I clicked a phishing link, what should I do now?
Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →
Part of our guide: What to do if you got scammed →
Take a breath: clicking a link, by itself, rarely hands anything over. The danger starts only if you then type a password, card number, or code into the page that opened. If all you did was tap and land on a form, you're very likely fine, close the tab and don't enter a single field.
Got a message like this? Paste it here →
These texts reach everyone, because everyone is expecting some kind of package, bill, or account notice. The message borrows a name you trust and adds a short deadline so you act before you think. It works best on people mid-task, glancing at a phone between other things, who tap first and read the address bar second.
Illustrative example of the pattern, not a real message someone received.
How to verify it yourself
- Look at the address bar of the page that opened. A real delivery or bank site uses its own exact domain, not a look-alike with extra words or an odd ending like .top or .info.
- Check whether the page is asking you to type anything. A link that just loads a page hasn't taken your information; a form that wants your password or card is the actual trap.
- Do not download or open any file the page offers. On a phone, clicking a link almost never installs anything unless you approve a download or an app install.
- Reopen the real service yourself by typing its known address or using its official app, never by continuing from the message you received.
Common questions
does clicking a phishing link infect my phone
On a modern phone, simply opening a link almost never installs malware on its own. Risk appears only if you approved a download, installed an app, or granted a permission, if you did none of those, you're very likely fine.
I opened the link but did not enter anything am I safe
Yes, most likely. Phishing pages work by collecting what you type; if you entered nothing, there is nothing for them to steal. Close the tab and move on.
should I change my password after clicking a scam link
Only if you actually typed your password into the page. A click alone doesn't expose it, but if you entered credentials, change that password now and turn on two-factor authentication.
what happens if I clicked but closed the page fast
Closing quickly is exactly the right move and means the page had no chance to collect anything from you. There's nothing further you need to fix beyond staying alert for follow-up messages.
If you already responded
- If you only tapped the link and saw a page load, stop here, do not type anything, and close the tab. A click on its own does not give a scammer your accounts.
- If a form appeared, do not fill in any field: no password, no card number, no verification code. That is the exact information the page was built to capture.
- If you DID type your password into the page, change that password now on the real site, and turn on two-factor authentication so a stolen password alone can't unlock the account.
- Delete the original message so you don't tap it again by accident, and block the sender's number if it came by text.
- Watch the next few days for follow-up messages that reference the same 'issue', scammers often try a second, more personal approach after the first link. Report the message at reportfraud.ftc.gov.