Resources · Security
What to do if you clicked a phishing link
You clicked, and a second later something felt off. Maybe the page looked almost right but not quite. Maybe it asked you to log in and you started to, then stopped. Maybe nothing happened at all, which somehow feels worse, because now you’re not sure.
First thing: you’re not careless, and you’re not the first. These emails are built by people whose full-time job is fooling careful, busy professionals. Falling for a good one isn’t a character flaw. What matters now is the next few minutes, and they’re worth doing in order.
Here’s the order: Stop. Lock. Watch.
Stop
Cut it off before it can do anything.
If you entered a password or downloaded a file, disconnect that device from the internet right now. Turn off the Wi-Fi or unplug the network cable. It sounds dramatic, but it’s the single most useful thing you can do in the first minute. A lot of the damage from a bad link happens after the click, when the page or a downloaded file quietly tries to reach back out to whoever sent it. Cutting the connection interrupts that.
Don’t type anything else into the page. Close it.
And don’t delete the email yet. It feels like the natural thing to do, get rid of it, but you’ll want it later to report the scam and to remember exactly what it looked like. Just leave it alone for now.
Lock
Now protect the account before anyone can use it.
If you entered a password, change it, and do it from a different device you trust, not the one you’re worried about. If you typed your email password into a fake page, assume that password is now in someone else’s hands and change it immediately.
Then change it anywhere else you used the same password. This is the part people skip, and it’s the part that matters most. Attackers know we reuse passwords, so the first thing they do with a stolen one is try it on your other accounts, your bank, your other email, your business tools. One reused password is one key that opens ten doors. If that key is out there, change every lock it fits.
Turn on the extra sign-in step, if it isn’t already on. You’ll see it called two-factor authentication or multi-factor authentication, but the idea is simple: even if someone has your password, they still can’t get in without a second thing, usually a code sent to your phone or generated by an app. The FTC recommends this specifically because it’s what stops a stolen password from becoming a stolen account. It’s the highest-value ten minutes you’ll spend on your security all year.
Check what’s connected to the account. This one gets missed. Most email accounts keep a list of the other apps and services you’ve allowed to connect to them, often under a “Security,” “Connected apps,” or “Third-party access” setting. If an attacker got in, they may have quietly linked something of their own, or a connection you don’t recognize may be theirs. Look through the list and remove anything you don’t use or don’t recognize.
If this was a work account, tell whoever handles your IT immediately, even if you feel embarrassed. Speed beats pride here every time. The faster they know, the faster they can check whether anyone else at the company got the same email, because you’re usually not the only target.
Watch
Over the next few days, keep an eye out for what a break-in leaves behind.
Look for messages in your sent folder you didn’t send. Look for new forwarding rules on your email, this is the sneaky one worth understanding. An attacker who gets into your email will often set up a rule that quietly copies all your incoming mail to an address of theirs, so even after you change your password, they keep reading along. Check your email settings for any forwarding or filter rule you didn’t create, and delete it.
Watch for password-reset emails you didn’t ask for, from any account. That’s often the first sign someone is working through your logins. And watch anything with money attached.
If a bank account or credit card was involved, call the bank directly, using the number printed on your card, not any number from the email or the website you landed on. If you think you gave up a Social Security number, bank account, or credit card number, the FTC’s IdentityTheft.gov walks you through the exact recovery steps for what you lost.
The honest part
Changing your password locks the attacker out going forward. It does not un-send anything they may have grabbed in those first few minutes. That’s not meant to scare you, it’s the reason the “Watch” step matters. Do the locking fast, then stay alert for a couple of weeks. Most of the time, moving quickly is enough. Occasionally it isn’t, and catching it early is what limits the damage.
How to not be here again
A few plain habits prevent most of this:
Check the actual “from” address, not just the name. Scammers count on you reading “Amazon” and not looking closer. The trick is a near-miss domain, a recently registered lookalike that reads right at a glance: amacon.com instead of amazon.com, gmall.com instead of gmail.com, an extra letter, a swapped one. Click or tap the sender name to see the real address behind it. If it’s off by even a character, that’s your answer.
Be suspicious of any link that drops you straight onto a password screen. A real company almost never emails you a link that lands directly on an “enter your password” page. When a link’s whole purpose is to get you to log in right now, treat that as a red flag and go to the site yourself, by typing the address you already know, instead of following the link.
Slow down when something wants you to hurry. Nearly every phishing message has a clock on it: your account will be closed, your payment failed, act now. That urgency is the trick. It’s designed to get you to click before you think. The FTC’s own guidance for small businesses says the same thing, when a message pressures you to act immediately, that pressure itself is the warning sign. When in doubt, contact the company or person a way you know is real, a number from your records, a website you type in yourself, and confirm before you do anything.
Turn on the extra sign-in step everywhere that offers it, especially email and anything with money. And consider a password manager, so a single leaked password doesn’t put everything at risk.
This guidance follows the U.S. Federal Trade Commission’s advice for small businesses and consumers on recognizing phishing and recovering after responding to it. To report a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org and file a report at ReportFraud.ftc.gov. If you lost personal or financial information, IdentityTheft.gov provides step-by-step recovery.
Most of this you can do yourself, and if you’ve read this far, you’re already ahead of most people. But if your email or accounts got hit and you’d rather have someone steady walk through it with you, or you’d like to shore things up before anything happens, that’s the kind of thing we help small businesses and practices with.
Email Adero