What to do after clicking a phishing link

Clicked a link in a suspicious email or text and worried about what happens next? Here is what to do straight away, how to check whether anything has been taken or opened in your name, how to report the message, and how to tell the next fake one apart from the real thing.

What to do after clicking a phishing link
Short answer

Clicking a link in a fake email or text is not the end of the story. Most people who do it lose nothing, because the link on its own does not hand over your money. What matters is what you did next: whether you typed in a password, card number or one-time code, and whether anything was downloaded onto your device.

Clicking a link in a fake email or text is not the end of the story. Most people who do it lose nothing, because the link on its own does not hand over your money. What matters is what you did next: whether you typed in a password, card number or one-time code, and whether anything was downloaded onto your device.

The first move is always the same. Contact your bank or payment services provider immediately if money or account details are involved, using a number you know is genuine rather than one from the message1. Then check your statements and your credit file for anything you do not recognise, and report the message so it can be investigated2.

First steps: contact your bank using a number you know is genuine

Speed matters more than anything else you do. The Financial Ombudsman Service's guidance for people caught by scams involving unauthorised payments and identity theft lists the immediate steps: contact your bank or payment services provider immediately, contact the police on 101, report the scam to Report Fraud, and keep records of all contact and correspondence between you and the scammer2. Take Five, the national anti-fraud campaign, gives the same first instruction: contact your bank immediately if money or account details are involved, and report it to the police at reportfraud.police.uk or on 0300 123 20401.

The reason to use a number you already have, rather than one in the message or on a website the message sent you to, is that scammers can mimic an official telephone number so the call appears to come from a legitimate organisation such as a bank or utility company8. If you are unsure whether a call is genuine, dial 159 to be connected safely to your bank, or 101 for the police4. There is more on this in how to check your bank is really contacting you and on the 159 number.

If you gave away card details rather than login details, the same first call applies. If you made a payment yourself, having been talked into it, the rules on refunds are different from those covering a payment you never authorised, and authorised and unauthorised payments explains how the two are treated. Paid a fraudster? What to do straight away sets out the full sequence.

Check your statements and credit file for signs of fraud

A phishing link rarely takes money by itself; the damage shows up later as a transaction or an account you did not open.

A phishing link that collected your login details can be used later, quietly. The Information Commissioner's Office advises requesting a copy of your credit file to check for any suspicious credit applications, and regularly checking your credit card and bank statements for suspicious activity while monitoring your credit report3. Experian's guidance on phishing says the same: check your bank account and credit card statements regularly for transactions you do not recognise, and check your credit file frequently for unrecognised accounts or unusual credit rejections9.

Checking your credit file is free, and StepChange notes you can do it for free to look for any credit taken out in your name fraudulently10. What you are looking for is anything you did not open: a new account, a credit search you did not trigger, or a rejection you cannot explain. Identity theft covers what to do if you find something.

If the message related to your pay rather than your bank, there is a separate check. Government guidance on payslip fraud says you can use your Personal Tax Account, the HMRC app, your National Insurance record, or your Student Loan repayment account if you have one, to check deductions11. And if a message offered you a loan, check you are using a legitimate loan provider by searching the FCA Firm Checker and using the contact details listed there, not the ones given to you12.

How to report a phishing email, text or call

Reporting is quick and it helps shut down the campaign for everyone else. Scam emails can be reported to report@phishing.gov.uk, which the National Cyber Security Centre will investigate5. Report Fraud passes phishing emails to the National Fraud Intelligence Bureau10. Phishing websites can be reported to the National Cyber Security Centre5.

If you use Gmail or Outlook, both have a built-in route. On Gmail, select the three dots on the right of the email address and press Report phishing13. On Outlook, select the three dots on the right of the email address and press Report, then Report phishing13. Outlook also allows you to forward the message, including the full message header, to abuse@outlook.com if the address is suspicious13.

For texts and calls, the reporting routes differ by nation and by type, and where to report a scam in England, Wales, Scotland and Northern Ireland sets them out. Forwarding suspicious texts to 7726 covers the free route for nuisance texts.

Malware: what a click can install on your device

Not every click installs something, but some do. Which? warns that clicking on links could lead you to download malware, malicious software that can take over your phone and access your data15. Handelsbanken's guidance on smishing is blunter: clicking on the link will then download a virus or malware onto your device16.

There is a second, related trick worth knowing about. A caller may tell you your device has a virus and that you need to download software to fix it, when the software is actually spyware8. If someone rings out of the blue about a virus on your device, that call is the scam. Should you let a caller access your computer? explains why remote access requests should be refused.

If you did download something, or your device is behaving oddly, the practical steps are to run up to date anti-virus software and to change passwords for accounts you accessed around that time, using a different device where you can. Setting strong, separate passwords for your accounts and using up to date anti-virus software is the standard advice for keeping accounts safe17.

What your bank will never ask you for

No, and this is one of the most reliable tests you have. Northern Ireland's nidirect guidance is explicit: your bank will never ask you for your PIN or your online account password, and neither will any trustworthy online retailer6. Age UK's online banking guidance adds the detail of how banks actually verify you: they will never ask for your full PIN or password, instead asking for specific numbers or letters, for example the first and third character18.

The rule holds across the industry. A bank will never ask for your PIN, or for a whole security number or password, either over the phone or via email19. The Financial Services Compensation Scheme makes the same point about itself: it will never ask for bank details, account passwords, or PIN numbers20. The Finance and Leasing Association's identity theft guidance repeats it: banks will never contact you to ask for your personal identification number or for a whole security number or password21.

"You will never be asked for your bank details by text, social media, email or via links to click within a text or email"
nidirect, Protect your identity22

If a message or call asks for a whole password, a full PIN, or a one-time code, that is the moment to stop. One-time passcodes explains why sharing a code hands over the keys to your account.

Spotting the next one: signs of a fake message or website

The old advice about poor spelling and grammar is no longer enough on its own. Which? reports that fraudsters are able to create much more convincing messages, free from the poor spelling and grammar we have always relied on to spot scams5. That makes the structural checks more important than the cosmetic ones.

Legal and General's phishing guidance lists what to check: whether the website address matches the site it claims to be, spelling mistakes and bad grammar, unusual use of capitals and a mix of US and UK English, who the email is addressed to, and any request for urgent action23. Markerstudy's policyholder guidance narrows it to two key areas: the send-from email address, and whether any click-through link is the web address of the actual company or person they claim to be24. First direct notes a simple tell: hovering over the sender's name can reveal a random address25.

What to checkWhat a fake often shows
Sender addressA random or mismatched address when you hover over the name25
The link itselfDoes not match the web address of the company it claims to be24
ImagesPixelated images can strongly indicate the email is a scam26
ToneUrgent demands to act now23
GreetingNot addressed to you personally23
Hovering over the sender's name, or expanding the header, often reveals an address that has nothing to do with the organisation named in the message.

What a padlock does and does not prove

No, and this is one of the most common misunderstandings. A padlock next to a website's URL means the site is encrypted, so what you do on it, such as browse or make payments, cannot be intercepted, but scammers can forge or buy padlocks, so seeing one does not always mean a website is safe7. The 's' in https stands for 'secure', which describes the connection, not the honesty of the site behind it27.

That said, the absence of both is a clear warning. One building society's guidance puts it plainly: look for the little padlock and the https, because without both of these it is not secure28. MoneyHelper's checklist for a genuine website address bar is a locked padlock symbol, an address starting with https://, and no spelling mistakes or strange characters29.

The practical rule is to treat the padlock as a minimum, not a guarantee. Check the address itself, character by character, especially on links that arrived in a message. Fake websites and online shopping scams covers what to do if you have already entered details on one.

Who scammers pretend to be

The list is long and it changes with the news. Take Five's banking fraud guidance says scammers often impersonate trusted organisations such as banks, HMRC and broadband providers30. Courier fraud guidance names your bank, card provider, the police or a fraud team27. TaxAid describes fraudsters sending emails purporting to be from reputable organisations such as the Post Office, inviting you to click a link to a fraudulent website asking for bank account or payment card details31.

Phishing itself is defined as fraudsters impersonating people or companies, typically through messages with links, to trick you into revealing your personal or financial information32. NatWest's impersonation scam guidance describes phishing as one of the most common forms of scams, with fraudsters circulating malicious links or files under the guise of a legitimate email33.

The pattern to hold on to is that the message arrives unexpectedly and asks you to do something: click, log in, pay, or confirm details. If you did not initiate it, verify it through a route you chose yourself. Phishing, vishing and smishing covers the family of scams in more detail, and clone firms covers fraudsters posing as authorised companies.

Phishing by text, phone call and letter

Yes, and the names differ by route. Phishing by phone call is vishing, defined as scammers impersonating people or companies over the phone to get you to reveal your personal or financial information32. Virgin Money's fraud guidance lists the full set: emails (phishing), texts (smishing), phone calls or voicemails (vishing) and QR code phishing (quishing)34. Email scams, also known as phishing scams, involve fraudsters sending emails purporting to be from well-known brands to steal personal information and bank details26.

Letters are used too. Age UK's guidance on TV Licence scams notes that this scam can come as a text, phone call, letter, or most often as a phishing email35. A common text tactic is a message asking you to follow a link to fix a problem with an account or to track a parcel, leading to a fake website where you are asked to log in8.

How can I protect my accounts from phishing in future?

The core habits are simple and they are repeated across the guidance. Avoid clicking on links in emails, texts and social media, and always verify the website you are on36. Set strong and separate passwords for your accounts and use up to date anti-virus software17. Check your bank and credit card statements regularly, and check your credit file for anything you do not recognise3.

Two habits catch most of the rest. The first is to confirm payment details by phone before sending money: when anyone emails you bank details, it is worth calling them to confirm, using a number from their website rather than one in the email10. The second is to slow down when a message demands urgency, because urgency is the pressure tactic that makes people skip the checks23.

If you have already lost money, claiming a refund from your bank after a push payment loss explains the process, and taking a refused scam refund to the Financial Ombudsman covers what happens if the bank says no. Free, impartial help is available from MoneyHelper and from debt advice charities such as StepChange.

Sources37 cited
  1. Protect yourself Take Five, 2026-09-26
  2. Scams involving unauthorised payments and identity theft Financial Ombudsman Service, 2026-09-26
  3. Identity theft Information Commissioner's Office, 2026-09-25
  4. AI scams Age UK, 2026-08-19
  5. How to spot and avoid AI scams Which?, 2026-08-07
  6. Protect your identity nidirect, 2025-10-28
  7. How to spot a fake, fraudulent or scam website Which?, 2026-08-07
  8. Phone scams Age UK, 2026-08-19
  9. Phishing Experian, 2026
  10. How to spot, avoid and report scams StepChange, 2026-09-25
  11. How to avoid payslip fraud GOV.UK, 2026-08-25
  12. Types of scam MoneyHelper, 2026-09-25
  13. I'm a scams expert and these are my tips for reporting scams Which?, 2026-06-17
  14. Common methods HSBC, 2026
  15. How to spot a messaging scam Which?, 2026-06-29
  16. Protect yourself Handelsbanken, 2026
  17. Conveyancing scams Take Five, 2026-09-26
  18. Online banking Age UK, 2026-03-23
  19. What is identity theft Which?, 2026-01-06
  20. Scams: what to look for Financial Services Compensation Scheme, 2026-05-05
  21. Identity theft Finance and Leasing Association, 2026-09-25
  22. Check your state pension age nidirect, 2026-09-01
  23. Phishing, vishing, smishing Legal and General, 2026-09-26
  24. Advice on how to protect your identity Markerstudy, 2026-09-26
  25. Email scams and payment requests first direct, 2026
  26. How to spot an email scam Which?, 2026-08-11
  27. Courier fraud Take Five, 2026-09-26
  28. Identifying text scams AIB (NI), 2026
  29. Shop safely online MoneyHelper, 2026-09-25
  30. Banking fraud Take Five, 2026-09-26
  31. Tax refund scams TaxAid, 2025-10-21
  32. Scams glossary Which?, 2026-07-22
  33. Impersonation scams NatWest, 2026-09-25
  34. Fraud Virgin Money, 2026-09-25
  35. TV Licence scams Age UK, 2026-04-13
  36. Card fraud Take Five, 2026-09-26
  37. Digital wallet fraud Take Five, 2026-09-26

More questions on Scams and Fraud

Related guides

Paid a fraudster? What to do straight away
First Steps for VictimsGives the immediate steps after sending money or sharing details: contacting the bank, freezing cards, changing passwords and keeping evidence.
Identity theft: protecting yourself and what to do if it happens
Identity TheftExplains how personal details are stolen and misused and the steps to take if accounts are opened in your name.
Where to report a scam in England, Wales, Scotland and Northern Ireland
Where to Report a ScamExplains who to report to in each nation, including Report Fraud (formerly Action Fraud), Police Scotland, the FCA and your bank.
One-time passcodes: why you get them and why never to share one
One-Time PasscodesExplains how passcodes and in-app approvals confirm payments under Strong Customer Authentication.

Frequently asked questions

Is my phone or computer infected if I clicked a phishing link?

Not necessarily. Clicking a link can take you to a cloned website that simply collects whatever you type, or it can download malware, which is malicious software that can take over your phone and access your data. If you did not enter any details and did not download or open anything, the risk is lower. If you did download something, or your device starts behaving oddly, run up to date anti-virus software and consider having the device checked.

Will my bank ever ask for my full password?

No. Banks will never ask for your full PIN or password, either over the phone or by email. Instead they ask for specific numbers or letters, such as the first and third character. No trustworthy retailer will ask either. If someone contacts you asking for a whole security number or password, treat it as a scam and contact your bank using a number you know is genuine.

Does https or a padlock mean a website is safe?

No. A padlock next to a website address means the site is encrypted, so what you do on it cannot be intercepted. It does not mean the site is honest. Scammers can forge or buy padlocks, so seeing one does not always mean a website is safe. Check the address itself for spelling mistakes or strange characters as well.

Should I delete the phishing email or forward it first?

Both have a place. Reporting helps the authorities and your email provider block the campaign, so forward the message to report@phishing.gov.uk before deleting it. In Gmail or Outlook you can also use the Report phishing option. Once reported, delete the email and empty the recycle bin on your device.

What types of organisation do scammers usually pretend to be?

Banks, card providers, the police, fraud teams, HMRC, broadband providers, the Post Office and courier firms are all commonly impersonated. Scammers can also mimic an official telephone number so the call appears to come from a legitimate organisation such as a bank or utility company. Any unexpected contact asking for details or payment is worth checking independently.

Can phishing come by text, phone call or letter as well as email?

Yes. Phishing by text is called smishing, by phone call or voicemail it is vishing, and QR code phishing is known as quishing. Scams can also arrive as letters. One example, TV Licence scams, can come as a text, phone call, letter, or most often as a phishing email. The same rules apply whichever route it takes.

How can I protect my accounts from phishing in future?

Avoid clicking links in emails, texts and social media, and always verify the website you are on. Set strong, separate passwords for your accounts and use up to date anti-virus software. Check your bank and credit card statements regularly, and check your credit file for accounts or applications you do not recognise. If anything looks wrong, contact your bank immediately.