After a click
How To: Respond After Clicking a Phishing Link
Updated 17 August 2026
In short. Speed and honesty beat embarrassment. What you do next depends on whether you only opened a page, typed a password, or ran something — and whether the device is yours or the company’s.
Stop
- Do not enter more data.
- Do not download the “fix”.
- Do not reply.
- Screenshot the URL if IT may need it, then close the tab when they say so.
What the click can do is the background. This page is the action list.
At home (UK)
NCSC: do not panic.
- No details entered, nothing installed — stay alert for odd sign-ins. You may not need more.
- Typed a password — change it on that account and anywhere you reused it, from a device you trust. Turn on MFA if it was off.
- Bank or card details — contact the bank on a number you already have, not a number in the email.
- Something may have run — full antivirus scan.
- Report the mail — forward to
report@phishing.gov.uk. Lost money: Action Fraud (England, Wales, Northern Ireland) or Police Scotland.
GOV.UK also covers reporting suspicious emails and websites.
At work
Use your organisation’s process, not a guess.
- Stop interacting with the page.
- Report immediately on the official channel: phish button, SOC mailbox, or service desk. Do not hide it.
- Say what you clicked, whether you typed credentials, whether a file ran, the time, and which device.
- Credentials — let IT reset the identity, revoke sessions, and check MFA. Use the path they give you.
- Malware possible — disconnect or isolate as local policy says. Do not “clean” a managed PC yourself.
- Money or supplier change — freeze the payment. Call the real requestor on a number you already have.
Reporting a click is the correct professional move. Silence is how a mailbox takeover spreads.
Elsewhere the labels differ (CISA and IC3 in the US). The idea is the same: report, reset, isolate.
