PassaTime↗All stories
QUICK CHECK 35 / LINK SAFETY

I clicked a phishing link. Am I hacked?

The next step depends on what you did after the page opened. Pick what happened and get a clear checklist.

A suspicious link can make your stomach drop. But opening a page, typing a password, sharing a code, and installing an app are different events. The click alone does not prove your account or device was compromised.

What did you do after opening it?

Choose every step that applies. Your picks are not saved or sent.

Select all that happened

This checklist cannot scan a device or determine whether it was compromised. Reporting and recovery steps vary by country.

If you entered more than one kind of information, do each relevant step. If money moved or you handed over a verification code, contact the bank or account provider through its official app or a number you already trust.

Remember: don’t return to the message to fix the problem. Use an official route, and match the response to what actually happened.

The FTC steps apply to the United States; KISA’s hotline applies to South Korea. Use the official fraud, bank and cybercrime services for your country.

Sources: U.S. Federal Trade Commission, phishing response; FTC, steps after a scam; Google Account recovery and security; Korea Internet & Security Agency, 118 hotline.