Clicked on a Phishing Link? Here Is What to Check.
By NorwegianSpark Editorial · Published September 6, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
The first thing to establish is which of two very different things happened, because most advice on this topic treats them as one.
You clicked a link and looked at a page. In the overwhelming majority of cases, on an updated device with a modern browser, nothing happened. A web page cannot silently install software on a patched system as a matter of routine. The click was the bait; the trap was further in.
You clicked, and then typed something, or opened something. A password, a card number, a verification code, a downloaded file you ran, a permission you approved. That is the event that matters, and everything below is about containing it.
If you only did the first, read the quick check and get on with your day. If you did the second, work down the list in order.
The ten-minute triage
- Do not go back to the page. Do not tap anything on it, including "cancel", "unsubscribe" or a close button drawn inside the page rather than by the browser. Close the tab from the browser's own control.
- Ask what you gave it. Nothing? A password? Which one, and where else is that same password used? A card number? A one-time code? Write the answer down before doing anything else, because the rest of the response depends entirely on it.
- If you entered a password, change it now on the real site — reached by typing the address yourself or using a saved bookmark, never by following any link in the message. Then change it everywhere else you used the same one, which is the step people skip and the one that matters most.
- If you read out or entered a one-time code, treat the account as compromised. Change the password, sign out all sessions from the account's own security page, and check for any new recovery email address, forwarding rule or app password the attacker may have added. Attackers add persistence; removing their access means removing that too, not just changing the password.
- If you entered card details, contact the card issuer using the number printed on the card, not any number from the message. Ask for the card to be replaced rather than just watched.
- If you downloaded and ran a file, run a full scan with your security software before anything else. This is the one branch where the malware question is real. Our step-by-step guides are how to tell if your PC has malware and how to remove malware, and for Apple machines, how to remove malware from a Mac.
- Turn on a second factor on the affected account if it was not on already. This converts the stolen password from a key into a useless string.
What CISA says, and the part worth memorising
CISA's public guidance on recognising phishing lists the indicators that are worth committing to memory, quoted verbatim from its own page on 6 September 2026: "urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately"; "requests to send personal and financial information"; "untrusted shortened URLs"; and lookalike addresses, "like amazan.com".
Its instruction for a message you have not acted on is short: "Delete the message. Don't reply or click on any attachment or link, including any 'unsubscribe' link. Just delete."
The first indicator is the one that identifies almost every campaign. Urgency is not a side effect of phishing; it is the mechanism. The message needs you to act before you check, because checking defeats it. If you notice nothing else, notice when a message is trying to make you hurry.
Judge the damage honestly
| What you did | Realistic exposure | First move |
|---|---|---|
| Clicked, saw the page, closed it | Very low on a patched device | Nothing beyond staying alert to follow-up messages |
| Entered an email address only | Low; expect more targeted mail | Watch for a follow-up that references it |
| Entered a password | High for that account, and for every reuse of it | Change it, then change every reuse |
| Entered a one-time code | Account should be assumed taken | Change password, sign out all sessions, audit recovery settings |
| Entered card details | High | Call the issuer on the number on the card, ask for a replacement |
| Downloaded and ran a file | High, and device-wide | Full scan, then change passwords from a different device |
| Approved an app or permission prompt | Ongoing access until revoked | Revoke it in the account's connected-apps page |
The bottom two rows are the ones people underestimate. A file you ran can harvest saved passwords straight out of the browser, which is why the advice there is to change passwords from a different device — changing them on the compromised one hands the new ones over as you type them. And an approved OAuth permission survives a password change entirely; it has to be revoked separately in the account's own settings.
Report it, and why that is not pointless
In the United States, consumer fraud goes to the FTC at ReportFraud.ftc.gov, and cybercrime goes to the FBI's Internet Crime Complaint Center, which describes itself as "the central hub for reporting cyber-enabled crime". Elsewhere, your national cybercrime or fraud reporting body is the equivalent. If the message impersonated your employer, tell whoever handles IT there — a campaign that reached you reached others.
It feels futile at an individual level. It is not futile in aggregate: reporting is how a phishing domain gets taken down and how a pattern gets recognised. It costs two minutes.
The follow-up call, which is the part that actually empties accounts
Expect a second contact, and expect it to be the more convincing one.
Having your details from the form, an attacker often follows up by phone, posing as your bank's fraud team and warning about the suspicious activity they themselves caused. They may trigger a genuine verification code to your phone so that a real message arrives seconds before they ask you to read it back.
The rule, with no exceptions: an inbound request for a verification code is always fraudulent. No legitimate institution phones you and asks you to read one out. If a code arrives that you did not trigger, that is itself the alarm.
If you are ever unsure, hang up and call the number printed on your card or on your official statement — never a number given to you in the message or by the caller. The related threats are covered in smishing and scam texts, AI voice clone scams, and the wider picture in your password is on the dark web.
The counter-argument to panic
It is worth saying plainly, because the anxiety after a click is disproportionate to the risk in most cases: on a patched device with a modern browser, visiting a malicious page and leaving is usually a non-event. Drive-by installation without any interaction is rare and generally depends on an unpatched flaw. The industry's own advice about disconnecting from the internet immediately is sound for the "I ran a file" branch and largely theatre for the "I looked at a page" branch.
Which means the most valuable thing you can do after a click is not to scan frantically. It is to establish honestly what you typed. That single question determines whether this was a nothing or a something, and the whole of the response follows from it.
The prevention side, for next time, is in how to spot and avoid phishing, and moving to passkeys removes the phishable secret altogether on the accounts that support them. Endpoint protection covers the download branch — Bitdefender is built for that class, and Norton 360 bundles it with identity tools.
Clicking is rarely the disaster. Typing is. Work out which you did, contain that, and report it. This is general guidance, not security advice for a specific threat model.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.
Continue reading
privacy
Password Managers Explained
Why a password manager is the highest-value security tool most people don’t use — and how to choose one.
privacy
Are Password Managers Hackable in 2026?
Yes — and one of the big ones was. What LastPass actually said happened, what zero-knowledge does and does not cover, and why the maths still favours using one.
guides
Best Antivirus for Mac 2026: Which One to Pick
The best antivirus for Mac in 2026: whether macOS needs third-party protection, how we chose our picks, and reviews of Bitdefender, Norton and Avast.
