Close the page, stop downloads and permission requests, and record what you did after opening the link. The correct response depends on whether you only viewed the page or also entered a password, shared a code, paid, installed software, or exposed identity information. Do not rely on clearing browser history as a security response.
Immediate steps after clicking
- Close the page and any pop-ups it opened.
- Cancel downloads and do not open downloaded files.
- Remove browser notification or site permissions you just granted.
- Update the browser, operating system, and trusted security software.
- Run a security scan when a file, app, extension, or profile may have been installed.
- Write down the URL, time, device, and information entered.
Disconnect the device from the network if an unknown app is running, remote access was granted, or the device is behaving unexpectedly. Use a known-clean device for urgent account and financial recovery.
If you only opened the page
Opening a page does not automatically mean an account was stolen or the device was infected. Modern browsers isolate much web content, but no browser eliminates all vulnerability risk. The more common danger is the action a page persuades the visitor to take.
Close it, review downloads and permissions, update the device, and monitor for unfamiliar behavior. Do not revisit the page to investigate. Private-browsing mode, airplane mode after the fact, or deleted history cannot undo information already sent to a server.
If you entered a password
Open the real service independently and change the password immediately. Use a new password that is not a variation of the exposed one. Change every other account that used the same or a similar password, starting with email, banking, cloud storage, and password-management accounts.
End other sessions, review recent logins, remove unknown devices, check recovery phone numbers and email addresses, and turn on two-factor authentication. For email, inspect forwarding rules, filters, sent messages, and deleted items because an intruder may use the mailbox to reset other accounts.
If you shared a one-time code or approved a login
Contact the provider and secure the account even if the password was never disclosed. A code or approval may authorize a sign-in, password reset, new device, or transaction. Change the password, end sessions, review recovery methods, and tell the provider which action occurred.
If you entered card or bank information
Call the financial institution using the number on the card, statement, or official app. Explain what information was entered and ask whether the card or account credentials should be replaced. Review pending and completed transactions and enable alerts.
If you sent money, contact the payment company immediately and ask about its fraud, dispute, or recall process. Options depend on the payment method and whether the transaction was authorized; recovery is not guaranteed.
If you entered identity information
Names and email addresses create different risks from a Social Security number, driverâs license, medical record, or tax information. Use IdentityTheft.gov to build a recovery plan for the information involved. For an SSN, review what to do when a Social Security number is exposed.
Be alert for follow-up scams that use the submitted information to sound credible. A person who claims to recover lost money for an advance fee may be targeting previous victims.
If you installed an app, extension, or profile
Disconnect the device when the software is still active or remote control is possible. Remove the app or extension and revoke device-administration, accessibility, notification, VPN, or configuration-profile permissions that you did not intend to grant. Update and scan the device.
Change important credentials from another trusted device. A factory reset may be justified when an attacker had administrative control, security tools cannot remove the software, or trust cannot be restored through ordinary review. Back up necessary personal files and follow the manufacturerâs process.
How to report a fake link
Use the report-phishing or report-junk function in the email, text, browser, or platform where the link appeared. Report consumer fraud at ReportFraud.ftc.gov and internet-enabled crime to the FBI Internet Crime Complaint Center when appropriate.
Notify the organization being impersonated through its official security channel. Preserve the original message, URL, screenshots, downloads, transaction identifiers, and timeline when there is a loss or account compromise.
How security tools help after a click
Security software may identify known malicious apps, files, or destinations. A scan cannot determine whether credentials were submitted to a convincing but technically simple page, and a clean result does not cancel a payment or secure an account.
Do not reopen the link to test it. If you preserved a public URL that contains no private token or account information, the URL Checker can add technical evidence for reporting. Account, payment, and device recovery should still follow what you entered, approved, paid, or installed.
PSafeâs analysis of incident response
List what you entered, downloaded, installed, or approved, then identify the accounts and payments each action exposed. This keeps you from changing unrelated passwords while leaving the affected account open, or scanning the device while ignoring credentials already submitted.
Secure the most sensitive exposure first, preserve evidence, and watch for follow-up scams.
Frequently asked questions
I closed the page immediately. Am I safe?
The risk is lower if you entered nothing, downloaded nothing, and granted no permissions. Update and review the device, but do not assume that closing alone reverses an action already completed.
Should I change every password?
Change the password entered and every account that reused it. Prioritize email and financial accounts. Unrelated unique passwords do not need to be changed solely because of the click.
Does clearing browser history remove malware?
No. It removes local browsing records. It does not uninstall apps, revoke permissions, recover accounts, or delete information submitted to a website.
Can antivirus tell whether my password was stolen?
No. It may detect malicious software or known sites. It cannot determine whether a page operator received information that you typed.
Should I contact the police?
Local law enforcement may be appropriate for a material financial loss, threats, stalking, or documentation requested by a financial institution. Also use the FTC, IC3, provider, and identity-theft reporting channels that fit the incident.