ScamGuard+ guide

Clicked a Scam Link? What to Do Next

Clicked a suspicious link? What you do next depends on whether you only opened it, entered information, downloaded something or sent money.

Clicked a suspicious link? What you do next depends on whether you only opened it, entered information, downloaded something or sent money.

Use the steps below to slow the situation down, verify the claim through a separate route and protect yourself without giving the suspicious contact more information.

First: work out what happened

Do not keep reopening the link to investigate it. Instead, note whether you only viewed the page, typed a password, entered personal or banking information, downloaded a file, installed software or approved a payment. Those details determine the right response.

If you only opened the link

If you opened a suspicious page but did not enter information, download files or install software, the National Cyber Security Centre says further action is unlikely to be needed. Close the page, keep your browser and device software updated, and stay alert for unusual account notifications or follow-up messages.

If you entered a password or personal details

Change any password you entered, especially anywhere the same password has been reused. Review the affected account for unfamiliar activity and use stronger sign-in protection such as a passkey or multi-factor authentication where available. If a work account or work device was involved, tell your IT team promptly.

If you entered bank or card details

Contact your bank using the number on the back of your card, inside its official app or another trusted contact route. Do not call a number supplied in the suspicious message. Explain exactly what you entered and follow the bank’s instructions.

If you downloaded or installed something

If the link caused you to download a file or install software, stop using the suspicious software. On devices that support antivirus scanning, the NCSC recommends running a full scan and allowing the security software to deal with anything it finds. If you installed remote-access software at a scammer’s request, contact your bank and the relevant account providers quickly.

Report the scam

Suspicious emails can be forwarded to report@phishing.gov.uk and suspicious texts can be forwarded free to 7726. If you lost money or were hacked, use the UK fraud-reporting route appropriate to where you live; in Scotland, report to Police Scotland.

Practical checklist

Quick checklist

  • Do not reopen the suspicious link
  • Write down what you entered, downloaded or approved
  • Change any exposed or reused passwords
  • Contact your bank if payment details or money are involved
  • Run a security scan if you downloaded or installed software
  • Report the suspicious message or website

Official UK guidance

Scam techniques and reporting routes change. These official sources were checked when this guide was updated: