Skip to content
IT

I clicked a scam link: what to do in the first two hours

You clicked, maybe you even typed your details, and now your heart is racing. Stop for a minute: in most cases this is fixable. Here is what to do, in order, starting with the most urgent.

For Humans Staff · · 5 min read

Cyber for Humans
Level
principiante
Time
30 minutes
What you need
The phone or computer you used, and your payment card to hand

It happens to everyone, and it mostly happens when you are in a hurry. A text about a parcel, an email from the bank, a message that looks like it is from your daughter. You clicked. Maybe you stopped halfway, maybe you typed something in.

The first thing to know is that clicking on its own is almost never enough to cause damage. The harm comes from what follows: the details you typed into the page, or an app you installed. So breathe, and do these things in this order.

In plain words

Phishing: a fake message imitating a real sender (your bank, the post office, a courier) to get you to type your credentials into a page that looks like the real one. Credentials: username and password, plus the codes that arrive by text.

If you only clicked, and typed nothing

The most common situation, and the least serious. The page opened, you realised it was fake, you closed it.

  1. Close the tab and do not go back.
  2. On a computer, run a scan with the antivirus you already have (on Windows: search for "Windows Security", then Virus & threat protection, Quick scan).
  3. If a file downloaded in the meantime, delete it without opening it, and empty the bin.
  4. You do not need to change passwords. You do not need to wipe anything.

If you typed your credentials

Here time matters. The goal is to get there before they do.

  1. Change that service's password immediately, but not from the link in the message: open the app yourself, or type the address into the browser yourself.
  2. Change that same password everywhere you reused it. This is the step almost everyone skips and the one that does the most damage: whoever has your password for one site will try it on all the others, starting with your email.
  3. Start with the email account. Anyone who gets into your inbox can reset the password for everything else. If time is short, secure that first.
  4. Turn on two-step verification wherever you had not: from that point a stolen password alone is no longer enough. We have a step-by-step guide.
  5. In the service's settings look for "connected devices" or "active sessions" and sign out everywhere. Then sign back in yourself.

If you entered your card details

  1. Freeze the card. It takes thirty seconds in your banking app, searching for "block card". If you cannot, call the number printed on the back of the card, not one you found on the internet.
  2. Look at the last few days of transactions. Note the date, time and amount of anything you do not recognise.
  3. Formally dispute the unauthorised transactions. Your bank will tell you how, usually a form in the app or in branch.
  4. Ask for a replacement card. Treat the old number as burned.
Relax:

For unauthorised payments, European rules require the bank to refund you except in cases of gross negligence by the customer. Reporting immediately and in writing is exactly what puts you on the right side of that. Do not be put off by the first "no" over the phone: the claim has to go in writing.

If you installed an app or gave access to your phone

This is the most serious situation, and it is typical of the fake technician or fake bank-operator scam that asks you to install a program for “support”.

  1. Put the phone in aeroplane mode: it cuts off any connection in progress straight away.
  2. Uninstall the app: press and hold it on the screen and choose Uninstall. On Android check Settings > Apps too, because sometimes it does not show on the home screen.
  3. On Android also look at Settings > Accessibility and Device admin apps: remote-control tools hide there. Revoke permissions for anything you do not recognise.
  4. Restart the phone, then change your passwords as above, from a different device.
  5. If you still do not feel safe, a factory reset is the definitive guarantee, and it is exactly why having a backup matters more than anything else.

Then, calmly: report it

Reporting is not the same as filing a criminal complaint, it is much faster, and it matters: scam campaigns get shut down because enough people report them.

In Italy you can do it on the Postal Police website, in the report online section. If you have actually lost money, you do need to file a complaint, and it is also the document your bank will ask for.

Our Where to check page lists the useful addresses, including the CERT-AGID weekly bulletin of scams circulating in Italy: very often the message you received is in there, and seeing that it happened to thousands of other people helps more than you would think.

The verdict

Clicking is not the end of the world. The two hours that matter are for three things: change your email password before any other, freeze the card if you typed it in, remove any app a stranger asked you to install. Once those are done, the rest can be sorted calmly.

How to avoid the next one

One signal gives away almost all of these messages: they ask you to do something urgent, starting from a link. No bank, no postal service and no courier works that way. The rule that always holds is to close the message and reach the service on your own terms, from the app or by typing the address by hand.

To train your eye, we wrote how to spot a scam text message.

Sources

More in Cyber for Humans