What to Do After Clicking a Suspicious Link
Short answer
Work in this order: disconnect only if you downloaded a file, change the password you entered — from a different device — before anything else, sign out all other sessions, verify the account's recovery email and phone are still yours, check for new forwarding rules, then scan. Changing passwords you did not type is wasted time.
On this page
The instinct after clicking something you should not have is to do everything at once: run a scan, change all your passwords, clear cookies, maybe reinstall something. Most of that is motion rather than progress, and the genuinely time-critical step gets done fourth.
The list below is ordered by what stops ongoing damage, not by what feels thorough. Work down it and stop at the point where the steps stop applying to what you actually did.
Step 0 — establish what you did
Thirty seconds, and it determines everything after.
| What happened | Urgency | Start at |
|---|---|---|
| Page opened, nothing typed | None | Step 7 |
| Password entered | Hours | Step 2 |
| One-time code entered or login approved | Minutes | Step 2, immediately |
| Card details entered | Minutes | Step 6 |
| File downloaded and opened | Hours | Step 1 |
| Remote access software installed | Minutes | Step 1, then Step 2 |
Be honest about the password one. A fake login page that shows an error and then forwards you to the real site is a standard design, and the error is not evidence that the attempt failed. Assume anything typed was captured.
Step 1 — disconnect, but only if a file is involved
If you downloaded and ran something, or installed remote access software, cut the network now. Flight mode on a phone, Wi-Fi off or ethernet unplugged on a computer. This stops data leaving and stops instructions arriving.
If you only typed a password, do not disconnect. You need the network for Step 2, and the page that captured your password already sent it the moment you pressed submit. Disconnecting afterwards accomplishes nothing except delaying the fix.
If someone talked you into installing remote access software during a phone call, disconnect, then uninstall it, then assume everything typed while they were connected is known.
Step 2 — change the password you entered
The highest-value step, and the one that should happen before any scanning.
Use a different device if one is available, particularly if a file was involved on the first machine. Go to the service directly — type the address, or open the app you already have. Never through the email.
Change only the password you actually entered. Changing passwords you did not type is a common way of spending an hour achieving nothing, and it delays the steps below that matter more.
If you cannot sign in because the password has already been changed, the account is taken over and the procedure is different. Go to what to do when someone is logged into your account.
Step 3 — sign out every other session
Changing a password does not always evict existing sessions, and a stolen session cookie keeps working until it is revoked. This is the step most often skipped and the reason some people get re-compromised a week later.
Find the security or devices section of the account and use the option to sign out everywhere. Google’s version is covered in seeing where your Google account is signed in; Microsoft, Apple and the major social platforms all have an equivalent.
Step 4 — verify the recovery details
This is the step that determines whether the problem is over or merely paused.
Check the recovery email address and recovery phone number on the account. An attacker with even brief access changes these, because it gives them a way back in regardless of your new password. Remove anything unfamiliar.
While you are there, check whether two-factor authentication is enabled, and whether the second factor listed is yours. An authenticator app you did not add is a loud signal.
Step 5 — check for persistence
Specifically on email accounts, where the consequences compound.
- Forwarding rules and filters. A rule silently copying your mail elsewhere, or deleting password-reset emails before you see them, survives every password change. Look under the account’s filters and forwarding settings and remove anything you did not create.
- Connected apps and third-party access. Revoke anything unfamiliar.
- App passwords. Some providers allow these for older mail clients, and they bypass two-factor authentication entirely. Revoke any you do not recognise.
- Signature changes. Occasionally altered to add a malicious link to every message you send.
Step 6 — card details, if any were entered
Ring the number printed on the back of the card. Not a number from the email, and not one from a search result, which is itself a common scam route.
The card can be blocked and reissued in that call. Do not wait to see whether a charge appears, and do not dismiss a small unexplained charge as a glitch — small test transactions are how stolen cards are validated before being used properly.
Step 7 — now scan
Last, not first, and only genuinely necessary if a file was involved.
On Windows, use the offline scan rather than a quick scan, because it reboots and scans before Windows loads: Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. The full procedure, including the cleanup afterwards, is in scanning for and removing malware on Windows.
On a Mac, check login items and browser extensions by hand first, as in checking your Mac for malware, then run one on-demand Malwarebytes scan.
On a phone, scanning is largely unavailable and largely unnecessary. Review installed apps and permissions instead.
Step 8 — report it
Forward the message to your email provider’s reporting address or use the in-client report button, which improves filtering for everyone. For a work account, tell IT first and before cleaning up, since your cleanup can destroy evidence they need. In the UK, suspicious emails can be forwarded to the National Cyber Security Centre’s reporting address and texts forwarded to 7726.
What to skip
- Changing every password you own. Only those you typed, plus anywhere you reused that password.
- Clearing cookies as the main response. Harmless, irrelevant to a captured credential.
- Running four scanners. One good scan, one second opinion, stop.
- Factory resetting after a click. Disproportionate, and it leaves the actual exposure untouched.
- Waiting to see if anything happens. The checks above take fifteen minutes. Waiting costs you the window in which they work.
Realistic expectations
If you typed nothing, this is already over and Step 7 is optional reassurance. That is the most common outcome by a wide margin.
If you typed a password, Steps 2 to 5 take roughly fifteen minutes per account and close it properly. The cases that turn into long problems are almost always the ones where someone changed the password, felt finished, and never looked at the recovery email address or the forwarding rules. Those two checks are the difference between an afternoon and a month.