
Protect · 6 min
You clicked a suspicious link. Use the first hour well.
Match the response to what you entered, installed, approved, or paid.
A calm sequence
- 01
Name what happened
Clicking, entering a password, giving a code, downloading a file, installing software, granting remote access, and sending money require different responses. Write down the time and what you did.
- 02
Protect the account
From a trusted device, go directly to the real service, change any exposed password, sign out other sessions if offered, and turn on multifactor authentication. Change reused passwords on other accounts too.
- 03
Protect the device
If software was installed or control was granted, disconnect the device from the network. Use built-in or trusted security tools and seek qualified help if you cannot verify what changed.
- 04
Protect the money
Call the bank, card issuer, or payment provider through a number you know is real. Ask about stopping or reversing transactions and watch for follow-up impersonation attempts.
- 05
Report the message
Use the email or messaging service’s report function and report fraud to the FTC. Tell affected people if the attacker may send messages from your account.
Pause when you see
- A follow-up caller promising recovery
- Changing the password through the suspicious link
- Reusing the newly changed password elsewhere
Primary sources