Clicked a phishing link or entered your details on a fake page?

Clicking a phishing link is common, and most of the time nothing further happens. The risk comes from what you did next — entering a password, a card number, or an authentication code on a page designed to look genuine.

This page sets out the order that matters, what to check on your device, and where Cyber Crisis Desk turns those steps into a tracked plan.

Working out what actually happened

  • Did you only click a link, or did you also type a password, code or card details?
  • Was the page a login look-alike, a fake invoice, a delivery notice, or something requesting a one-time code?
  • Did you download or open a file from the link or an attached message?
  • Did anything unusual happen afterwards — a redirect, a sudden install prompt, or the page closing itself?
  • Was this on a work device, a personal device, or a shared one?

Being precise about which of these applies changes what you need to do next, so it is worth two minutes of thought before you act.

Safe immediate actions, in order

  1. If you entered a password, change it first on the real site (typed directly or via a bookmark, never via the link you clicked), from a device you trust.
  2. Change any other account using the same or a similar password, starting with email, banking and anything financially sensitive.
  3. Add or check two-step verification (MFA) on the affected account and any reused elsewhere. If you entered a one-time code on the fake page, treat the account as compromised even with MFA on, and change the password too.
  4. Check the device for anything downloaded or installed as a result of the click, and run a reputable security scan if you are unsure.
  5. Review recent account activity — sign-ins, forwarding rules, saved payment methods, and any new devices or app connections.
  6. If you entered card details, contact your card issuer to flag the card and watch for unauthorised transactions.
  7. Warn anyone who might be targeted next — colleagues if it was a work account, or contacts if the message appeared to come from you.

Evidence worth preserving

  • A screenshot or copy of the phishing message, including the sender address and any link URL.
  • A screenshot of the fake page, if it is still reachable, without submitting anything further to it.
  • Account sign-in and activity logs from around the time of the click.
  • Bank or card statements showing any unauthorised activity.
  • A short timeline: when you clicked, what you entered, and what you changed and when.

What to avoid

  • Do not go back to the fake page to "check" it or enter anything else there.
  • Do not reuse a password you have used elsewhere, or a small variation of the old one.
  • Do not ignore it because "nothing seems wrong yet" — credential misuse is often delayed.
  • Do not attempt to trace or identify who sent the message. Cyber Crisis Desk is strictly defensive: no hack-back, no tracing.
  • Do not forward the phishing message to colleagues without warning them not to click it themselves.

Who to involve

  • Your bank or card issuer — promptly, if any payment or card detail was entered, or money has moved.
  • Your IT team or provider — if this happened on a work device or account, so they can check for wider exposure.
  • The genuine service being impersonated — many providers have a dedicated address for reporting phishing that copies their brand.
  • Your data-protection regulator — if other people's personal data was likely accessed through the compromised account. In the UK that is the ICO; other countries have their own authority and deadlines.
  • National reporting channels — for example Action Fraud and the NCSC in the UK, and the equivalent body where you operate.

Cyber Crisis Desk is not a law-enforcement, legal or forensic service and does not report on your behalf. It prepares the structured information you need to do so.

How Cyber Crisis Desk helps

A short free triage establishes exactly what was entered and where, then selects the matching playbook so you are not guessing at the right order of steps.

  • Client Next Action puts password and MFA changes first, ahead of anything else, so the highest-risk gap closes fastest.
  • Evidence requests tell you exactly which screenshots and logs to upload, and store them in your private case.
  • Recovery tracks record which accounts and devices have been checked, so nothing is missed.
  • Structured reports assemble the timeline for a bank, provider or authority if needed.
  • Monitoring and closure keeps the case open while you watch for follow-on fraud, and closes it once checks pass.

See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.

Watching for follow-on fraud

  • Check bank and card statements regularly for a few weeks after the incident, not just once.
  • Watch for password-reset emails you did not request — a sign someone is trying to pivot into other accounts.
  • Be extra cautious of follow-up messages referencing the incident itself, which can be a second phishing attempt.
  • Consider a fraud alert or credit monitoring if card or identity details were entered.

Clear limitations

  • We cannot recover money already transferred or reverse a fraudulent card transaction; only your bank can do that.
  • We cannot make account changes for you; only you or your administrator can act on your accounts.
  • This is guided response, not a substitute for a qualified incident-response team in a severe or regulated case.
  • We do not provide legal advice or make legal determinations for you.

Common questions

I only clicked the link but did not enter anything. Do I still need to act?
The risk is much lower, but check the device for anything downloaded automatically, and keep an eye on the account the message referenced. If in doubt, changing that one password costs little.
I have MFA turned on. Am I safe even though I entered my password?
MFA reduces the risk but does not remove it, especially if you also entered a one-time code on the fake page or the attacker used a real-time relay. Change the password and review recent account activity regardless.
Which passwords do I actually need to change?
Start with the account the phishing page impersonated, then any account using the same or a similar password. A password manager makes this far easier going forward by keeping every password unique.
How long should I keep watching for fraud afterwards?
Several weeks at minimum for statements and login alerts, longer if identity or card details were involved, since some misuse is delayed to avoid drawing attention.

Related incident help

Work through it with a plan

Emergency triage is free and takes a couple of minutes.