Incident Response Guide

I Clicked a Phishing Link — What Do I Do Now?

First: take a breath. Clicking a bad link happens to careful, experienced people every day — what matters most now is what you do in the next few minutes, not the click itself.

Here's a clear, step-by-step path, whether this happened on a personal device or a work account.

Scan a Link or Email — Free →

Immediate steps (first 15 minutes)

  1. Stop interacting with the page or message. Don't enter any more information, and don't download anything else from it.
  2. If a file downloaded automatically, don't open it. If you already opened it and something looks wrong, disconnect from Wi-Fi or unplug the network cable.
  3. Run the original link through TrustCan's link checker so you have a record of what it actually was.
  4. From a different, trusted device, change the password for any account you entered credentials into — and anywhere else you reused that password.
  5. Turn on multi-factor authentication on that account if it isn't already enabled.

If you entered a password or payment details

  • Change that password everywhere it was reused, not just on the original account.
  • If it was a financial account or card number, call your bank's fraud line immediately — don't wait for a charge to appear.
  • If it was a work email or Microsoft 365 account, check for new inbox rules or forwarding addresses you didn't set up, and revoke active sessions.

If you're a business owner or manager

Treat this as a business incident the moment you learn about it, even if it seems minor. The window between a click and real damage (a wire transfer, a ransomware deployment, a compromised mailbox spreading further) is often measured in hours, not days. Phenicie Business Management offers a free initial incident triage to help you figure out what actually happened and what to do next — use the form below or call (406) 957-1576.

What not to do

  • Don't reply to the original message, even to "confirm" something is wrong.
  • Don't wipe or reset a business device before it's been looked at, if there's any chance of a wider compromise — you may need that evidence.
  • Don't assume it's fine just because nothing bad has happened yet.

Frequently asked questions

I clicked a link but didn't enter anything. Am I still at risk?
Usually the biggest risk is entering credentials or downloading a file — simply loading a page is lower-risk on modern browsers, but not zero-risk. Still run the link through TrustCan, watch for anything downloaded automatically, and keep an eye on your accounts for the next few days.
I entered my password. What's the very first thing I should do?
Change that password immediately from a different device or browser, and change it anywhere else you reused it. Then enable multi-factor authentication if it isn't already on. If it was a work or email account, notify your IT contact right away — don't wait to see if anything looks wrong first.
Should I turn off my computer?
Not unless you downloaded and ran a suspicious file and you have a reason to believe malware is actively running (unusual pop-ups, ransom messages, unexplained slowness). Disconnecting from Wi-Fi or network cable is usually safer than a full shutdown, since it preserves evidence for anyone investigating.
Do I need to report this to anyone?
If it's a personal account, no formal reporting is required, but changing passwords and enabling MFA is still worth doing. If it's a work account or affects a business, report it internally right away — the sooner an incident is triaged, the smaller the potential damage.
Worried someone already clicked, downloaded a file, entered a password, or sent money? Contact Phenicie Business Management now at (406) 957-1576.

Someone interacted with a suspicious email or link?

Phenicie Business Management offers a free initial incident triage to help determine the next action.

TrustCan is a free tool from Phenicie Business Management, a Montana-based IT and cybersecurity provider.

Call (406) 957-1576