Security guides

What to Do After Clicking a Malicious Link

A calm response checklist for suspicious links, exposed passwords, payment details, downloads and command execution.

The right response depends on what happened after the click: viewing, signing in, downloading and running commands carry different risks.

First, stop interacting

Close the page and do not return to collect screenshots or copy commands. Note the time, message source and URL if already available. Do not delete workplace messages or logs that your incident-response team may need.

If you only viewed the page

Risk may be lower, but report the link and watch for unexpected downloads, browser notifications or sign-in alerts. Keep the browser and endpoint security tools updated.

If you entered credentials

From a known-clean device, change the password and revoke active sessions. Change any reused passwords as well. Inform the affected organisation and enable multi-factor authentication where available.

If you entered payment or identity information

Contact the relevant bank, payment provider or organisation through an official channel. Monitor accounts and follow their fraud-response guidance.

If you downloaded a file or ran a command

Disconnect the device from sensitive networks and contact security staff. Running a command can create a more serious incident than simply visiting the page. Avoid self-cleanup that could destroy evidence.

Continue learning

Explore the detection catalogue.

Browse detectionsCheck a link