What Happens If You Click a Phishing Link
Short answer
If you only opened the page and typed nothing, almost always nothing happens — close the tab and move on. If you entered a password, change that password immediately from a different device, then sign out all sessions and check the account's recovery email and phone. If you entered card details, ring your bank's number from the card itself.
On this page
You clicked. The page looked wrong, or you realised halfway through, and now you are trying to work out how much trouble you are in.
The honest answer, most of the time, is very little. A clicked link is not an infection. The thing that determines whether this is a non-event or a genuine problem is not the click at all — it is what you typed after it.
Work out which category you are in before doing anything, because the responses are completely different and the wrong one wastes the time that matters.
Which situation are you actually in
| What you did | Realistic risk | First action |
|---|---|---|
| Opened the page, typed nothing | Very low | Close the tab |
| Typed a password | High, immediate | Change that password now |
| Typed a card number | High, immediate | Ring the bank on the card |
| Entered a 2FA or one-time code | Severe, minutes matter | Change password, revoke sessions |
| Downloaded and opened a file | Moderate to high | Disconnect, scan offline |
| Approved a login prompt or push | Severe | Revoke sessions, change password |
The three rows involving a code or an approval are the urgent ones. A one-time code is only useful for a short window, and the attacker is typically sitting at the login screen waiting for it. Every minute counts in a way it does not for a simple password entry.
If you only opened the page
Close the tab. That is genuinely the whole response.
For a page to compromise a current, updated browser just by loading, it would need an unpatched flaw in the browser itself. Those exist, they are valuable, and they are not spent on bulk phishing campaigns aimed at whoever clicks a parcel notification. Chrome, Edge, Safari and Firefox all patch this class of bug quickly and update themselves in the background.
What the page did learn is minor: your approximate location from your IP address, your browser and operating system, and the fact that this particular email address clicks links. The last one is the only meaningful consequence, and it means you may receive more attempts. It is not a reason to do anything drastic.
If the page prompted you to install something, allow notifications, or “update your browser”, and you declined, you are fine. If you accepted, skip to the section on downloads below.
If you typed a password
This is the common case, and the order of steps matters because each one closes a different door.
1. Change the password, from a different device if you can. Do it directly in the real app or by typing the site’s address yourself. Not from the email, not from any link in it. If the attacker has the old password, you are racing them, and this step is what ends the race.
2. Sign out every other session. Changing a password does not always evict sessions already signed in, and this is the step most people skip. Nearly every major service has it, usually near the security settings: Google has it under your account’s device list, Microsoft, Apple and the large social platforms all offer the equivalent. Checking where your Google account is signed in walks through that one specifically.
3. Check the recovery details. This is the step that separates a scare from a long-running problem. An attacker who got in for even a minute may have changed the recovery email address or phone number, which lets them take the account back later regardless of your new password. Confirm both are still yours, and remove anything you do not recognise.
4. Check for forwarding rules and app passwords. On email specifically, look for a new filter or forwarding address silently copying your mail elsewhere. This is a standard persistence trick and it survives every password change you make. Also revoke any connected apps you do not recognise.
5. Change the password anywhere you reused it. If that password was also your shopping account’s, your streaming account’s, and your old forum login’s, all of those are now at risk. Reuse is the mechanism that turns one mistake into several.
6. Turn on two-factor authentication if it was not already on. It makes the next version of this a non-event.
If you entered a verification code
Act in minutes, not hours. The attacker triggered a genuine login, you supplied the code, and they may be inside the account right now.
Do the password change and the session revocation above, in that order and without pausing to investigate. Investigate afterwards. If the account is your primary email, treat it as the highest priority in your digital life, because every other account’s password reset flows through it.
The fuller lockdown sequence, including what to check once you are back in, is in what to do when someone is logged into your account.
If you downloaded or opened a file
This is the one case where malware is a realistic outcome, particularly with documents that asked you to enable editing or enable content, installers, or anything that arrived as a compressed archive with a password in the email body. That password-protected archive pattern exists specifically to stop your mail provider from scanning the contents.
Disconnect from the network first — flight mode, or unplug the ethernet cable. Then scan properly rather than with a quick scan, because a quick scan checks the usual locations and a live scan can be evaded by something already running.
On Windows, the offline scan is the right tool: Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. The machine reboots into a minimal environment and scans before Windows loads. It takes about fifteen minutes. The full walkthrough is in scanning for and removing malware on Windows.
If the file was opened on a phone, the risk is considerably lower. iOS and Android both sandbox applications heavily, and a document cannot install software on its own. An app you installed from outside the official store is a different matter.
If you entered card details
Ring the number on the back of the card. Not a number from the email, not a number from a search result, which is itself a scam route.
Your bank can block the card and reissue it in the same call, and card fraud is reversible in a way that credentials are not. Do not wait to see whether a charge appears. Do not assume a small test charge is a coincidence, because small test charges are precisely how stolen cards are validated before being used properly.
What does not help
- Running six different malware scanners. If one reputable scanner finds nothing after a full scan, the seventh will not either. It will find tracking cookies and call them threats.
- Factory resetting a phone because you clicked a link. Disproportionate by a wide margin, and it does nothing about the credential you typed, which is the actual problem.
- Changing your email address. The password and the sessions are what matter.
- Clearing cookies as the primary response. Harmless, occasionally tidy, and entirely beside the point if a password left the building.
Realistic expectations
The large majority of clicked phishing links end with nothing happening at all, because most people stop at the page and something about it feels off before they type.
Where a password was entered, the password change plus signing out other sessions usually closes it completely, and the whole job takes about ten minutes per account. The cases that become genuinely difficult are the ones where nobody checked the recovery email and forwarding rules, and the attacker quietly kept access for weeks. Spend the extra two minutes on those two checks — they are the difference between a bad afternoon and a bad month.