Clicking is not always enough to do harm. What counts is what you did next - and how quickly you react now.
Start by taking a breath : this happens to well-informed people, the imitations have become excellent. What follows depends on a single question - did you only open the page, or did you type something into it ?
With nothing typed and nothing downloaded, the risk is low. Close the tab, do not go back to the page, and run a full antivirus scan as a precaution. Stay alert over the following days to any unusual behaviour from the machine.
Here you need to act straight away, in this order :
Call your bank without waiting, using the number on the back of your card, and ask for the card to be stopped. Most banks have an emergency line open at all hours.
You can then report the incident and, if money has left the account, file a police report. Keep everything : the message you received, screenshots, the address of the site. Those are what the dispute file is built on.
Disconnect the machine from the internet, then run an offline scan from Windows Security - it runs before the system starts and catches what an ordinary scan misses. The steps are set out in our article on removing a virus.
If the file was an office document that asked you to "enable macros", treat the machine as compromised and have it examined.
This is the most serious case. If you installed remote access software at a caller's request, that person had full control of the machine : files, open accounts, saved passwords.
Switch the computer off, uninstall the remote access software, change your important passwords from another device, and keep an eye on your bank accounts. A clean reinstall is the only serious guarantee here.
Urgency is the main signal : account blocked, parcel on hold, fine to pay before tonight. Then check the sender's real address, not just the display name. Hover over links without clicking to see where they lead. And remember that no public body and no bank ever asks for a password or a code in a message.
Keep an eye on your bank statements, small amounts included - a one-euro debit is often used to test a card before something larger. Be wary too of a call that follows soon after the incident : scam victims are frequently contacted by fake support services offering to "recover the funds".
We can check the state of the machine, go through your email settings and help you secure your accounts, often remotely with no visit needed.
No. The great majority of fraudulent links lead to a fake login page meant to steal a password, not to install a program. If you typed nothing and downloaded nothing, the risk stays low.
It is advisable as soon as there is a financial loss, and banks often require it for the dispute. Reporting is useful even where no money was lost.
Change the password from another device, turn on two-factor authentication, then check the forwarding rules and the authorised apps in the account settings. That is where access is most often maintained.
Would you rather we took care of it ? See our virus removal and cleanup service, in Lyon and across the Rhone.
We check the machine and your accounts, remotely or at your home.
Automatic assistant: it can make mistakes. Never share a password or a card number.