Skip to content
Breachfolio
A hand switching a single railway point as a train approaches, one route lit in red
GUIDES · PHISHING

I clicked a phishing link. Here is what actually happens.

The short answer

If you only opened it and closed it, almost certainly nothing happened. The click is not the crash: it is the switch. What decides is what you did in the ten seconds after.

An email or a text arrived, you tapped without thinking, and half a second later your stomach turned over. First things first: this happens to everybody, including people who do this for a living. Let us work out whether you actually have a problem.

12 min read

First, slow your pulse

Most articles on this open with a list of catastrophes and leave you worse off than you arrived. We will go the other way, because that is what the facts support:

Opening a link, on its own, almost never compromises anything. An up-to-date browser opens the page inside a box walled off from the rest of the system. What does the damage is not the visit: it is what the page persuades you to do next.

So the useful question is not "did I click?". It is "what did I do after I clicked?"

The scale: place yourself before doing anything

Least to most serious. Find your rung and act only from there:

  • 1. You opened it and closed it. Typed nothing, downloaded nothing. Almost certainly nothing happened. This is by far the most common case.
  • 2. You opened it on your phone. Even less likely to matter: phone apps are more strictly separated from each other than programs on a computer.
  • 3. A download started and you never opened it. A file sitting in your downloads folder does nothing until you run it. Delete it and get on with your day.
  • 4. You typed your username and password. This is where the real problem starts, and it is the genuinely common scenario. Go to the section below.
  • 5. You downloaded a file AND opened it. Especially an .exe, an .msi, a .scr, or a document that asked you to "enable content". This is the serious one.
  • 6. You approved something. Read out a verification code over the phone, tapped "yes" on a prompt, or granted permissions to an app. This is the top rung, because your second factor stops protecting you.

Notice the jump: between 3 and 4 there is no half step, there is a chasm. Everything below it is noise; from there up, you act.

Why a click alone almost never infects

Worth understanding, because it is what will spare you the panic next time:

  • The page opens sandboxed. The browser runs web content in a compartment separated from the operating system.
  • Downloading is not running. A file reaching your disk does not mean it started. You have to open it.
  • The system warns you first. Windows and macOS put a warning in front of anything downloaded and unsigned before it runs.
  • And above all: phishing rarely wants to infect you. It wants you to type. That is cheaper and works better. The fake page is not a technical trap, it is a form.

The exception that is real, and when it matters

It would be dishonest to close with "do not worry" and stop there. Drive-by downloads exist: a page exploiting a browser flaw to install something without you touching anything.

But it is worth stating what that requires, because that is exactly the part usually left out: an out-of-date browser, and a flaw not yet patched. With current browsers, which update themselves silently, it is difficult and rare.

Translated into something you can act on: if your browser is current, this paragraph is not about you. If you have spent months ignoring "restart to update", do it now and stop reading for a moment.

If you only opened it and closed it

Rungs 1 to 3. This is the whole list, and it is not long:

  • Close the tab and do not go back. No need to clear history or "clean" anything.
  • Delete the downloaded file if there was one, without opening it.
  • Check your browser is up to date. Two minutes, and it covers the exception above.
  • Do not wipe the machine, do not change every password and do not buy anything. There is no reason to.
  • Report the message as phishing in your mail client. It helps the next person not get it.

And that is it. Genuinely.

If you typed the password: the order matters

Rung 4, the common one. Here you do need to move, and the order is not the obvious one:

  • 1. Change that account's password, going in through the official app or typing the address yourself. Never through the link in the message.
  • 2. Sign out of every open session. This is the step almost nobody takes and the one that matters most: if they took the session cookie, they are still inside even after you change the password. Nearly every service has a "sign out of all devices".
  • 3. Turn on two-factor authentication if you had not. It is what makes a stolen password worth little.
  • 4. Change that same password anywhere you reused it. If it was on three other sites, you have four problems, not one.
  • 5. If it was your email password, start there. Email is the master key: everything else is recovered through it. The steps are in this guide.

The usual mistake is doing 1 and skipping 2. Changing the password without ending sessions leaves the door just as open, except now you think you closed it.

If you downloaded and opened a file

Rung 5. The only part of this guide that justifies real concern:

  • Disconnect the machine from the network if you genuinely suspect something. It cuts the data path while you get organised.
  • Change passwords from ANOTHER device. Doing it from the suspect machine hands over the new ones too.
  • Run a full scan, not a quick one, with the system's own antivirus, which you already have.
  • Assume the browser's saved passwords are gone. They are the first thing this kind of program takes, and the browser cannot protect them: here is why.
  • If it is a work machine, tell them now, however awkward. Telling them late is what turns an incident into a disaster.

The signs that something did happen

Do not hunt for these with a magnifying glass; if they appear, they are obvious:

  • Sign-in alerts from places you have not been.
  • Contacts receiving messages from you that you did not send.
  • Your phone loses signal abruptly with no fault on the line. That is the signature of a SIM swap.
  • New rules in your mailbox forwarding or filing things by themselves. It is the first thing an intruder sets up, so you never see the alerts.
  • Small odd charges on the card. They test with a little before going for a lot.

That fourth point deserves a look even from rung 1: check your mailbox's forwarding rules. Thirty seconds, and it is where the quiet problem hides.

What not to do

  • Wipe the computer "just in case". Disproportionate everywhere except rung 5, and not even the first step there.
  • Install three more antivirus programs. They get in each other's way. The system's own, kept current, is enough.
  • Go back to the page "to check something". There is nothing to check.
  • Reply to the message to see what they say. It confirms your address is live and working.
  • Change fifty passwords at once from the same machine. Order them by importance and do it from a clean one.

What to take away

That the click is the switch, not the crash. Almost everyone searching for this is on rung 1 and nothing has happened to them, and what they need is somebody to say so with reasons rather than sell them fear.

And if you are higher up the scale, the order is what matters: end sessions before almost anything else, and change passwords from a different device. With that settled, the rest is paperwork.

One last thing, for next time: if two-factor authentication was on for the affected account, the password you typed is worth rather little. It is the only measure in this guide that works for you before anything happens at all.

Frequently asked questions
I only opened it and closed it. Do I need to do anything?
Almost nothing. Close the tab, check your browser is up to date, and report the message as phishing. Opening a page without typing or downloading anything almost never compromises the machine: the browser runs it sandboxed from the rest of the system. No need to wipe anything, change passwords, or install something.
What if it was on my phone?
Even less cause for concern. On Android and iOS apps are more strictly separated from one another than programs on a computer, and a web page cannot install anything by itself. The real phone risk is the same as the computer one: that you typed the password, or installed something from outside the official store and granted it permissions.
I typed the password but caught it immediately. Am I in time?
Usually yes, and the sooner the better, but do it in the right order: change the password by going in through the official app, then sign out of every open session. That second step is the one almost nobody takes and the one that decides it: if the session cookie was taken, they can stay inside even though the password is now different.
Do I need to wipe my computer?
Almost never. It is only worth considering if you downloaded a file and also ran it, and even then it is not the first step: changing passwords from another device and running a full scan come first. Wiping the machine because you clicked is like changing the locks because somebody rang the doorbell.
Is running an antivirus scan worth it?
Worth it if you ran something; if you only opened the page there is nothing to find. And in that case use the one already built into the system, with a full scan rather than a quick one. Installing two or three more does not multiply the protection: they interfere with each other and usually leave the machine worse off.
It was on my work computer. Should I tell them?
Yes, now, and even if you think nothing happened. In a company the information matters more than the blame: telling them early lets them review access and cut things off, and telling them late is what turns a small incident into a large one. Nobody was ever fired for reporting a click quickly; for sitting on it for three days, some have been.