Phishing guide

What should I do after clicking a phishing link?

Use a calm, evidence-based response after a suspected phishing click, credential entry, download, consent grant, or payment.

Content reviewed
Short answer

Stop interacting with the page and separate what happened: opening a page, entering credentials, approving access, downloading a file, and sending money require different responses. A click alone does not establish compromise.

What you may be seeing

A link can lead to a harmless dead page, a credential form, an OAuth consent screen, a download, or an exploit attempt. The response should match the action and evidence.

Do not keep revisiting the link to investigate it. Record the message and approximate time if doing so is safe, then use known-good channels.

Signals to inspect—and why they matter

Strong evidence

Credentials or a one-time code were submitted

The recipient should assume those submitted secrets were disclosed and replace or invalidate them through the real service.

A file was downloaded or opened

A download creates a different risk than viewing a page. Organization-managed devices should be reported to IT/security rather than self-remediated in ways that erase evidence.

An app-consent prompt was approved

OAuth consent can grant an application access without taking the password. A password reset alone may not revoke that access.

Contextual signals

The page looked polished or showed HTTPS

Encryption protects traffic to a domain; it does not prove the domain belongs to the claimed organization.

Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.

Safe verification steps

  1. Close the page and do not download, run, approve, or submit anything else.
  2. From a known bookmark or manually entered address, review the affected account’s recent activity and connected applications.
  3. If this involved a work or school device or account, report the event through the organization’s known security channel and preserve the message.
  4. If a file ran, follow your organization’s endpoint process. On a personal device, update security software and run its scan as the FTC advises.

What to do next

  • Credentials entered: change the affected password from the official service, replace reused passwords, review sessions and recovery details, and enable strong MFA.
  • Consent approved: review and revoke the application’s access through the official account portal; organization-managed accounts need administrator review.
  • Money or payment data sent: contact the financial institution or payment provider using a known number and ask about reversal or protective steps.
  • Identity information disclosed: use the response plan for the specific data; in the United States, the FTC directs people to IdentityTheft.gov.
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.

Limitations and uncertainty

What this guide cannot establish

  • No checklist can determine from the click alone whether code executed or data was taken.
  • Disconnecting a managed device, deleting files, or wiping history can conflict with an organization’s incident process. Follow its instructions.
  • Response steps vary by service, device, country, and the information disclosed.