Skip to content
SOS Informatique Computer repair in Lyon - Individuals and businesses

What to do after clicking a fraudulent link

Clicking is not always enough to do harm. What counts is what you did next - and how quickly you react now.

Start by taking a breath : this happens to well-informed people, the imitations have become excellent. What follows depends on a single question - did you only open the page, or did you type something into it ?

You only opened the page

With nothing typed and nothing downloaded, the risk is low. Close the tab, do not go back to the page, and run a full antivirus scan as a precaution. Stay alert over the following days to any unusual behaviour from the machine.

You typed in a password

Here you need to act straight away, in this order :

  1. Change that password immediately, going to the real site - address typed by hand, never from the message you received.
  2. Change it everywhere else you used the same one. That is the real danger of reuse : one stolen password opens several doors.
  3. Turn on two-factor authentication for the account concerned. Even if the password is circulating, it will no longer be enough.
  4. Check your email rules. An attacker often sets up an automatic forward so they can keep reading your messages after you change the password. Look at the filters, the forwarding settings and the recovery addresses saved on the account.

You entered bank details

Call your bank without waiting, using the number on the back of your card, and ask for the card to be stopped. Most banks have an emergency line open at all hours.

You can then report the incident and, if money has left the account, file a police report. Keep everything : the message you received, screenshots, the address of the site. Those are what the dispute file is built on.

You downloaded or opened a file

Disconnect the machine from the internet, then run an offline scan from Windows Security - it runs before the system starts and catches what an ordinary scan misses. The steps are set out in our article on removing a virus.

If the file was an office document that asked you to "enable macros", treat the machine as compromised and have it examined.

You gave someone remote access

This is the most serious case. If you installed remote access software at a caller's request, that person had full control of the machine : files, open accounts, saved passwords.

Switch the computer off, uninstall the remote access software, change your important passwords from another device, and keep an eye on your bank accounts. A clean reinstall is the only serious guarantee here.

Recognising the trap next time

Urgency is the main signal : account blocked, parcel on hold, fine to pay before tonight. Then check the sender's real address, not just the display name. Hover over links without clicking to see where they lead. And remember that no public body and no bank ever asks for a password or a code in a message.

The following days

Keep an eye on your bank statements, small amounts included - a one-euro debit is often used to test a card before something larger. Be wary too of a call that follows soon after the incident : scam victims are frequently contacted by fake support services offering to "recover the funds".

Getting support

We can check the state of the machine, go through your email settings and help you secure your accounts, often remotely with no visit needed.

Frequently asked questions

Do I necessarily have a virus if I clicked a link ?

No. The great majority of fraudulent links lead to a fake login page meant to steal a password, not to install a program. If you typed nothing and downloaded nothing, the risk stays low.

Should I report phishing to the police ?

It is advisable as soon as there is a financial loss, and banks often require it for the dispute. Reporting is useful even where no money was lost.

My email address is sending messages to my contacts, what should I do ?

Change the password from another device, turn on two-factor authentication, then check the forwarding rules and the authorised apps in the account settings. That is where access is most often maintained.

Further reading

Would you rather we took care of it ? See our virus removal and cleanup service, in Lyon and across the Rhone.

Uneasy after a suspicious message ?

We check the machine and your accounts, remotely or at your home.

Contact Us