phishtriage

For everyone · 5 minutes

What if I already clicked?

Take a breath. Scams are made to fool careful people, and this happens to many of us. Acting soon usually limits the harm. Find what happened below. If more than one thing happened, do them in the order they appear.

If you only opened the link and typed nothing, the risk is usually small. What matters most is whether you paid, typed a password or other details, or opened a file.

If it happened on a work computer or a work account, tell your IT team first, and do what they say.

If someone asked you to install an app or share your screen

  1. Hang up, or close the chat.

  2. Turn off the internet on that computer: switch off Wi-Fi or unplug the cable.

  3. Call your bank. Use the phone number on the back of your bank card.

  4. At work, tell your IT team. At home, ask someone you trust to help remove the app.

If you paid, or gave card or bank details

Do this as soon as you can.

  1. If you typed your card details, block your card now. You can do this in your bank’s own app or online banking.

  2. Call your bank. Use the phone number on the back of your bank card, or from your bank’s own website. Never use a number from the email or the page.

  3. Tell them what happened. Ask them to stop the payment, and to block your card if you couldn’t.

  4. If you typed your online banking login, tell them that too. They can help you secure your account.

  5. If money has gone, report it to the police as well. In Estonia, see Report it below.

If you typed Smart-ID, Mobile-ID or ID-card PIN codes

  1. Call your bank now, as above. Tell them you typed your PIN codes on a fake page.

  2. If you typed Mobile-ID PIN codes, change them.

  3. If you typed Smart-ID PIN codes, delete your Smart-ID account, then set it up again.

  4. If you typed ID-card PIN codes, suspend your ID-card certificates.

Your bank can tell you how to do each of these.

If you typed a password, or a code sent to your phone

  1. Change that password now. Go to the real website yourself: type its address, or use its app. Don’t use the link in the email.

  2. If you use the same password anywhere else, change it there too. Give each account its own password.

  3. Turn on two-step sign-in for that account. This means a code on your phone is needed as well as the password. Most email, bank and shopping sites offer it in their security settings.

  4. If the website lets you, sign out of all other devices. This throws out anyone who got in with your old password.

  5. If it was your email account, check that its recovery phone number and recovery email address are still yours.

If you can’t sign in any more, use the website’s own help for a lost or forgotten password. If it was a work account, tell your IT team straight away.

If you opened an attachment or a file

  1. Don’t open the file again.

  2. At work, tell your IT team now. Do what they say. They may ask you to leave the file and the computer as they are.

  3. At home, delete the file.

  4. At home, run a full scan with your antivirus program. On Windows, you can use the Windows Security app.

  5. If you are still worried, change your important passwords from a different device, such as your phone.

If you only clicked the link

  1. Close the page. Don’t type anything into it.

  2. If a file downloaded by itself, don’t open it. Delete it.

At work: tell your IT team

If it happened on a work computer or a work account, tell your IT team as soon as you can, whatever you clicked. It is their job, they would much rather hear early, and you are not the first. The same email may have reached your colleagues, and your message helps protect them.

Keep the email

Don’t delete the email yet. Your bank, your IT team or the police may want to see it. Just don’t click anything else in it. You can delete it once you have reported it.

Report it

In Estonia:

In other countries: report it to your country’s cybercrime or consumer-protection service.

What PhishTriage can and can’t do now

PhishTriage can’t undo a click. It can’t take back what you typed or paid, and it can’t tell you whether someone has used your details.

It can help you find out whether it really was a scam. Open the email and check it with PhishTriage. See Check an email.

Don’t go back to the page to check it. If you typed something into it, a check could send us a picture of what you can see in that tab. It could also send us the page’s code. Both could show what you typed.

Do the steps above first. Checking can wait. If the answer is Don’t trust this or Be careful, finish any steps you skipped. If it says Looks safe but something still feels wrong, trust that feeling. Changing a password costs only a few minutes.

For next time, Background protection warns you within a few seconds when you open a site already known to be dangerous.