Phishing First Aid: What to Do After Clicking a Phishing Link
A calm, action-focused guide for protecting accounts, devices, payments, work systems, and evidence after a phishing interaction.
First, stop and change the question
After a suspicious interaction, the most useful question is no longer whether the message looks like phishing. The priority becomes limiting damage, protecting accounts or money, preserving evidence, and reaching the right trusted support channel.
The Phishing First Aid tool creates a private action plan based on what happened. It covers 12 possible actions, from simply reading a message to entering a password, sharing an MFA code, opening a file, changing bank details, sending money, or involving a managed workplace device.
If you only opened or read the message
Reading a normal email or text usually does not carry the same risk as entering information or running a file. Stop interacting, avoid its links and contact details, and preserve the message if it may need to be reported.
Do not let fear push you into downloading untrusted cleanup software or calling a number supplied by the same suspicious message.
If you clicked but entered nothing
Close the page and do not return to investigate. Open the relevant account or service independently and review recent activity if the page appeared to sign you in or redirect through an unexpected flow.
Update the browser and operating system, then use trusted built-in or organization-approved security scanning if the page attempted a download or the device behaves unexpectedly.
If you entered a password
Use a trusted device and independently open the official service. Change the exposed password immediately. Sign out other sessions, review recovery details, remove unfamiliar devices, and enable MFA.
If the password was reused, change it anywhere else it was used. Reuse allows one exposed credential to become several compromised accounts.
If you shared an MFA or verification code
A code may complete a login even when the password is later changed. Contact the official account provider or workplace security team promptly. Revoke active sessions, review enrolled MFA devices and recovery methods, and remove anything unfamiliar.
Never approve a second prompt sent by the attacker while trying to fix the first interaction.
If you shared personal or financial information
Personal information can support account recovery attacks or identity fraud. Document what was disclosed and secure accounts that use those details for verification.
For card or banking information, contact the financial institution using the number on the card, official app, or known statement. Ask about replacement, transfer review, and appropriate fraud controls. Do not use a phone number or recovery service promoted by the suspicious message.
If you downloaded or opened a file
If the file was downloaded but not opened, do not open it. Leave it available for security review when a workplace team may need evidence.
If it was opened, stop using it and contact qualified IT or security support. A managed device should follow the organization's incident process. Do not wipe, reimage, or investigate a workplace device on your own unless instructed.
If money was sent or bank details changed
Contact the sending bank, card issuer, marketplace, or payment provider's official fraud team immediately. Ask whether the payment can be stopped, recalled, frozen, or disputed. Record transaction IDs and support reference numbers.
If bank details were changed in a workplace or supplier system, restore verified details through the normal finance process and alert anyone who might send funds using the changed record.
Beware of recovery scams. Someone promising to recover money for another fee may be continuing the same fraud.
When work accounts or devices are involved
Use the normal internal IT or security reporting channel. Explain which account or device was involved, what action occurred, and the approximate time. Follow containment instructions rather than improvising.
Fast reporting helps a security team review sessions, mailbox rules, device alerts, forwarding settings, payment workflows, and related accounts before the incident spreads.
Preserve useful evidence
- Keep the original message and sender details.
- Record the approximate time of each interaction.
- Preserve screenshots without continuing the conversation.
- Save transaction, ticket, or support reference numbers.
- Note which account, device, file, or payment was involved.
- Do not send passwords, codes, private keys, or full financial details in a report.
What the tool does not do
Phishing First Aid does not contact a bank, employer, platform, authority, or security company. It does not repair a device, secure an account, reverse a payment, or confirm that an incident is contained.
The plan is general guidance generated locally from the actions selected. Urgent professional help is appropriate when money is moving, an account is actively controlled by someone else, a workplace system is involved, or a device may be compromised.
Use a trusted route for every recovery step
Independently open the official app or website. Use a number on a card, known statement, internal directory, or official support page. Do not rely on the suspicious message's links, phone numbers, reply address, or recommended recovery provider.
If you are still deciding whether a real message is suspicious, use the Phishing Message Analyzer or Email Identity Checker. For a complete overview, read the Human Risk Intelligence tools guide.
Continue with the right checker
CheckLink browser extension
Open the current page, inspect links from the browser menu, and jump into CheckLink faster without an account.
Works with Chrome and compatible Chromium-based desktop browsers. Firefox and Safari versions are not currently available.

The extension sends a URL only when you choose a scan action. It does not store scan history.