I clicked on a phishing link: What should I do? (2024)

Table of Contents

What happens if you click on a phishing link?

URL phishing — or manipulating users to click on malicious links — is a social engineering attack (and a common cybersecurity threat). Phishing links can be programmed to do several different things, from passing your information to spreading malware. Here’s what may happen when you click on a phishing link.

Cybercriminals may get your information

Clicking on a phishing link may instantly transmit your location and device information to malicious actors. With this information in their hands, they may be able to target you with location-based scams or commit other types of cybercrimes (like financial fraud or identity theft). Additionally, cybercriminals may sell your compromised information on the dark web, enabling other malicious parties to target you.

You may be redirected to a phishing site

Some phishing links redirect you to fake websites (that often look legitimate), where cybercriminals may ask you to enter sensitive information. Sometimes, if your browser has security loopholes, just landing on a fraudulent website may trigger a malware download (known as a drive-by download).

It may install malware on your device

Some phishing links may be set up to download malicious files when you click them. This may be the most dangerous type because you have less time to stop the malware from spreading on your device.

The malicious download may contain spyware — dangerous malware designed to steal your information (like credit card details, usernames, and passwords). Some types of malware may also give the attackers remote access to your device.

What should you do if you click on a phishing link?

Even if you’re aware of the dangers of phishing, you may still sometimes fall for a clever phishing campaign. So what should you do if you open a phishing email and click on a phishing link? Here are the steps to take if you’ve done so.

  1. Don’t provide information. Clicking on a phishing link is bad — but clicking on a link and entering your information is worse. If you’ve clicked on a phishing link and were taken to a potentially malicious website, don’t enter any information or interact with the website in any way (e.g., click other links or accept cookies). What you need to do is leave the fake website immediately to avoid further problems.
  2. Disconnect from the internet. Going offline on your device is important because it interrupts whatever is happening behind the scenes — whether it’s a malware download or the attackers already harvesting your sensitive information. Disconnect from your Wi-Fi or turn on Airplane Mode on your phone — then you can safely investigate the attack further.
  3. Check your device for malware. Once you’re offline, check for signs of malware infection. If you’re using a desktop or a laptop, run a scan using your anti-malware software. The scan should detect if your device has been infected and display the steps for removing malware. For iOS devices, it may not always be possible to run an antivirus scan — we’ll talk more about this operating system in the FAQs.
  4. Back up your data. Malicious infections may damage or delete your files, so it’s important to back them up. Because you won’t be connected to the internet, the best way to back up your files is to use an external encrypted storage device. Be sure to back up your files only after removing malware to keep it out of the backup.
  5. Change your passwords. The next step is securing all your accounts that may be at risk (such as your bank or student loan account). Using a separate device, update your passwords and passphrases. For security reasons, don’t perform this step on the device you used when you clicked the phishing link — it should still be disconnected from the network. Check out our strong password guidelines for tips.
  6. Report the phishing link. Finally, report the phishing link to help protect others from falling for the same scam. You should perform this step after you’ve made sure that your device is safe and hasn’t been infected with malware. If the phishing link came from an email, go back to the email and click the “Report spam” button. You may also report the phishing email to an official government body, such as the Federal Trade Commission in the U.S. or the National Cyber Security Centre in the UK.

How can you protect yourself from phishing?

As internet users, we’re often targeted by phishing scams. While companies do their part to prevent phishing, make sure you’re also taking steps to keep yourself safe. Here’s how to protect yourself from phishing.

  • Learn to detect phishing. Get familiar with how phishing attempts look, sound, and feel so that you can learn to recognize them. Though phishing attacks can sometimes be difficult to spot, they often have common characteristics that give them away (like a sense of urgency and poor grammar). In addition to recognizing these attacks, using anti-phishing solutions that block dangerous phishing websites, can help you further enhance your online security. We’ll review the most common signs of a phishing attack in detail below.
  • Think before you act. When you receive an urgent email (e.g., with a subject like “Action required”), make sure you think before you do anything — use the SLAM method. Take the time to ensure the sender’s email address is legitimate by visiting the company’s official website or contacting the company at a number you trust (not one from the message). It’s highly unlikely that a legitimate company would expect you to take action the second you receive an email — so it’s best to slow down and carefully think it through.
  • Keep software up to date. Regularly updating your software generally improves your cybersecurity and can help defend against phishing campaigns. Software (and browser) updates often contain the latest security patches to keep you safe against constantly evolving threats.
  • Set spam filters for email. Most email providers allow you to set spam filters — specific filtering rules that keep out unwanted or potentially malicious emails. You can set these filters to look for specific criteria and stop emails that match the criteria from reaching your inbox. With the help of spam filters, you can automatically reduce the number of fraudulent emails you receive.
  • Use multi-factor authentication (MFA). While setting up multi-factor authentication won’t prevent phishing attacks, it may help protect your accounts from attackers. Multi-factor authentication asks account owners to authorize login attempts using a special code or a second device. While the attackers may have your login credentials, they hopefully won’t be able to authorize the login and reach the account.
  • Consider using a password manager. A password manager is a specialized tool that lets you securely create, store, and autofill your passwords. Password managers typically generate strong, unique passwords you don’t have to remember and autofill them for known websites. Plus, your passwords are stored in an encrypted vault, so even if attackers succeeded in accessing your device, they wouldn’t be able to steal your passwords. Check out more information about the NordPass password manager.

How to recognize phishing scams

Learning to recognize phishing scams is crucial. Most phishing campaigns have similar characteristics. Here are the most common.

  • A sense of urgency. Most attackers want to create a false sense of urgency so that you take action before you can think your actions through. The less time you have to think about what you’re doing (e.g., entering your login credentials), the less likely you are to notice the warning signs. If an email or a text message sounds unusually urgent and asks you to take action immediately, take a moment to pause and carefully review the message.
  • First-time or infrequent senders. While it’s possible to get an email from someone legitimate who has never emailed you before, it’s worth treating such emails with caution. If you receive an email marked as “External” or from a sender you don’t recognize, slow down and review the email carefully. Also, some companies would never use various messaging apps to contact you. For example, various Telegram scams could try to look like legitimate companies. If it feels off, you’re probably onto something.
  • Mismatched email domains. If you get an email supposedly from a reputable company like NordVPN or your bank, but the sender’s email address uses another domain (like Gmail.com), it’s probably a phishing scam. Also, watch out for slight misspellings of legitimate domain names (e.g., @n0rdvpn.com) — scammers often use these to trick users.
  • Bad spelling or grammatical errors. Cybercriminals rarely spell-check their content, so phishing emails and text messages are often littered with mistakes. While sometimes these errors result from awkward translation practices, other times they may be a deliberate approach. Scammers want to avoid people who notice these mistakes because they’re more likely to realize it’s a scam before they part with their money.
  • Generic greetings. When you get a legitimate email from a company about a product you use, it typically won’t have a generic greeting (like “Dear customer”). You will most likely have provided your name when signing up for their services, and most companies use personalization to make emails more engaging. If you receive an email with a generic greeting, it may be fraudulent.
  • Suspicious files or links. Most phishing attacks include suspicious attachments or links you’re urged to interact with. Legitimate companies (like banks) won’t send you emails with direct login links or attachments to open — so if you get such an email, it’s most likely a phishing scam. If you’re suspicious about a link, you can check if it’s legitimate by hovering over it with your mouse until its actual URL appears. With scam links, it’ll likely be a string of numbers that don’t look like the company’s web address. And always check for typos in the links so you don’t fall for a typosquatting attack.
  • Asking for empathy or compassion. Marijus Briedis, CTO at NordVPN, explained that the most common scam on Facebook consists of a post containing some variation of “I can’t believe he’s gone. I’ll miss him so much” and a link. Watch out for phishing scams that exploit your empathy or compassion by urging you to share personal information. Be wary of emails that tug at your heartstrings or ask for financial help. Always verify the legitimacy of such requests before taking any action.

For more information, check out our article on how to protect yourself from phishing emails.

Online security starts with a click.

Stay safe with the world’s leading VPN

Get NordVPN

Learn more

FAQ

I clicked on a phishing link: What should I do? (2024)

FAQs

Should I be worried if I clicked on a phishing link? ›

Clicking on a phishing link may instantly transmit your location and device information to malicious actors. With this information in their hands, they may be able to target you with location-based scams or commit other types of cybercrimes (like financial fraud or identity theft).

What if I accidentally clicked on a suspicious link on my phone? ›

We have a detailed guide on scanning and removing malware from your Android phone. However, the safest method is to perform a factory reset, so back up your phone and then reset it.

What happens if you reply to phishing? ›

You're Telling Attackers Where to Attack

Because it confirms that your email address is valid and frequently monitored. If you respond to a phishing email, you're essentially playing a digital version of "Marco Polo" with the attacker.

Can you get phished by opening a link? ›

Alternatively, clicking on a link can direct you to a dangerous phishing website where you're prompted to enter your personal information. Continue reading to learn more about how clicking a link can lead to getting hacked and how to avoid clicking on these malicious links.

Will I get hacked if I accidentally open a link in an email but closed it right away? ›

No, you cannot get hacked just by opening an email. The only way you can get hacked through an email is by interacting with the contents of the email, such as clicking on a malicious link or attachment. Continue reading to learn more about malicious emails and how to avoid getting hacked through them.

Can a phone be hacked by clicking on a link? ›

Fake or malicious websites can hack your phone through sophisticated drive-by downloads that can launch an attack without any user interaction such as clicking a link or downloading a file. Even legitimate websites can be abused by hackers to infect your device via malvertising pop-ups and banners.

What if I accidentally opened a phishing email? ›

If you've accidentally opened a phishing email or clicked on a suspicious link, don't panic. Take immediate action to protect yourself by marking the email as spam, reporting it to your IT department or company, refraining from further interaction with the email, and deleting it from your inbox.

What to do if you responded to a phishing text? ›

What to do if you clicked on a link in a spam text message:
  1. Disconnect from your Wi-Fi and/or mobile network. Hackers need an internet connection to access your device. ...
  2. Scan your device for malware and viruses. ...
  3. Change your passwords and enable two-factor authentication (2FA). ...
  4. Update your device and apps.

What happens after being phished? ›

When you are phished, scammers convince you to give up sensitive data — such as passwords, bank account information, or your Social Security Number (SSN) — by tricking you with beguiling emails, phone calls, and texts. With firm purchase on your information, phishers can steal your money or, worse, your identity.

What if I clicked on a phishing link but did not enter password? ›

If you clicked on a link by accident but didn't enter any login details or information, it is possible that no harm was done. However, it's still important to follow safety precautions. Phishing threats are constantly evolving. Some viruses only require a link click to affect your device.

How can you tell if your phone has been hacked? ›

If your device is quick to heat up, it might be due to malicious activity. If apps you haven't downloaded suddenly appear on your screen, or if outgoing calls you don't remember making pop up on your phone bill, that is a definite red flag and a potential sign that your device has been hacked.

How to check if a link is phishing? ›

Here are a few ways you can check the safety of a link before you click on it.
  1. Hover your mouse over the link. ...
  2. Use a URL checker. ...
  3. Don't enter any data. ...
  4. Don't click on anything on the site. ...
  5. Disconnect from the internet. ...
  6. Do a full scan of your device using antivirus software. ...
  7. Keep an eye on your accounts.
Feb 9, 2023

How serious are phishing attacks? ›

Phishing is dangerous because it preys on human error and bypasses even the most robust technical defenses. Cybercriminals can gain access to sensitive data like account information, email addresses, and personal material, leading to identity theft and financial loss.

How do I know if I have been phished? ›

Here are some ways to recognize a phishing email: Urgent call to action or threats - Be suspicious of emails and Teams messages that claim you must click, call, or open an attachment immediately. Often, they'll claim you have to act now to claim a reward or avoid a penalty.

What happens if I open a phishing attachment? ›

If you downloaded any attachments from a phishing email, don't open them — they could contain malware that can steal your personal information or lock you out of your data.

How do I check if a phishing link is safe? ›

To find out if a link is safe, just copy/paste the URL into the search box and hit Enter. Google Safe Browsing's URL checker will test the link and report back on the site's legitimacy and reputation in just seconds. It's that easy to use Google's URL scanner.

Top Articles
How to Unblock Websites Without a VPN: 3 Easy Methods
Library Guides: History: Archives and Archival Research
Devotion Showtimes Near Xscape Theatres Blankenbaker 16
Xre-02022
Lowe's Garden Fence Roll
Victor Spizzirri Linkedin
Ohio Houses With Land for Sale - 1,591 Properties
Edina Omni Portal
Uca Cheerleading Nationals 2023
Craigslist Monterrey Ca
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Form V/Legends
Chatiw.ib
Mate Me If You May Sapir Englard Pdf
9192464227
Brendon Tyler Wharton Height
Mama's Kitchen Waynesboro Tennessee
Nwi Police Blotter
Oppenheimer & Co. Inc. Buys Shares of 798,472 AST SpaceMobile, Inc. (NASDAQ:ASTS)
Best Cav Commanders Rok
B67 Bus Time
Celsius Energy Drink Wo Kaufen
U.S. Nuclear Weapons Complex: Y-12 and Oak Ridge National Laboratory…
Tamilrockers Movies 2023 Download
Unterwegs im autonomen Freightliner Cascadia: Finger weg, jetzt fahre ich!
Where to Find Scavs in Customs in Escape from Tarkov
CDL Rostermania 2023-2024 | News, Rumors & Every Confirmed Roster
Amazing deals for Abercrombie & Fitch Co. on Goodshop!
Mail.zsthost Change Password
Theater X Orange Heights Florida
Encore Atlanta Cheer Competition
Lisas Stamp Studio
Craigslist Dubuque Iowa Pets
Speechwire Login
Orange Park Dog Racing Results
Cinema | Düsseldorfer Filmkunstkinos
Yu-Gi-Oh Card Database
How to Use Craigslist (with Pictures) - wikiHow
Citibank Branch Locations In Orlando Florida
Avance Primary Care Morrisville
10 games with New Game Plus modes so good you simply have to play them twice
Eastern New Mexico News Obituaries
Timberwolves Point Guard History
Anhedönia Last Name Origin
How to Print Tables in R with Examples Using table()
Umd Men's Basketball Duluth
Santa Clara County prepares for possible ‘tripledemic,’ with mask mandates for health care settings next month
Dr Mayy Deadrick Paradise Valley
Professors Helpers Abbreviation
Rite Aid | Employee Benefits | Login / Register | Benefits Account Manager
bot .com Project by super soph
Espn Top 300 Non Ppr
Latest Posts
Article information

Author: Errol Quitzon

Last Updated:

Views: 6467

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.