I Clicked a Phishing Link. Am I Fked?
You clicked the delivery text. Or the “your account is suspended” email. Or a message from your boss, who apparently now communicates exclusively through urgent gift-card requests.
Then you noticed the address looked like a keyboard fell down the stairs.
**If you clicked a phishing link but didn’t enter information, approve anything or install software, you’re usually at much lower risk.** A click alone does not automatically hand over your bank account. But what happened next matters.
Here’s how to work out whether you’re mildly rattled or actively cooked — and what to do now.
What should you do immediately after clicking a phishing link?
Stop interacting with the page. Don’t type anything else, approve a notification or call a number displayed there. Close the tab.
Then identify which situation applies:
- **You only opened the page:** follow the click-only steps below. - **You entered a password:** change it through the real service immediately. - **You entered card or banking details, or sent money:** contact your bank through a trusted channel now. - **You downloaded something:** don’t open it; check whether it installed or ran. - **You installed software or allowed remote access:** disconnect the affected device from the internet and use another trusted device for recovery. - **It involved work:** tell your IT or security team promptly, even if you’re embarrassed.
Open the genuine app or use a known address or bookmark. Don’t return through the suspicious message, and avoid sponsored search results when hunting for support.
If you clicked but didn’t enter anything
This is generally the least alarming scenario. Phishing usually works by persuading you to hand something over, not by making your phone explode through vibes.
Still, a malicious page may learn basic information such as your IP address and browser details. A unique link may also tell the sender that your address or number is active.
Take these sensible steps:
- Check your browser’s download list for unexpected files. Don’t open them. - Install available browser and operating-system security updates. - Remove any notification permission you granted to the suspicious site. - If you saw unexpected downloads, persistent warnings or strange behaviour, run your device’s built-in security checks or a reputable security scan where supported.
**Don’t install a “cleaner” advertised by the suspicious page.** The giant “YOU HAVE 37 VIRUSES” banner is not a diagnosis. It’s a sales pitch with a siren.
Rarely, malicious sites exploit browser or device vulnerabilities without further interaction. Keeping software updated reduces that risk. A click alone usually doesn’t justify a factory reset.
If you entered a password or verification code
Act quickly, using a trusted device if you suspect the original one is compromised.
Go directly to the genuine account and change its password to something unique. If you reused that password elsewhere, change it on those accounts too. Start with your email account because it can often reset access to everything else.
Then:
- Use “sign out everywhere” or revoke other sessions where available. - Review recovery email addresses, phone numbers and registered devices. - Remove unfamiliar connected apps and access permissions. - Check email forwarding rules and filters for changes you didn’t make. - Enable multi-factor authentication, preferably a passkey or security key where supported.
**Changing a password may not terminate every existing session.** Attackers can sometimes steal session tokens or obtain access by tricking you into approving a sign-in. Session controls matter too.
If you entered a one-time code, approved an unexpected login prompt or authorised an app, treat that as possible account access — even if you never typed your password into the fake page.
Locked out? Use the service’s official recovery process. Ignore strangers promising account recovery for a fee. That’s often the sequel nobody ordered.
If you entered bank details or sent money
Contact your bank or payment provider immediately through its genuine app, the number on your card or a trusted statement. Explain exactly what you shared or authorised.
If your app lets you freeze the affected card, that can be a useful temporary step while you contact the bank. It does not replace reporting the incident and may not stop every transaction.
Tell the bank whether you shared:
- A card number, expiry date or security code. - Online banking credentials or verification codes. - Account details only. - An authorised transfer to someone you now believe is a scammer.
These are different risks. Sharing an account number is not the same as giving someone your banking login, but your bank can assess the specifics.
Ask about securing access, replacing cards, disputing transactions or attempting to recall a transfer. **Recovery is not guaranteed**, and protections vary by country, payment method and circumstances.
Never move money to a “safe account” because an incoming caller tells you to. Hang up and contact the bank independently.
If you downloaded or installed something
Downloading a file is not the same as running it. If it remains unopened, remove it without launching it and check for anything else unexpected.
If you opened an executable, enabled document macros, installed an app or extension, or gave someone remote control, take it more seriously.
Disconnect the device from Wi-Fi or mobile data and unplug Ethernet. Stop using it for banking or password changes. From another trusted device, secure affected accounts and contact your bank if financial information may have been exposed.
For a work device, follow your organisation’s incident process before deleting files or attempting repairs. For a personal device, use reputable technical support if you’re unsure what ran or whether the device is clean. Some compromises need a proper rebuild, not an optimistic restart.
Your damage-control checklist
Once urgent containment is underway:
- Save the message, sender details, timestamps and relevant transaction references without reopening the link. - Report the message through the email service or messaging platform. - In the UK, forward suspicious emails to **report@phishing.gov.uk**; suspicious texts can generally be forwarded to **7726** through UK mobile networks. - Use your country’s official fraud-reporting route if money or identity information was stolen. - Monitor accounts for unfamiliar activity and unexpected password-reset messages. - Warn contacts if your account sent scam messages.
Reporting a message does not secure your account. Do the recovery steps too.
How fked are you, really?
These bands are a triage guide, **not measured probabilities**. Use the highest band that fits.
- **0–20: Rattled, probably not cooked.** You only clicked, your software is current, and nothing else happened. Check downloads and permissions, then stay alert. - **21–45: Exposed, but manageable.** You shared contact details or allowed notifications. Revoke permissions and expect more convincing follow-up scams. - **46–70: Account-compromise territory.** You entered credentials or approved access. Secure the account and revoke sessions now. - **71–90: Urgent containment.** You shared banking credentials, ran suspicious software or granted remote access. Involve your bank, IT team or reputable technical support as appropriate. - **91–100: Active damage.** Money is moving, accounts are being taken over or an attacker still has access. Prioritise professional help and containment immediately.
This is general security guidance, not legal or financial advice. Get qualified help for financial losses, identity misuse or a device you cannot confidently secure.
You are not doomed because you clicked. Phishing is designed to make ordinary people act before thinking. The useful question is what access you gave away — and how quickly you can take it back.
Want your own verdict? Tell **fked.ai** what happened and find out how fked you really are.