Clicked a Suspicious Link? What to Do Next

Clicked a suspicious email or text link? Take a breath. What you did afterward matters more than the message's scary wording. Opening a page, typing a password, installing software and allowing remote control are different situations. Start with the section that matches what happened.

This checklist helps you explain the situation and take sensible first steps. It cannot establish whether a device or account is safe. If a work computer, business account or customer information is involved, notify your organization's IT or security contact promptly and follow its incident instructions.

First, stop interacting with the message

Do not type more information, approve a sign-in request, pay a fee or follow a supposed helper's directions. Close the suspicious page. If you need to check an account, open its official app or use a website address you already trust.

A browser pop-up that tells you to call a phone number is a familiar tech-support scam tactic. Its logo, alarm sound or countdown does not make the number trustworthy. Use an independently verified contact instead.

If you only opened the page

Write down whether anything downloaded, whether you opened it and whether you entered any information. A page appearing on screen does not by itself establish that your password was stolen; it also does not establish that the computer is clean.

Check your browser's download list without opening an unexpected file. Keep supported browser, operating-system and security software current. If you see unfamiliar activity or cannot tell what happened, ask a trusted technician to assess the device. Avoid repeatedly visiting the page to test it.

If you entered a password or verification code

Use the legitimate service from a device you trust to change the affected password. Give that account a unique replacement. Change the password on any other account where you reused it, too. Start with important accounts such as email rather than spending time replying to the suspicious sender.

Turn on multifactor authentication, also called two-step verification, where available. Never approve a sign-in you did not initiate. If you shared a code or approved an unexpected prompt, tell your IT contact or the service's official support team exactly that; changing a password is not a complete incident assessment.

Check account access, not just the password

Review recent security activity and signed-in devices through the real service. Follow its instructions to remove unfamiliar access. Check whether recovery contact details have changed. For email, inspect forwarding settings and rules that could send copies of your messages elsewhere.

If you cannot sign in, use the provider's official account-recovery process. Google provides a compromised-account checklist covering security events, devices and account settings. Use guidance for the service you actually have; the buttons and recovery options differ.

If you downloaded software or allowed remote control

Tell a trusted technician the program's name, whether you opened it and whether another person controlled your screen. A download you never opened and a remote-control session deserve different explanations.

Do not continue banking or entering passwords on a device while an untrusted person has access. Get help assessing the device and ending that access. Updating security software and running a scan are useful steps, but deleting one file or seeing a clean scan does not answer every account-security question.

For a business device, avoid improvising cleanup before contacting IT. Your organization may need to preserve information about what happened.

If payment or personal information was involved

Contact your bank, card issuer or payment service immediately through its official app or a verified number. Explain the transaction and ask what recovery options are available. Do not send another payment to someone promising a refund.

If sensitive identity information was exposed, use IdentityTheft.gov for a recovery plan. You can report a scam at ReportFraud.ftc.gov. A report is useful, but it does not guarantee reimbursement.

Bring a clear account of what happened

Keep the original message and note the approximate time, device and accounts involved. Explain what you clicked, typed, downloaded, paid or permitted. You do not need to reopen the link to collect these details. Never send a technician your password or verification codes in an ordinary message.

Once the immediate situation is addressed, use our home security checklist to review safer habits. Our guides on choosing a password manager and backup questions to ask explain additional layers. Device protection, account safeguards and recovery planning serve different purposes; none makes a person completely unhackable.

Need help choosing the next step? Contact User Friendly Security and describe what happened. We will clarify the appropriate service, availability and scope before work begins. Buying an ongoing plan is not a promise of immediate incident cleanup. You can review the plan comparison separately when considering ongoing protection.

Reviewed October 6, 2026. Sources: Microsoft phishing guidance; FTC tech-support scam guidance; FTC recovery guidance; Google account-security guidance.

Back to blog