I Think I Clicked a Bad Link — Now What?

First: you're not the first person this has happened to, and panicking won't help. Here's exactly what the FTC recommends, based on what actually happened when you clicked.

If you're not sure anything downloaded, but you gave out information

If you think a scammer now has information like your Social Security number, credit card number, or bank account number, go to IdentityTheft.gov. It will walk you through the specific steps to take based on exactly what information was exposed — the right next step depends on what you gave them, so this is the fastest way to get an answer specific to your situation rather than a generic one.

If you think something downloaded onto your device

If you clicked a link or opened an attachment that may have installed something harmful, update your computer's security software, then run a scan and remove anything it flags as a problem.

Either way: report it

Reporting helps beyond just you — it helps the FTC track and fight the people running these scams. If you got a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org. If you got a phishing text message, forward it to SPAM (7726).

If you're still unsure what happened or what you clicked, and you gave out personal information, IdentityTheft.gov is the right starting point; it's built to help you figure out the right next step even when you're not certain what was exposed.

Want to recognize the next one before you click? See the 4 common signs →

Based on the Federal Trade Commission's Consumer Advice, “How To Recognize and Avoid Phishing Scams” (consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams), and IdentityTheft.gov.