Clicked a suspicious link or typed your password? What to do now
It happens to careful people every day. Phishing messages are made to look exactly like your bank, a delivery company or a streaming service. What you should do now depends on how far you got, so find the situation below that matches yours.
Situation 1: you clicked the link, but didn't type anything
This is the most common case and usually the least serious. Simply opening a phishing page rarely does harm by itself on an up-to-date device.
- Close the page. Don't enter anything, and don't download anything it offers.
- If a file downloaded automatically, don't open it. Delete it from your Downloads folder.
- Make sure your device and browser are up to date, since updates fix the weaknesses these pages sometimes try to use.
- Optionally, run a scan with your security software for peace of mind. On Windows, see how to scan with Windows Security.
Situation 2: you typed a password
Assume the password is now known to the scammer, and act quickly. They often try it within minutes.
- Change that password straight away, by typing the real website's address yourself or using its official app. Don't use any link from the message.
- Change it anywhere else you used the same password. Scammers automatically try stolen passwords on other popular sites. Start with your email account, because email can be used to reset everything else.
- Turn on two-step verification for that account, so a password alone isn't enough to get in.
- Check the account for changes you didn't make: a new recovery email or phone number, forwarding rules in your email, or devices you don't recognize signed in. Remove anything unfamiliar.
- Sign out of all other sessions if the account offers that option. Most major services do, in their security settings.
Situation 3: you entered card or bank details
- Call your bank or card company now, using the number on the back of your card or on their official website. Not a number from the message.
- Tell them what happened. They can block the card, issue a new one and watch for fraudulent charges.
- Watch your statements closely for the next few months, and report anything you don't recognize.
Situation 4: you shared ID details such as a Social Security number
This one takes more steps, but there is an official, free, step-by-step plan for it.
- Go to IdentityTheft.gov, the FTC's official site. It gives you a personal recovery plan based on exactly what information was exposed.
- Consider placing a fraud alert by contacting one of the three US credit bureaus. According to the FTC, a fraud alert lasts one year and makes it harder for someone to open new accounts in your name.
- Get your free credit reports and check for accounts you didn't open.
- If you think your identity is being misused, a credit freeze gives stronger protection than a fraud alert. IdentityTheft.gov explains the difference.
How to spot the next one
The FTC lists the patterns most phishing messages share. Once you know them, they're much easier to see:
- Urgency: "Your account will be suspended today" or "unusual sign-in detected".
- A problem you didn't know about: a failed delivery, an unpaid invoice or a locked account.
- A link or attachment you're asked to open to fix it.
- A sender address or link that's slightly off, such as a misspelled company name or an unusual domain.
The safest habit is simple: never fix a problem through the link in the message. Go to the company's website or app yourself and check there. If the problem is real, you'll see it.
Report it
Reporting helps protect others. You can forward phishing emails to the organization being impersonated (most banks publish an address for this), and report the scam at ReportFraud.ftc.gov.