I clicked a phishing link. Am I hacked?
The next step depends on what you did after the page opened. Pick what happened and get a clear checklist.
A suspicious link can make your stomach drop. But opening a page, typing a password, sharing a code, and installing an app are different events. The click alone does not prove your account or device was compromised.
What did you do after opening it?
Choose every step that applies. Your picks are not saved or sent.
Close the page.
If you did not enter information, open a file, install an app or approve a request, the click alone does not prove your account or device was compromised. Keep your browser and device updated. If a file downloaded, check the last option too.
FTC: What to do after a phishing message →Secure the account from a trusted device.
Do not follow the message again. Open the service through its official app or a known address and change the password. Change it anywhere you reused it, review signed-in devices, recovery details and connected apps, then turn on two-step verification. If locked out, use the service’s official recovery process. Do not share another verification code.
Google Account recovery guidance →Contact your bank or card issuer now.
Use the number on your card or inside the official app. Ask about locking or replacing the card, stopping or disputing transactions, and check recent activity. If you shared identity information too, contact the official fraud or identity-theft service where you live. U.S. residents can use the FTC’s recovery guidance.
FTC: What to do after a scam →Do not open it again.
Update your device and trusted security software, run a scan, and follow the device maker’s instructions for anything the scan identifies. If it is a work device, contact IT. If you installed remote-access software, get help through the official device or service provider. Change passwords from a separate trusted device if you suspect malware.
FTC: Scan for harmful software →This checklist cannot scan a device or determine whether it was compromised. Reporting and recovery steps vary by country.
If you entered more than one kind of information, do each relevant step. If money moved or you handed over a verification code, contact the bank or account provider through its official app or a number you already trust.
Remember: don’t return to the message to fix the problem. Use an official route, and match the response to what actually happened.
The FTC steps apply to the United States; KISA’s hotline applies to South Korea. Use the official fraud, bank and cybercrime services for your country.
Sources: U.S. Federal Trade Commission, phishing response; FTC, steps after a scam; Google Account recovery and security; Korea Internet & Security Agency, 118 hotline.