First: breathe. Clicking a link is scary but fixable if you act fast. What matters is whether you entered passwords, card numbers, or installed anything.

Right now (next 10 minutes)

  1. Stop — close the tab. Don't enter anything else.
  2. Disconnect — if you downloaded a file, don't open it. Run a scan with Windows Defender or Malwarebytes.
  3. Screenshot — save the text or email for reports, then delete it.
  4. Did you type a password? — change it immediately on a different device if possible. Start with email (that's the master key).

If you entered bank info or paid

Within 24 hours

Before you click next time

Paste any suspicious text into ScamCheck first. It's free, runs in your browser, and gives you a risk score plus a full action plan. Forward the link to parents — they're the #1 target.

Minute-by-minute if you just tapped

  1. Now: Close the tab. Do not enter more data.
  2. If you typed a password: Change it on a device you trust; enable 2FA
  3. If you typed a card: Call the issuer; watch for small test charges
  4. If you installed something or gave remote access: Disconnect, run a reputable malware check, change critical passwords from another device
  5. Document: Screenshot the text and URL bar if still visible

Passwords you should rotate first

Email, banking, Apple/Google ID, and any site where you reused the phished password. Use a password manager if you can—reused passwords turn one phish into many.

Watch for the second hit

After a successful phish, criminals often call pretending to be the bank’s fraud department. Hang up. Dial the number on your card. Never read one-time codes to someone who contacted you first.

FAQ