You clicked it. Maybe you realized immediately, maybe you didn't notice for hours. Either way, you're here now, and the next few minutes matter more than anything that's already happened. Here's exactly what to do, in order.
Step 1 — Don't enter anything else
If you landed on a page and haven't typed anything yet, close the tab now. Don't enter your password, don't fill out any forms, don't download anything from it. Clicking a link by itself usually isn't enough to compromise you — the danger starts the moment you type something in or run a file.
Step 2 — Disconnect if something downloaded
If a file downloaded automatically the moment the page loaded, disconnect from Wi-Fi or mobile data immediately and don't open it. Some phishing pages are built to trigger a silent download the instant they load, hoping you'll open the file out of curiosity. An unopened file on a disconnected device can't do much. An opened one, on a connected device, can.
Step 3 — Change your password if you entered one
If you typed your password into the fake page, go to the real website — type the address yourself, never click back through the phishing message — and change your password right away. Pick something you've never used anywhere else. A compromised password that gets reused elsewhere just hands the attacker a second and third account for free.
Not sure how bad this is?
Nerva IR can walk you through the rest of this checklist for your specific situation — what accounts to check, what to lock down first, and what to watch for over the next few weeks.
Step 4 — Turn on two-factor authentication
Even if an attacker already has your password, MFA (multi-factor authentication) usually stops them from getting in — it's the single highest-leverage step you can take today. On Gmail, Outlook, and Apple ID, it's a few taps under Security settings, and takes under two minutes on each account. Do it now, not after you've "dealt with everything else."
Step 5 — Check for damage
Once your password is changed and MFA is on, look for signs the account was actually used while it was exposed:
- Check your sent messages — did anything go out that you didn't write?
- Check email forwarding rules — attackers often set up silent forwarding so they keep reading your mail even after you change the password.
- Check recent login activity (most email and social platforms show this under account security).
- Check connected apps and revoke anything you don't recognize.
Step 6 — Scan your device
If a file did download and you're not sure whether it ran, scan the device before you trust it again. Windows Defender, macOS's built-in XProtect, and Android's Play Protect all run a scan for free from their respective security settings — you don't need to buy anything to do this first pass.
What if I entered my bank details?
Call your bank immediately using the number printed on your card — never a number from the phishing message itself, even if it looks official. Ask them to block the card and monitor your statements closely for the next 30 days. Most banks can issue a replacement card within days and will reverse confirmed fraudulent charges.
How to tell it was phishing
For next time, the tells are usually consistent: a false sense of urgency ("act within 24 hours or lose access"), a sender address that doesn't quite match the real company, a URL that's close-but-not-quite the real domain, a generic greeting instead of your name, and threats about your account being closed or suspended. The Google Safety Center keeps an up-to-date library of real examples if you want to train your eye.
If someone else already has your password because of this — not just you having changed it as a precaution — the recovery steps are a little different. See Someone Has My Password — What to Do Right Now for the full account-takeover playbook.