Skip to content
Privacy & Safety

What happens if you click a phishing link?

Clicking a phishing link rarely hands over your account by itself. What you do next decides whether it stays that way. Here is the first-response checklist.

Email Unsubscriber Team 9 min read
Flat vector illustration of a cursor arrow mid-click on a hooked link, beside a first-response checklist card, an unplugged power plug, a key in a fresh padlock, a 2FA shield, and a magnifying glass over a small bug.

You clicked the link before you finished reading the email. Now the page is loading, or a file just landed in your downloads, or nothing visible happened at all, and your stomach drops. The question is not academic anymore. You clicked, so what happens now?

Clicking a phishing link rarely hands over an account by itself. The danger starts if you then type a password, enter card details, or run a download the page offers. If you typed nothing, close the tab. If you entered credentials, change that password from a device you trust and turn on two-factor authentication now.

What actually happens the moment you click?

Three things can happen when you click, and only one of them is dangerous the instant it happens. Knowing which one you are looking at tells you how far to go.

The most common outcome is the quietest. The link pings a server the attacker controls and confirms that a real person reads this inbox. Nothing loads that looks alarming, and nothing downloads. Your reward is more spam, because a confirmed live address is worth more on the lists attackers buy and sell. Phishing is the volume game behind this: the FBI’s Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in its 2024 annual report, more than any other category of internet crime that year.

The second outcome is a fake page that asks you for something. It clones a login screen for your bank, your email, or a store, and asks you to sign in to “verify” or “confirm.” Whatever you type there goes straight to the attacker. This is the one that turns a click into a compromised account, and it needs you to act before it works.

The third outcome is the rarest and the most serious: the page tries to run malware. Usually it does this by talking you into it, with a fake “update your browser” button or a file that downloads on its own. A true drive-by that infects a current device with no action from you is uncommon in mass phishing, though not impossible.

Usually not, if your browser and operating system are up to date. A single click that loads a page rarely installs anything by itself. Modern browsers sandbox web pages, and the exploits that would break out of that sandbox are valuable, so attackers spend them on targets worth more than a random inbox. On a fully patched phone, the risk from one click is close to zero for the mass campaigns most people meet. The same logic covers simply opening the message: opening an email on its own rarely infects you, and the danger starts only when you act on what is inside.

The real risk sits one step later, in what you do after the page loads. Typing a password, entering card details, or running a download is the action that hands something over. The page is built to make that next step feel routine.

Malware is still worth taking seriously when a file downloaded. The FTC’s guidance on recognizing and avoiding phishing scams is blunt about it: if you think you clicked a link or opened an attachment that downloaded harmful software, update your security software and run a scan. An outdated device is where the odds shift against you, so the patch you keep postponing is doing quiet defensive work.

What should I do right now if I just clicked?

Work through these in order. Most people only need the first step and the last one, but do the ones that match what you did.

  1. Stop and enter nothing. Close the tab. Do not type a password, do not fill a form, and do not go back to “finish” the unsubscribe or the verification. Landing on a page is not the same as handing over an account. The form is where the damage lives.
  2. Disconnect if a download started. If a file began downloading or a page pushed an installer at you, turn on airplane mode or pull the Wi-Fi. Cutting the connection stops malware from calling home or pulling down a second stage while you sort out the device.
  3. Change any password you typed, from a device you trust. Use a phone or computer you did not click from and have scanned for malware. Google, Microsoft, and the FTC all warn that a keylogger on the affected device steals your new password the moment you type it. Start with your email password, since your inbox resets everything else.
  4. Turn on two-factor authentication. With a second factor set, a stolen password alone no longer opens the account. This is the single most useful thing you can do after a credential slip.
  5. Scan the device. Run a full scan with reputable security software, not a quick one, and remove anything it flags. Do this while offline if a download ran.
  6. Report the phishing message. Use Report phishing in your email app, then report the scam to the FTC.

Done in that order, you close the credential door and the malware door before either one becomes a real problem.

What if I already typed my password or card details?

This is the case that rewards speed, so move now. The attacker may try your stolen login across other services within minutes, and a reused password turns one leak into several.

Change the password on the real site first, from a device you trust. If you used that same password anywhere else, change it there too, because attackers assume you reused it and check. Turn on two-factor authentication while you are in the settings. Then watch the account for sign-ins you do not recognize, new forwarding rules, or filters you did not create, which are the footprints of someone who got in and wants to stay. Our guide to spotting whether your email account is hacked walks through that cleanup in full, including the hidden forwarding rules a password change does not remove.

If you entered card details, call your bank or card issuer and tell them the number may be compromised. They can watch for fraud or reissue the card. If you handed over other personal information, such as a Social Security number, the FTC’s IdentityTheft.gov gives a tailored recovery plan for what you lost.

What if a file downloaded or a page told me to install something?

Treat it as a malware attempt until a scan says otherwise. Do not open or run the file, and do not click the “update” or “verify you are human” button the page offered, since those prompts are the delivery mechanism, not a real fix.

Disconnect the device from the internet first. Then run a full antivirus or anti-malware scan and let it quarantine or remove what it finds. After that, watch the device for the tells of an infection: a battery that drains fast, a phone or laptop running hot, apps or extensions you did not install, pop-ups, or a jump in data use. If anything looks off after a clean scan, or the device is one you cannot afford to get wrong, take it to someone who can inspect it properly.

Report it in two places: your email provider and the authorities. Both make the next attempt less likely to land, for you and for other people.

In your email app, use Report phishing or Report spam rather than just deleting the message. That trains your provider’s filter and pulls copies out of other inboxes. In the United States, report the scam to the FTC at ReportFraud.ftc.gov, and if you gave out personal information, use IdentityTheft.gov for step-by-step recovery. CISA, the U.S. cyber agency, also asks people to forward phishing messages so it can track and disrupt the campaigns behind them. Reporting takes a minute and it is the part most people skip.

How worried should I be if I only clicked and typed nothing?

Not very. If you landed on a page, entered nothing, and no file downloaded, you are almost certainly fine, especially on an updated device. The click most likely confirmed your address is active, so the practical consequence is more spam heading your way, not a hijacked account.

Do two small things anyway. Keep an eye on the accounts that matter for a week or two, and expect a bump in junk mail. If that bump arrives, it is a sign your address got flagged as live, which is a nuisance rather than a breach. The fake unsubscribe link is a common way this plays out, and we cover it in detail in how phishing hides behind fake unsubscribe links.

Fewer messages to judge means fewer chances to click the wrong one. Every list you are on is another envelope you have to sort real from fake each morning, and modern phishing reads clean, with correct spelling and your real name, so the old giveaways no longer help. Our guide to spotting AI phishing emails covers what to check instead, starting with the sender’s real address and where a link actually points.

Shrinking the pile is the slow, dull part, and every footer link you open by hand is one more roll of the dice. Email Unsubscriber scans your Gmail or Outlook inside your own browser, lists every subscription sender, and fires the real one-click unsubscribe wherever a sender supports it, which keeps you off footer landing pages entirely. The scan runs on your device, and we never read, analyze, or monetize your email content. It is not a spam filter and it will not undo a phishing click, but a smaller inbox is a smaller target.

The takeaway

A click by itself rarely costs you an account. What follows it can. Close the tab and type nothing, disconnect if a download started, and if you entered a password, change it from a device you trust and turn on two-factor authentication. Scan the device, report the message, and watch your accounts for a week. Then cut the volume of mail you have to judge, so the next dodgy link is one you never see.

Frequently asked questions

What happens if you click a phishing link but don't enter any information?

Usually very little. On an up-to-date browser and phone, a single click that loads a page and nothing else rarely hands over an account. The most common result is that the click confirms your address is live, which tends to bring more spam. Close the tab, do not go back to finish anything, and watch for a rise in junk mail.

Can you get hacked just by clicking a link?

Rarely, if your browser and operating system are current. The dangerous outcomes need a second step from you: typing a password on the fake page, entering card details, or running a download the page offers. A drive-by download that infects a fully updated device without any action is uncommon for mass phishing, though not impossible, which is why keeping software updated matters.

What is the first thing you should do after clicking a phishing link?

Stop and enter nothing. Close the tab and do not return to complete a login or form. If a file started downloading, disconnect from the internet to cut the malware off. Then decide the rest by what you did: change any password you typed from a device you trust, and scan the device if anything downloaded.

Should I change my password after clicking a phishing link?

Only if you entered a password on the page, or reused that same password elsewhere. Change it from a device you trust and have scanned, not the one that may be infected, because a keylogger steals a new password the moment you type it. Start with your email password, then turn on two-factor authentication so a stolen password alone is not enough.

How do I know if my phone has a virus after clicking a link?

Watch for signs after the click: fast battery drain, the phone running hot, unfamiliar apps, pop-ups, or a spike in data use. Run a full scan with reputable security software. On an updated phone that only loaded a page and downloaded nothing, infection is unlikely. The bigger risk on mobile is a fake login page harvesting what you type.

Where do I report a phishing link?

Report it in your email app first, using Report phishing or Report spam, so your provider filters similar mail. In the United States, report the scam to the FTC at ReportFraud.ftc.gov, and if you gave out personal information go to IdentityTheft.gov for recovery steps. CISA also asks people to forward phishing messages so it can track campaigns.

What happens if you accidentally click a phishing link on your phone?

The same rules apply as on a computer. A single tap usually loads a page rather than infecting the phone, and the real risk begins if you log in or install what the page offers. Do not enter credentials, close the tab, and if you already typed a password, change it from a different trusted device and enable two-factor authentication.