Clear answers, no fluff
Cybersecurity

What Should You Do if You Clicked a Phishing Link but Didn't Enter Anything?

Clicking a suspicious link is alarming, but if you didn't enter information, your risk is lower. Here's exactly what to do next.

If you clicked a phishing link but did not enter any information or download anything, your risk is significantly lower — but you should still take precautions.

What the risk actually is: - Simply visiting a phishing page usually does NOT compromise your device by itself, especially on an updated phone or computer. - The danger from phishing links mainly comes from what you do next: entering credentials, downloading a file, or granting permissions. - However, in rare cases, malicious sites can attempt 'drive-by downloads' that exploit unpatched software vulnerabilities.

What to do, step by step:

1. Don't enter anything or download anything. If a login page or form appeared, close it immediately without typing.

2. Disconnect from the internet if you're worried something downloaded — turn off WiFi/data briefly.

3. Don't click any further links or buttons on the page.

4. Close the browser tab/window.

5. Run a security scan with your device's antivirus (Windows Security, or a reputable app) to check for anything that may have downloaded.

6. Update your device. Make sure your operating system and browser are current, which patches the vulnerabilities drive-by downloads rely on.

7. Watch for follow-up: Be alert to any unusual activity, and if the link was in an email pretending to be a real company, consider changing that account's password as a precaution.

If you DID enter information: Change that password immediately (and anywhere you reused it), enable two-factor authentication, and monitor the affected accounts closely.

Related questions

Can you get hacked just by clicking a link?

Usually not from clicking alone, especially on an updated device — the real danger comes from what you do after: entering passwords, downloading files, or granting permissions. However, in rare cases, malicious sites exploit unpatched software through 'drive-by downloads,' which is why keeping your device updated is important.

What happens if you accidentally click a phishing link?

If you only clicked and didn't enter information or download anything, the risk is low. Close the page, don't interact further, run an antivirus scan, and ensure your device is updated. If you entered login details, change that password immediately, enable two-factor authentication, and monitor the account for suspicious activity.

Should I change my password after clicking a phishing link?

If you only clicked the link without entering anything, changing your password isn't strictly necessary, though it's a reasonable precaution for the impersonated account. If you entered any login credentials on the phishing page, change that password immediately — and anywhere you reused it — and turn on two-factor authentication.

More cybersecurity answers

This article is general information, not professional advice. For decisions about your own situation, talk to a qualified professional.