stopped interacting with the suspicious page or message.
- I did not call numbers or download tools from the suspicious page.
- I checked whether anything downloaded.
- I used official apps, bookmarks, or typed addresses for real accounts.
- I preserved evidence if work, fraud, money, identity, or reporting is involved.
If you only clicked
- I closed the page.
- I did not enter information.
- I did not approve a prompt.
- I checked downloads.
- I checked browser notifications and permissions if prompted.
- I monitored account alerts.
- I reported the message if appropriate.
If you entered credentials, codes, approved MFA, or allowed an app
- I changed the affected password through the real site/app.
- I changed reused passwords on other accounts.
- I signed out of other sessions where supported.
- I reviewed login activity and devices.
- I checked recovery email, recovery phone, and backup codes.
- I removed suspicious connected apps or permissions.
- I enabled or strengthened MFA.
- I prioritized my email account if it was affected.
Credential Theft Protection Guide
If a file downloaded, opened, or software was installed
- I deleted suspicious downloaded files I did not open.
- I stopped using suspicious software.
- I ran a trusted scan if a file/app was opened or installed.
- I considered offline or advanced scanning if symptoms continue.
- I changed important passwords from another trusted device if needed.
- I contacted IT/security for a work device.
If browser notifications or permissions were allowed
- I removed the suspicious site's notification permission.
- I reviewed site permissions.
- I checked extensions and downloads.
- I updated the browser.
Browser Security Settings You Should Change
If payment or bank information was entered
- I contacted the bank, card issuer, or payment provider through a trusted channel.
- I followed provider guidance to freeze, block, replace, or secure accounts.
- I reviewed transactions.
- I disputed unauthorized activity through the provider.
- I reported fraud where relevant.
If identity information was shared
- I identified what personal information was exposed.
- I used official identity-theft recovery resources where applicable.
- I considered a credit freeze or fraud alert if I am in the US and sensitive identity data was exposed.
- I monitored accounts and credit activity.
- I contacted affected companies if fraud occurred.
Identity Theft Protection Guide
If a work account or work device was involved
- I reported it to IT or security.
- I preserved the message or details.
- I did not delete evidence or run unsanctioned cleanup tools unless instructed.
12. FAQ
Immediate Recovery
Am I hacked if I only clicked a phishing link?
Not necessarily. If you only opened the page and did not enter information, approve a prompt, download/open a file, install software, or allow permissions, the risk is usually lower. You should still close the page, check downloads, review browser permissions, monitor account alerts, and report the message if appropriate.
What should I do first after clicking a phishing link?
Stop interacting with the page or message. Do not enter more information, call numbers from the page, or download anything from it. Then identify what happened after the click so you can follow the correct recovery branch.
Should I disconnect from the internet after clicking a phishing link?
Only in some cases. Disconnecting can help if you opened suspicious software, suspect active malware, saw remote access, or are using a work device where policy requires it. If you only clicked or entered a password, account recovery may be more urgent.
Should I delete the phishing email or text?
Not immediately if you may need it for work reporting, fraud reporting, provider reporting, or evidence. If you do not need it, report it through the right channel and then remove it.
Should I reply or unsubscribe from a suspicious message?
No. Do not reply, unsubscribe, or click more links in a suspicious message. Use the real company website or app if you need to contact the organization.
What if I clicked the link but closed it right away?
That is usually lower risk than entering information or opening a file. Still check your downloads, browser permissions, and account alerts. If nothing else happened, heavy account or device recovery may not be necessary.
What if I clicked a phishing link on my work computer?
Report it to your employer's IT or security team. Preserve the message or details if safe. Do not delete evidence or run cleanup tools unless your organization tells you to.
Technical Clarification
Can a phishing link install malware automatically?
It depends on the device, browser, software, and what happened next. Many phishing attacks require you to download, open, install, or approve something. Keep your browser and operating system updated, and run a trusted scan if a suspicious file or app was opened.
What is the difference between downloading a file and opening it?
A downloaded file is present on your device but may not have run. Opening, running, or installing it is higher risk because the file or app may execute code or request permissions. Delete suspicious downloads you did not open, and scan if anything was opened or installed.
What if I allowed notifications from a scam website?
Remove the site's notification permission in your browser settings. Scam notifications can create fake alerts even after you leave the site. This does not always mean the whole device is infected.
What if I entered a 2FA code on a fake page?
Treat the account as possibly accessed. Change the password through the real site/app, sign out of other sessions where possible, review login activity, reset MFA methods or backup codes, and consider phishing-resistant MFA where available.
What if I approved a login prompt by mistake?
Treat it as possible account access. Revoke sessions, change the password, review devices and account activity, and report it to IT/security if it was a work account.
What is OAuth consent phishing?
OAuth consent phishing is when a fake or malicious app asks you to grant access to your account or data. You may not have typed a password, but the app can still keep access until you revoke its permissions.
Can an iPhone get malware from a phishing link?
iPhones have strong security controls, but phishing can still steal account information, push fake popups, abuse browser interactions, or trick users into unsafe actions. If you entered Apple Account credentials, follow Apple's official recovery path.
Can Android get malware from a phishing link?
Android risk is higher if you installed an app, granted permissions, or opened a malicious file. Review recent apps, remove suspicious ones, check permissions, and use Play Protect. Also secure any account credentials you entered.
Can browser Safe Browsing or SmartScreen stop every phishing site?
No browser protection catches every phishing site. Safe Browsing, SmartScreen, Firefox protection, and Safari warnings can help, but new or targeted phishing pages may appear before they are blocked.
Prevention
How can I avoid phishing links in the future?
Use safer habits and stronger controls: unique passwords, MFA, updated browsers, careful account recovery settings, and extra caution with urgent messages. Do not rely only on spotting bad grammar or strange design.
Do password managers help prevent phishing damage?
They can reduce damage from stolen passwords because each account can have a unique password. Some password managers may also avoid filling credentials on the wrong domain. They do not replace recovery if you already entered a password.
Are passkeys safer after a phishing scare?
Passkeys and security keys can be more resistant to phishing than reusable passwords or one-time codes where supported. They are strongest when recovery methods, email accounts, and device security are also protected.
Does antivirus protect against phishing?
Antivirus can help with malicious files, unsafe downloads, and some dangerous sites. It does not recover stolen passwords, revoke app permissions, stop a bank transfer, or remove identity-theft risk.
Does a VPN protect against phishing links?
No, not in the way people often mean. A VPN can help protect network privacy, but it does not stop you from entering credentials on a fake page or approving a malicious prompt.
Should I use a scam checker for suspicious links?
A scam checker can help evaluate future suspicious messages or links, but it is not a recovery tool after credentials, money, identity information, or account access have already been exposed.
Should I change browser settings after a phishing attempt?
Yes, especially if the page asked for notifications, downloads, popups, camera, microphone, location, or other permissions. Review browser security settings and remove permissions for suspicious sites.
Account Security
Should I change my password if I entered it on a fake site?
Yes. Change it through the real site or app, not through the phishing link. Then sign out of other sessions where possible and review account activity.
Should I change the same password on other accounts?
Yes. If you reused the same or similar password anywhere else, change it there too. Use unique passwords for every account.
How do I know if someone logged into my account?
Check recent login activity, devices, security alerts, recovery settings, and connected apps in the real account settings. If anything looks unfamiliar, remove it and follow the provider's recovery steps.
Should I sign out of all devices?
Yes, if the service offers that option and you entered credentials, shared a code, approved a prompt, or suspect account access. This can remove active sessions, but the exact behavior depends on the service.
Should I reset my MFA backup codes?
Yes, if you think the account was accessed or the backup codes may have been exposed. Generate new backup codes through the real account settings and store them safely.
What if my email account was phished?
Prioritize it. Email accounts can be used to reset passwords on many other accounts. Change the password, sign out of sessions, review forwarding rules, check recovery details, and secure accounts that rely on that email.
What if I entered my Apple, Google, or Microsoft password?
Use the official recovery or security checkup path for that provider. Review login activity, devices, recovery information, app permissions, and MFA settings.
What if I entered bank login details?
Contact the bank through a trusted channel immediately. Change the password through the real bank site or app, review transactions, and follow the bank's fraud or account-security instructions.
Recovery Summary
If you clicked a phishing link, the right response depends on what happened next. If you only opened the page, focus on closing it, checking downloads and browser permissions, monitoring alerts, and reporting where appropriate. If you entered credentials, codes, approved a prompt, or allowed an app, secure the account and revoke access. If you opened a file or installed software, check the device with trusted tools. If money or identity information was exposed, contact the right institution or official recovery service quickly.
You do not need to panic, but you should act in the right order: stop interacting, identify the branch, contain the risk, secure accounts, check devices, protect money and identity, report the incident, and strengthen defenses for next time.