I clicked a phishing link. Here is what actually happens.
If you only opened it and closed it, almost certainly nothing happened. The click is not the crash: it is the switch. What decides is what you did in the ten seconds after.
An email or a text arrived, you tapped without thinking, and half a second later your stomach turned over. First things first: this happens to everybody, including people who do this for a living. Let us work out whether you actually have a problem.
First, slow your pulse
Most articles on this open with a list of catastrophes and leave you worse off than you arrived. We will go the other way, because that is what the facts support:
Opening a link, on its own, almost never compromises anything. An up-to-date browser opens the page inside a box walled off from the rest of the system. What does the damage is not the visit: it is what the page persuades you to do next.
So the useful question is not "did I click?". It is "what did I do after I clicked?"
The scale: place yourself before doing anything
Least to most serious. Find your rung and act only from there:
- 1. You opened it and closed it. Typed nothing, downloaded nothing. Almost certainly nothing happened. This is by far the most common case.
- 2. You opened it on your phone. Even less likely to matter: phone apps are more strictly separated from each other than programs on a computer.
- 3. A download started and you never opened it. A file sitting in your downloads folder does nothing until you run it. Delete it and get on with your day.
- 4. You typed your username and password. This is where the real problem starts, and it is the genuinely common scenario. Go to the section below.
- 5. You downloaded a file AND opened it. Especially an
.exe, an.msi, a.scr, or a document that asked you to "enable content". This is the serious one. - 6. You approved something. Read out a verification code over the phone, tapped "yes" on a prompt, or granted permissions to an app. This is the top rung, because your second factor stops protecting you.
Notice the jump: between 3 and 4 there is no half step, there is a chasm. Everything below it is noise; from there up, you act.
Why a click alone almost never infects
Worth understanding, because it is what will spare you the panic next time:
- The page opens sandboxed. The browser runs web content in a compartment separated from the operating system.
- Downloading is not running. A file reaching your disk does not mean it started. You have to open it.
- The system warns you first. Windows and macOS put a warning in front of anything downloaded and unsigned before it runs.
- And above all: phishing rarely wants to infect you. It wants you to type. That is cheaper and works better. The fake page is not a technical trap, it is a form.
The exception that is real, and when it matters
It would be dishonest to close with "do not worry" and stop there. Drive-by downloads exist: a page exploiting a browser flaw to install something without you touching anything.
But it is worth stating what that requires, because that is exactly the part usually left out: an out-of-date browser, and a flaw not yet patched. With current browsers, which update themselves silently, it is difficult and rare.
Translated into something you can act on: if your browser is current, this paragraph is not about you. If you have spent months ignoring "restart to update", do it now and stop reading for a moment.
If you only opened it and closed it
Rungs 1 to 3. This is the whole list, and it is not long:
- Close the tab and do not go back. No need to clear history or "clean" anything.
- Delete the downloaded file if there was one, without opening it.
- Check your browser is up to date. Two minutes, and it covers the exception above.
- Do not wipe the machine, do not change every password and do not buy anything. There is no reason to.
- Report the message as phishing in your mail client. It helps the next person not get it.
And that is it. Genuinely.
If you typed the password: the order matters
Rung 4, the common one. Here you do need to move, and the order is not the obvious one:
- 1. Change that account's password, going in through the official app or typing the address yourself. Never through the link in the message.
- 2. Sign out of every open session. This is the step almost nobody takes and the one that matters most: if they took the session cookie, they are still inside even after you change the password. Nearly every service has a "sign out of all devices".
- 3. Turn on two-factor authentication if you had not. It is what makes a stolen password worth little.
- 4. Change that same password anywhere you reused it. If it was on three other sites, you have four problems, not one.
- 5. If it was your email password, start there. Email is the master key: everything else is recovered through it. The steps are in this guide.
The usual mistake is doing 1 and skipping 2. Changing the password without ending sessions leaves the door just as open, except now you think you closed it.
If you downloaded and opened a file
Rung 5. The only part of this guide that justifies real concern:
- Disconnect the machine from the network if you genuinely suspect something. It cuts the data path while you get organised.
- Change passwords from ANOTHER device. Doing it from the suspect machine hands over the new ones too.
- Run a full scan, not a quick one, with the system's own antivirus, which you already have.
- Assume the browser's saved passwords are gone. They are the first thing this kind of program takes, and the browser cannot protect them: here is why.
- If it is a work machine, tell them now, however awkward. Telling them late is what turns an incident into a disaster.
The signs that something did happen
Do not hunt for these with a magnifying glass; if they appear, they are obvious:
- Sign-in alerts from places you have not been.
- Contacts receiving messages from you that you did not send.
- Your phone loses signal abruptly with no fault on the line. That is the signature of a SIM swap.
- New rules in your mailbox forwarding or filing things by themselves. It is the first thing an intruder sets up, so you never see the alerts.
- Small odd charges on the card. They test with a little before going for a lot.
That fourth point deserves a look even from rung 1: check your mailbox's forwarding rules. Thirty seconds, and it is where the quiet problem hides.
What not to do
- Wipe the computer "just in case". Disproportionate everywhere except rung 5, and not even the first step there.
- Install three more antivirus programs. They get in each other's way. The system's own, kept current, is enough.
- Go back to the page "to check something". There is nothing to check.
- Reply to the message to see what they say. It confirms your address is live and working.
- Change fifty passwords at once from the same machine. Order them by importance and do it from a clean one.
What to take away
That the click is the switch, not the crash. Almost everyone searching for this is on rung 1 and nothing has happened to them, and what they need is somebody to say so with reasons rather than sell them fear.
And if you are higher up the scale, the order is what matters: end sessions before almost anything else, and change passwords from a different device. With that settled, the rest is paperwork.
One last thing, for next time: if two-factor authentication was on for the affected account, the password you typed is worth rather little. It is the only measure in this guide that works for you before anything happens at all.
