Skip to main content
FixMyTech

What to Do After Clicking a Suspicious Link

By

Published

8 min read

Share

Short answer

Work in this order: disconnect only if you downloaded a file, change the password you entered — from a different device — before anything else, sign out all other sessions, verify the account's recovery email and phone are still yours, check for new forwarding rules, then scan. Changing passwords you did not type is wasted time.

On this page

The instinct after clicking something you should not have is to do everything at once: run a scan, change all your passwords, clear cookies, maybe reinstall something. Most of that is motion rather than progress, and the genuinely time-critical step gets done fourth.

The list below is ordered by what stops ongoing damage, not by what feels thorough. Work down it and stop at the point where the steps stop applying to what you actually did.

Step 0 — establish what you did

Thirty seconds, and it determines everything after.

What happened Urgency Start at
Page opened, nothing typed None Step 7
Password entered Hours Step 2
One-time code entered or login approved Minutes Step 2, immediately
Card details entered Minutes Step 6
File downloaded and opened Hours Step 1
Remote access software installed Minutes Step 1, then Step 2

Be honest about the password one. A fake login page that shows an error and then forwards you to the real site is a standard design, and the error is not evidence that the attempt failed. Assume anything typed was captured.

Step 1 — disconnect, but only if a file is involved

If you downloaded and ran something, or installed remote access software, cut the network now. Flight mode on a phone, Wi-Fi off or ethernet unplugged on a computer. This stops data leaving and stops instructions arriving.

If you only typed a password, do not disconnect. You need the network for Step 2, and the page that captured your password already sent it the moment you pressed submit. Disconnecting afterwards accomplishes nothing except delaying the fix.

If someone talked you into installing remote access software during a phone call, disconnect, then uninstall it, then assume everything typed while they were connected is known.

Step 2 — change the password you entered

The highest-value step, and the one that should happen before any scanning.

Use a different device if one is available, particularly if a file was involved on the first machine. Go to the service directly — type the address, or open the app you already have. Never through the email.

Change only the password you actually entered. Changing passwords you did not type is a common way of spending an hour achieving nothing, and it delays the steps below that matter more.

If you cannot sign in because the password has already been changed, the account is taken over and the procedure is different. Go to what to do when someone is logged into your account.

Step 3 — sign out every other session

Changing a password does not always evict existing sessions, and a stolen session cookie keeps working until it is revoked. This is the step most often skipped and the reason some people get re-compromised a week later.

Find the security or devices section of the account and use the option to sign out everywhere. Google’s version is covered in seeing where your Google account is signed in; Microsoft, Apple and the major social platforms all have an equivalent.

Step 4 — verify the recovery details

This is the step that determines whether the problem is over or merely paused.

Check the recovery email address and recovery phone number on the account. An attacker with even brief access changes these, because it gives them a way back in regardless of your new password. Remove anything unfamiliar.

While you are there, check whether two-factor authentication is enabled, and whether the second factor listed is yours. An authenticator app you did not add is a loud signal.

Step 5 — check for persistence

Specifically on email accounts, where the consequences compound.

  • Forwarding rules and filters. A rule silently copying your mail elsewhere, or deleting password-reset emails before you see them, survives every password change. Look under the account’s filters and forwarding settings and remove anything you did not create.
  • Connected apps and third-party access. Revoke anything unfamiliar.
  • App passwords. Some providers allow these for older mail clients, and they bypass two-factor authentication entirely. Revoke any you do not recognise.
  • Signature changes. Occasionally altered to add a malicious link to every message you send.

Step 6 — card details, if any were entered

Ring the number printed on the back of the card. Not a number from the email, and not one from a search result, which is itself a common scam route.

The card can be blocked and reissued in that call. Do not wait to see whether a charge appears, and do not dismiss a small unexplained charge as a glitch — small test transactions are how stolen cards are validated before being used properly.

Step 7 — now scan

Last, not first, and only genuinely necessary if a file was involved.

On Windows, use the offline scan rather than a quick scan, because it reboots and scans before Windows loads: Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan. The full procedure, including the cleanup afterwards, is in scanning for and removing malware on Windows.

On a Mac, check login items and browser extensions by hand first, as in checking your Mac for malware, then run one on-demand Malwarebytes scan.

On a phone, scanning is largely unavailable and largely unnecessary. Review installed apps and permissions instead.

Step 8 — report it

Forward the message to your email provider’s reporting address or use the in-client report button, which improves filtering for everyone. For a work account, tell IT first and before cleaning up, since your cleanup can destroy evidence they need. In the UK, suspicious emails can be forwarded to the National Cyber Security Centre’s reporting address and texts forwarded to 7726.

What to skip

  • Changing every password you own. Only those you typed, plus anywhere you reused that password.
  • Clearing cookies as the main response. Harmless, irrelevant to a captured credential.
  • Running four scanners. One good scan, one second opinion, stop.
  • Factory resetting after a click. Disproportionate, and it leaves the actual exposure untouched.
  • Waiting to see if anything happens. The checks above take fifteen minutes. Waiting costs you the window in which they work.

Realistic expectations

If you typed nothing, this is already over and Step 7 is optional reassurance. That is the most common outcome by a wide margin.

If you typed a password, Steps 2 to 5 take roughly fifteen minutes per account and close it properly. The cases that turn into long problems are almost always the ones where someone changed the password, felt finished, and never looked at the recovery email address or the forwarding rules. Those two checks are the difference between an afternoon and a month.

Frequently asked questions

How long do I have before it is too late?
For a typed password, usually hours — automated credential use is quick but not instant. For a one-time code, minutes, because the attacker is at the login screen waiting. Treat anything involving a code as the urgent case.
Should I disconnect from the internet straight away?
Only if you downloaded or opened a file. If you typed a password, disconnecting actively prevents you from doing the one thing that matters, which is changing it. The two situations call for opposite first moves.
Is a factory reset the safest response?
It is disproportionate for a clicked link and it does nothing about the credential you typed, which is usually the real exposure. Reserve it for a confirmed infection that keeps returning after proper removal.
Do I need to tell my bank if I did not enter card details?
Not usually. Banks are interested in card numbers, account details and payments you authorised under pressure. A clicked link with nothing entered is not something they can act on.
What if it was a work device or account?
Tell your IT or security team first, before trying to fix it. They may be tracking the campaign, they can see sign-in activity you cannot, and your own cleanup can destroy evidence they need.

All Security guides