What to do now
I clicked a phishing link: what to do now
Last checked
Do this now
Close the page and type nothing more
Close the tab or the app without filling in anything else, and do not use the page’s buttons.If something downloaded or installed, disconnect and scan
Do not open the file. Disconnect the device from the internet, run a full antivirus scan, and do not sign in to your accounts from it until the scan comes back clean.If you entered card or bank details, call your bank
Ask it to block the card and stop what can still be stopped. Find the number yourself, in your banking app, on your bank’s website or on the back of your card, never in the message. In the UK, 159 connects you to your bank.If you typed a password, change it from another device
Change it on the real site, which you open yourself, from a device you trust, and on every account that uses the same password. The full checklist after a password typed on a phishing site.If you allowed notifications or an app, remove it
- Notifications you accepted: on a computer, in Chrome, block the site in Settings › Privacy and security › Site Settings › Notifications. On an Android phone, turn notifications off for every site, so you do not open the page again: in Chrome, More › Settings › Site settings › Notifications, then turn off the setting at the top.
- An app you let into your Google account: on the account’s linked apps page (see Google’s help), choose Access to your Google Account › the app › See details › Remove access › Confirm.
- A profile installed on an iPhone: Settings › General › VPN & Device Management, then the profile, then Delete Profile; on a work phone, ask your IT team first.
Watch your accounts for the next few weeks
Look out for payments you did not make, sign-in alerts you did not trigger and messages your accounts sent without you.Report the message and the page
The services below use reports to have phishing pages blocked or taken down. Keep the message until you have reported it.
On this page07
Check it with isMalicious
isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.
URL scanner
Copy the link from the message rather than opening it again, and paste it into the URL scanner. The report shows whether threat intelligence sources list the URL or its host.
- What it does not mean
- Not listed is not proof of safety: a new or targeted phishing page is often unlisted at first. And a listing tells you the link is known to be malicious, not what happened on your device.
- Malicious URL database: the malicious and phishing URLs with enough threat intelligence for a report, shown as text, never as clickable links.
Report it
Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.
In the United States
IdentityTheft.gov (opens in a new tab)
If you gave personal or financial details: the steps for each kind of information you lost.
FTC, ReportFraud.ftc.gov (opens in a new tab)
Report the scam to the Federal Trade Commission, whether or not you lost money.
Anti-Phishing Working Group
The address the FTC gives for forwarding phishing emails.
Text 7726 (SPAM)
SMS7726Copy the scam text and forward it, then use your messaging app’s report junk option.
In the United Kingdom
Report Fraud (opens in a new tab)
If you lost money or were hacked, in England, Wales or Northern Ireland: report online or by phone. It replaced Action Fraud in December 2025.
Police Scotland (opens in a new tab)
In Scotland, report fraud and cyber crime to Police Scotland.
NCSC Suspicious Email Reporting Service
Forward the suspicious email. The NCSC analyses it and the sites it links to.
Text 7726
SMS7726Forward a scam text, free: it reports the message to your mobile provider. To report a call, text the word “Call” followed by the caller’s number.
NCSC: report a suspicious website (opens in a new tab)
Report a scam or phishing site.
Wherever you are
Google Safe Browsing (opens in a new tab)
Report the phishing page to Google.
Somewhere else? Report to your national police or your country’s cybercrime reporting service.
In France? The French version of this guide lists the French services.
How to spot the next one
- The link text and the address it opens are different. On a computer, hover over the link and read the address before you click.
- The address looks like the real one but is not: an extra word, a swapped letter, or the brand at the start of a longer address such as
paypal..com. account-check. example - The message pushes you to act now: an account about to be closed, a parcel held, a fine to pay today.
- It asks you to sign in or pay through the link instead of the app or the site you normally use.
Questions
I only clicked the link and typed nothing. Am I at risk?
If you did not enter any information, download a file or install anything, the UK’s National Cyber Security Centre says further action is unlikely to be needed. Stay alert to unusual emails and account notifications for a while.
The link came from a friend’s account. What does that mean?
Their account has probably been hacked. Tell them through another channel, a call or a different app, so they can change their password and warn their contacts.
Should I reply to the message to say I know it is a scam?
No. A reply confirms that your address or number is in use. Report the message instead, then delete it.
Is the URL scanner enough to know whether a link is safe?
No. It tells you whether threat intelligence sources already list the link or its host. A new or targeted page is often unlisted at first, so treat any unexpected link that asks you to sign in or pay as suspicious, listed or not.
Related guides
Change the password on the real site and everywhere you reused it, then lock the account down.
Read the link before you open it, and pay through the official app or site you open yourself.
Leave it closed, confirm with the sender another way, and check its hash if you want a second opinion.
Sources
The steps follow these official pages, read on :
- NCSCPhishing (opens in a new tab)
- NCSCPhishing scams: if you’ve shared sensitive information (opens in a new tab)
- FTCHow To Recognize and Avoid Phishing Scams (opens in a new tab)
- FTCMalware: How To Protect Against, Detect, and Remove It (opens in a new tab)
- GoogleUse notifications to get alerts (opens in a new tab)
- GoogleManage links between your Google Account & apps from other developers (opens in a new tab)
- AppleReview and delete configuration profiles (opens in a new tab)
- Cybermalveillance.
gouv. frQue faire en cas de phishing ou hameçonnage ? (opens in a new tab) (in French) - Service-Public.gouv.frHameçonnage (phishing ou vishing) (opens in a new tab) (in French)
- Cybermalveillance.
gouv. frPiratage d’un système informatique de particulier, que faire ? (opens in a new tab) (in French)
Free account
Keep checking with a free account
Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.
No credit card required