What should I do immediately after clicking a phishing link or entering my password on a suspicious site?

Business Tech & Tools

What should I do immediately after clicking a phishing link or entering my password on a suspicious site?

The short answer

If you only opened a page and entered nothing, close it, update your security software, and scan the device. If you typed a password, use a different trusted device to change that password immediately, end other sessions, turn on multifactor authentication, and change every other account that used the same password. If money or customer data may be involved, contact the financial provider or a qualified security professional now.

Do not spend an hour trying to decide whether the page was fake. The early protective steps are worth taking when the possibility is real.

First, match the response to what happened

What happened First response
You opened the page but typed nothing Close it, disconnect if the device behaves strangely, update protection, and scan
You downloaded or opened a file Take the device offline and seek qualified technical help if the file ran or warnings appear
You entered a password Change it from a trusted device and revoke active sessions
You approved an MFA prompt or shared a code Reset the account and factors; assume the login may have succeeded
You entered card or bank information Call the issuer or bank using a known number and watch transactions
You exposed customer or employee information Preserve evidence and begin your incident and legal-notification review

The FTC advises updating security software and running a scan after a suspicious link or attachment may have delivered malware. See its phishing guidance.

If you entered a password

Use a clean device and navigate to the real service from a saved bookmark or typed address. Then:

  1. Change the exposed password to a new, unique one.
  2. Sign out every other session or device.
  3. Turn on MFA or replace the factor that may have been approved.
  4. Review recovery email addresses, phone numbers, passkeys, keys, and app passwords.
  5. Remove unfamiliar forwarding rules, filters, connected apps, delegates, and devices.
  6. Check sent mail, deleted mail, account activity, and security alerts.
  7. Change reused passwords elsewhere, starting with email and financial accounts.

For email accounts, look closely at forwarding and mailbox rules. An intruder may leave access looking normal while silently copying messages or hiding replies.

If the device may be infected

Disconnect Wi-Fi or the network cable if you opened a suspicious attachment, installed anything, granted a browser extension permission, or see unexplained pop-ups, redirects, slowness, or security warnings. Do not use that device to change passwords.

Run the operating system's current security scan and install updates. If business-critical or sensitive data is on the device, get competent technical help before wiping evidence or restoring files. The FTC notes that a device known to be hacked or infected should be taken offline right away in its email spam and malware advice.

Protect money and people

Call a bank, card issuer, payroll service, marketplace, or payment processor through its official app or known number. Explain exactly what you entered and when. Ask about freezing activity, replacing credentials, and watching for attempted changes.

If an exposed account can message clients, warn them through a clean channel. Tell them not to trust recent payment changes, links, attachments, or urgent requests. Keep the warning factual and short.

When personal information may have been accessed, do not guess about notification duties. The FTC's Data Breach Response guide says businesses should secure operations, determine what information was affected, and assess notification requirements. Laws and contracts vary, so consult the appropriate insurer, counsel, security professional, regulators, or law enforcement for your situation.

Preserve a useful incident note

Record the time, sender, subject, visible URL, real URL if safely known, information entered, file opened, device used, accounts changed, people contacted, and screenshots. Do not forward a live malicious attachment to colleagues as your evidence.

After the immediate danger is controlled, fix the process that made the click costly: enable stronger MFA, use a password manager, add a payment-change verification rule, and run a short backup restore test.

Sources and further reading

A free next step

You don't have to build this alone

Bring your questions, share what you're working on, and meet other women building businesses from home. It is free to join.

Join Our Community Free

Related Questions

← All questions