17/06/2026
What to do if you think you’ve clicked a dodgy link...
It can happen, even to careful people. What matters is what you do next.
Disconnect immediately by turning off your Wi‑Fi / unplug the network cable to stop anything spreading.
Don’t enter any details. If the link asked for passwords, card details, or codes be sure to close it straight away.
Delete any downloads that may have been automatically downloaded. Do not open them.
Run a security scan using your antivirus or business security tools as soon as possible.
Change your passwords starting with email, Microsoft 365, banking, and anything important. Ideally from a different device if you can.
Enable 2FA/MFA if it is not already enabled.
Check bank accounts, credit cards and social media for any fraudulent activity.
Tell your IT support provider and your bank (if financial info may be affected).
At work, report it internally too.
Alert your contacts if your email may have been compromised telling them not to click on any links from you.
Be alert for follow‑up scams, fraudsters often try again once they know a link was clicked.
If you only clicked the link but did not enter data, the risk is lower but not zero. It is still recommended to run a scan, as the link might have initiated a "drive-by download" of malware.