You have time to act, and most clicks do not result in immediate harm

Clicking a phishing link does not automatically compromise your accounts or devices. What happens next depends on what you did after clicking — whether you entered a password, downloaded a file, or just landed on a fake page and closed it. The goal of a phishing email is to trick you into revealing login credentials or installing malware, but the click itself is only the first step in that chain. If you stopped before handing over information, your risk is lower than you might think.

The most important action is to stop and assess what actually happened in the moments after you clicked. Did a page load and you immediately close it? Did you type a password before realizing something was wrong? Did a file download to your computer? Your next steps depend on that answer, and they are concrete things you can do right now.

Key Takeaways

  • Clicking a link is not the same as compromising your account — what matters is whether you entered a password or downloaded a file afterward.
  • If you entered a password on a fake login page, change that password immediately on the real website using a different device or browser if possible.
  • If a file downloaded, do not open it; run a malware scan on your device using Windows Defender (built into Windows) or your antivirus software.
  • Report the phishing email to your email provider and the organization being impersonated so they can warn other users and take down the fake page.
  • Enable two-factor authentication on important accounts so that even a stolen password cannot be used to log in without a second verification step.

If you only clicked the link and closed the page immediately

A single click with no further action carries minimal risk. Visiting a fake website does not install anything on your device or steal your data just by loading the page. Phishing pages are designed to look like real login screens or urgent alerts, but they cannot do anything unless you interact with them.

You should still take two precautions. First, report the email to your email provider — forward it to the phishing report address (usually phishing@[your email provider].com, or use the report button in your email client). Second, if the email impersonated a real company like your bank or PayPal, report it to that organization's security team as well. This helps them take down the fake page and warn other users.

Monitor your accounts for the next few weeks for any unusual activity, but you do not need to panic or change passwords. If you see login attempts from unfamiliar locations or devices, that is a sign the email list was sold to attackers — in that case, change your password and enable two-factor authentication.

If you entered a password on the fake page

This is the scenario where immediate action matters. A phishing page that captured your password has given attackers the key to your real account. The longer you wait, the more time they have to log in, change your recovery information, or lock you out.

Change your password on the real website immediately. Use a different device or a different browser if possible — if your current device has malware, it might intercept your new password as you type it. Go directly to the official website by typing the address yourself (do not click any links), log in with your old password, and change it to something long and random that you have not used anywhere else. A strong password is at least 16 characters and includes uppercase, lowercase, numbers, and symbols.

After you change your password, check your account recovery settings. Look for a "Security" or "Account Settings" section and verify that your phone number, backup email address, and recovery options are still yours. Attackers often change these first so they can lock you out and reset your password themselves. If anything looks wrong, change it back immediately.

If the compromised account is connected to other services — for example, if you use your Gmail account to log into other websites — change your password on those services too. Attackers will try to use your stolen credentials across multiple platforms.

If a file downloaded to your computer

Do not open the file. Phishing emails often include attachments that look like invoices, delivery notices, or urgent documents, but they contain malware. Opening the file is what activates the threat.

Run a full malware scan on your device. On Windows, open Windows Defender (built into Windows 10 and 11) by searching for "Windows Security" in the Start menu. Click "Virus & threat protection," then "Scan options," select "Full scan," and click "Scan now." This will take 30 minutes to several hours depending on how much data you have. On Mac, use Malwarebytes (free version available) or your antivirus software if you have it installed.

While the scan runs, delete the downloaded file. Open your Downloads folder, find the file, right-click it, and select "Delete." Empty your Recycle Bin afterward. If you are not sure which file it was, sort your Downloads folder by date and look for anything that arrived around the time you clicked the link.

If the scan finds threats, your antivirus software will quarantine them (move them to a safe holding area where they cannot run). Review what was found and let the software remove it. If you see a threat that was not quarantined, or if your device starts behaving strangely after the scan (slow performance, unexpected pop-ups, new toolbars), you may need professional help — take your device to a local computer repair shop or contact your device manufacturer's support line.

Reporting the phishing email to your email provider

Every email provider has a way to report phishing. In Gmail, open the email, click the three-dot menu at the top right, and select "Report phishing." In Outlook, click the "Junk" button and select "Phishing." In Apple Mail, click "Report Junk" in the toolbar. These reports go directly to the email provider's security team and help them identify phishing campaigns.

You can also forward the email to the organization being impersonated. If the email pretended to be from your bank, go to your bank's website, find their security or fraud reporting contact, and forward the email to them. Most banks and major companies have a dedicated phishing report address. They use these reports to take down fake websites and alert customers.

Do not reply to the phishing email or click any links in it, even to "unsubscribe." Replying confirms your email address is active and may result in more phishing attempts.

Enabling two-factor authentication to prevent future damage

Two-factor authentication (often called 2FA or two-step verification) requires a second form of proof beyond your password when you log in. Even if an attacker has your password, they cannot access your account without that second factor — usually a code from an app, a text message, or a security key.

Enable two-factor authentication on your most important accounts: email, banking, social media, and any account that contains sensitive information. Most services offer it in their security settings. Look for "Two-factor authentication," "Two-step verification," or "Security settings" in your account menu.

Use an authenticator app rather than text message if the service offers both. Apps like Google Authenticator, Microsoft Authenticator, or Authy are more secure because they cannot be intercepted the way text messages can. If you use text message, make sure your phone number is registered with your phone carrier's account security — this prevents attackers from transferring your number to a different phone.

Signs that your device or accounts have been compromised

Watch for these warning signs over the next few weeks. If you see any of them, your device or accounts may have been compromised beyond just a stolen password. Unusual login activity includes login attempts from cities or countries where you have never been, or logins at times when you were asleep. Check your account's login history (usually found in Security or Account Activity settings) to see where and when your account was accessed.

Unexpected password reset emails, account lockouts, or messages saying your password was changed are also red flags. If you did not request these changes, an attacker may have accessed your account. Change your password immediately and check your recovery settings to make sure they still belong to you.

On your device, watch for new programs you did not install, unexpected toolbars in your browser, or your homepage changing on its own. These are signs of malware. If you see them, run another full malware scan and consider taking your device to a professional if the scan does not resolve the problem.

Frequently Asked Questions

Can a phishing link infect my device just by clicking it?

Clicking a link and landing on a fake website does not automatically install malware. Your device is only at risk if you download and open a file from that page. However, some phishing pages use advanced techniques to exploit browser vulnerabilities — this is rare but possible. Running a malware scan after clicking a suspicious link is a safe precaution.

How do I know if a website is fake before I enter my password?

Check the URL in the address bar — it should match the real company's website exactly. Fake sites often use slight variations like "amaz0n.com" or "paypa1.com" (with a zero or one instead of a letter). Look for "https://" and a padlock icon, which indicate a secure connection, but note that fake sites can have these too. When in doubt, close the page and go to the official website by typing the address yourself.

If I changed my password, do I still need to run a malware scan?

Yes. Changing your password protects your account, but it does not remove malware from your device. If a file downloaded when you clicked the link, malware could still be on your computer even if you changed your password. Run a full scan to be sure.

What should I do if I cannot access my account after clicking a phishing link?

You may have been locked out by an attacker who changed your password or recovery settings. Use the "Forgot password" option on the real website to regain access. You will need to verify your identity using recovery information (backup email, phone number, or security questions). If you cannot verify your identity, contact the company's customer support — they can help you prove you own the account.

Do I need to tell my bank or credit card company if I clicked a phishing link?

Only if you entered your banking credentials on the fake page or if you see unauthorized transactions on your account. If you only clicked the link and closed it, there is no need to call. If you did enter credentials, call your bank's fraud department immediately — they can monitor your account and issue a new card if needed.