Your device and accounts are at immediate risk, but the damage depends on what you do next
Clicking a phishing link does not automatically infect your device or steal your passwords. What happens next depends on three things: whether the link downloads malware, whether it takes you to a fake login page, and whether you enter your password or personal information. If you clicked but did nothing else, you are likely safe. If you entered login credentials or downloaded a file, you need to act now.
The most dangerous moment is not the click itself — it is the second or two after, when you might type your password into a fake website that looks real, or when a downloaded file silently installs software that watches everything you type.
Key Takeaways
- Clicking a phishing link alone does not compromise your accounts; entering your password on a fake login page does.
- If you clicked and then closed the page without entering anything, check your device for unusual activity but you are likely safe.
- If you entered a password, change it immediately in your real account, not through any link in the email.
- If you downloaded a file from the link, run a malware scan on your device and consider having a technician review what was installed.
- Report the phishing email to your email provider so they can warn other users and block the sender.
What actually happens when you click
A phishing link is just a URL — clicking it does one of three things. It either takes you to a fake website designed to look like your bank or email provider, it downloads a file to your device, or it does both. The click itself changes nothing on your device or accounts.
Your browser loads the page the link points to. If it is a fake login page, you see a form asking for your username and password. If it is a malware download, your browser may ask whether you want to save the file, or it may download automatically depending on your browser settings. If the link points to a legitimate website that has been hacked, you might see the real site with no obvious sign anything is wrong.
The danger starts only if you take the next step: typing your password into that fake form, or opening the downloaded file.
If you entered your password on a phishing page
Change your password immediately. Do not click any link in the phishing email to do this — open a new browser tab, type the real website address yourself, and log in with your current password. Then change it to something you have never used before.
The attacker now has your old password. They will try it on your email account, your bank, your social media, and anywhere else they can think of. If you use the same password in multiple places, change it everywhere. If you use a password manager, it can show you which accounts share the same password.
After you change your password, check your account activity. Look for logins from places you do not recognize, or changes to your recovery email or phone number. If you see suspicious activity, change your recovery information immediately and consider enabling two-factor authentication if you have not already.
Tell your email provider what happened. Most have a "Report Phishing" button in the email itself, or you can forward the email to their abuse team. This helps them block the sender and warn other users.
If you downloaded a file from the phishing link
Do not open it. If you already opened it, run a malware scan on your device right now. On Windows, open Windows Defender (search for "Windows Defender" in your start menu), click "Virus and threat protection," and select "Scan options." Choose "Full scan" and let it run — this can take an hour or more.
On Mac, download and run Malwarebytes (malwarebytes.com). It is free for a single scan. Let it complete and remove anything it finds.
If the scan finds malware, remove it and change all your passwords from a different device if possible. Malware can log your keystrokes, so passwords you type on an infected device may be compromised even after you change them.
If you are not confident the scan caught everything, or if you use your device for banking or work, consider having a technician look at it. A full professional scan costs between $100 and $300 but can catch things automated scans miss.
If you clicked but did nothing else
You are almost certainly safe. Clicking a link does not run code on your device or access your accounts. Watch your accounts for unusual activity over the next few days — unexpected logins, password reset emails you did not request, or charges you do not recognize — but in most cases, nothing will happen.
If the phishing email came to your work account, tell your IT department. They may want to check whether the link was part of a larger attack targeting your company, or whether other employees received the same email.
How to tell if a page is fake before you type anything
Before you enter any password, look at three things: the web address in your browser's address bar, the security indicator, and the page design.
The address bar shows the real website you are on. Phishing pages often use addresses that look similar to the real thing — "amaz0n.com" instead of "amazon.com," or "paypa1.com" instead of "paypal.com." If you are not sure, close the page and type the address yourself instead of clicking a link.
The security indicator is a small padlock or checkmark next to the address. A fake login page might have this too, so do not rely on it alone. But if the address looks wrong and there is no padlock, that is a red flag.
The page design sometimes gives it away. Phishing pages are often slightly off — buttons in the wrong place, text that does not quite match, or a logo that looks low-quality. But good phishing pages look nearly identical to the real thing, so design alone is not reliable.
The safest habit is to never click links in emails to log in to anything. Instead, open a new browser tab, type the website address yourself, and log in from there. This takes five extra seconds and makes phishing nearly impossible.
What to do if someone else clicked your phishing link
If a family member or coworker tells you they clicked a phishing link, ask them three questions: Did you enter your password? Did you download anything? Did you open any files? Their answers determine what happens next.
If they only clicked and closed the page, they are probably fine. If they entered a password, they need to change it immediately. If they downloaded or opened a file, they need to run a malware scan.
Do not blame them. Phishing emails are designed by professionals to look real, and even careful people click them sometimes. The important thing is catching it quickly and taking the right steps.
Frequently Asked Questions
Can a phishing link install malware just by clicking it?
Not on modern devices. Clicking a link loads a web page — it does not run code on your computer. Malware installs only if you download and open a file, or if you visit a website that exploits a security flaw in your browser (rare on updated devices). Clicking alone is safe.
How do I know if my password was actually stolen?
You do not know for certain unless you see suspicious account activity. But if you entered your password on a phishing page, assume it was stolen and change it immediately. Do not wait to see if something happens — change it now, then watch for unusual activity over the next few weeks.
Should I be worried if I clicked a phishing link at work?
Tell your IT department right away, even if you did not enter anything. They need to know so they can check whether the link was part of a targeted attack on your company, and whether other employees received it. They can also check your device for malware if you are worried.
What if the phishing email came from someone I know?
Their email account was probably hacked. Do not click any links in it. Tell them directly (by phone or in person, not by email) that their account is compromised so they can change their password. Do not reply to the email or click anything in it.
Can I get my money back if I entered my bank password?
Contact your bank immediately and tell them what happened. Banks can freeze your account and watch for fraudulent transfers. Whether you can recover stolen money depends on how quickly you report it and your bank's policies — some banks cover fraud losses, others do not. Call the number on the back of your card, not any number in the phishing email.