Scam Protection
What to Do If You Clicked a Phishing Link — Step-by-Step Guide for Seniors
You got a text or email that looked real. Maybe it said your bank account was locked, or your package couldn't be delivered. You clicked — and a second later, something felt wrong.
First: take a breath. Clicking a phishing link is not the end of the world. What matters most is what you do in the next 15 minutes.
This guide walks you through exactly what to do, in order, without any technical jargon. Whether you clicked on your phone, tablet, or computer — these steps work.
Last updated: 2026-06-22
Step 1: Don't Enter Any Information (Stop Immediately)
If a webpage opened after you clicked, do not type anything into it. No name, no password, no Social Security number, no credit card number. Close the tab or browser right now.
Phishing links do one of two things:
- Open a fake website that tricks you into typing your information
- Silently download something onto your device in the background
If you closed the tab without entering any information, you may be completely fine. The danger multiplies the moment you type anything into that page.
If you already entered information — keep reading, because steps 3 through 7 are critical for you.
Step 2: Disconnect From the Internet Temporarily
This sounds dramatic, but it takes 10 seconds and can prevent a lot of damage.
On your phone: turn on Airplane Mode (swipe down from the top of your screen and tap the airplane icon).
On your computer: unplug the internet cable, or click the Wi-Fi symbol and select "Disconnect."
Why does this help? Some phishing links download small programs called malware that "phone home" — meaning they send your information to criminals as long as you're connected. Cutting the connection gives you time to run a scan before anything more gets out.
You only need to stay disconnected for 5–10 minutes while you complete the next step.
Step 3: Run a Security Scan on Your Device
Now reconnect to the internet briefly for this step.
On your phone:
- iPhone users: Apple's built-in security is strong. Go to Settings → Privacy & Security and check that nothing looks unfamiliar. Also check your installed apps for anything you don't recognize.
- Android users: Open the Play Store, tap your profile icon, and select "Play Protect" → "Scan." This checks your apps for anything harmful.
On your computer:
- Windows: Open the Start menu, search for "Windows Security," and run a Full Scan.
- Mac: Macs don't have built-in malware scans, but you can download Malwarebytes (free version) from the official Malwarebytes website to run a scan.
If the scan finds anything suspicious, follow the instructions to remove it. Write down what it says before you click "remove" — that information may be useful later.
Step 4: Change Your Passwords (Starting With Email)
If the link looked like it came from your bank, email provider, Amazon, or any site where you have an account — change your password on that site right now, even if you didn't type anything.
Start with your email. Email is the master key to everything else. If criminals get into your email, they can reset passwords on every other account you have.
Here's how to change your Gmail password: go to gmail.com → click your profile photo → Manage Your Google Account → Security → Password.
Change passwords in this order:
- Email (most important)
- Online banking and investment accounts
- Social media (Facebook, etc.)
- Amazon and any shopping sites
- Medicare portal or any health accounts
Use a password that's at least 12 characters long and different for every account. If remembering passwords feels impossible, a password manager like 1Password stores them all securely so you only need to remember one.
Step 5: Turn On Two-Factor Authentication
Changing your password is good. Adding two-factor authentication (2FA) is even better.
Two-factor authentication means that even if someone steals your password, they still can't get in — because they'd also need your phone. Most people think of it as getting a text message with a 6-digit code when you log in.
To turn it on for Gmail: go to myaccount.google.com → Security → 2-Step Verification → Get Started.
For your bank, look under Settings or Security in their app or website. Most major banks now offer this.
It takes about 5 minutes to set up and adds a huge layer of protection to your most important accounts.
Step 6: Watch Your Bank Accounts and Credit Reports for the Next 30 Days
This is especially important if you entered any information — even just your name or email — on the suspicious page.
Log into your bank and credit card accounts every few days and look for:
- Small charges you don't recognize (criminals often test with a $1–$5 charge before making a bigger one)
- New accounts opened in your name
- Transfers you didn't authorize
You're also entitled to free credit reports from all three bureaus at AnnualCreditReport.com. Check yours now and again in 30 days.
If you want professional eyes watching this for you, an identity theft protection service runs 24/7 monitoring on your behalf and alerts you the moment something suspicious appears.
Aura Identity Theft Protection monitors your Social Security number, bank accounts, credit cards, and even the dark web, and alerts you within minutes of suspicious activity — not days. They also provide up to $1 million in identity theft insurance if something does go wrong. For seniors who want peace of mind without having to log in and check manually, it's one of the most practical tools available.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
Step 7: Consider a Credit Freeze
A credit freeze is free, takes about 10 minutes to set up, and is one of the most powerful protections available to you. When your credit is frozen, no one — including criminals who have your information — can open a new credit card, loan, or line of credit in your name.
You need to freeze your credit at all three bureaus separately:
- Equifax: equifax.com/personal/credit-report-services
- Experian: experian.com/freeze/center.html
- TransUnion: transunion.com/credit-freeze
When you need to apply for credit yourself — say, refinancing your home or opening a new account — you temporarily unfreeze it online and refreeze when done. It does not affect your current credit cards or existing accounts.
What If You Already Gave Them Your Information?
If you typed your name, Social Security number, bank account number, or credit card number into the page, act quickly:
Bank or credit card number: Call the number on the back of your card right now. Tell them you may have given your information to a phishing site. They can freeze the card and watch for fraud.
Social Security number: Place a credit freeze (see Step 7) and call the Social Security Administration's fraud hotline at 1-800-269-0271.
Medicare number: Call 1-800-MEDICARE (1-800-633-4227) and report possible misuse.
Password for a major account: Change it immediately and enable two-factor authentication (see Steps 4 and 5).
Protecting Your Retirement Savings Specifically
Phishing attacks disproportionately target retirees — and for good reason. Retirement accounts represent decades of savings that criminals would love to access.
If you have an online 401(k), IRA, or brokerage account, log in to each one and check for anything unusual. Also make sure the email address on file is yours and still secure — if criminals gained access to your email, they could use it to reset your investment account passwords.
Some retirees also choose to hold a portion of their savings in physical gold or silver as a way to diversify away from accounts that can be compromised digitally. Unlike a brokerage account, physical precious metals can't be stolen through a phishing link.
Augusta Precious Metals specializes in helping retirees move part of their IRA into gold and silver. They offer free educational resources with no sales pressure, which is unusual in this industry.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
The Strongest Layer of Everyday Protection
Beyond responding to one phishing click, the best defense is protection that works in the background — so you're covered even when you don't notice something is wrong.
NordVPN is a tool that works quietly in the background on your phone and computer. It does two important things:
- Encrypts your internet connection — so even on public Wi-Fi at a coffee shop, doctor's office, or library, no one can intercept what you're doing
- Blocks known malicious websites — NordVPN's Threat Protection feature automatically blocks phishing sites before they can load, even if you click a link
Most people set it up once and then never think about it again. It runs in the background and does its job automatically. The first month is free, so there's no risk in trying it.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
How to Avoid Phishing Links in the Future
Now that you've handled the immediate situation, a few habits will dramatically reduce your chances of getting caught again:
Slow down when you get unexpected messages. Phishing works by creating urgency. "Your account will be closed!" "Your package is held!" That pressure is the trick. Real companies almost never demand immediate action via text or email.
Call to verify, don't click. If you get a message from your bank, Social Security, or Medicare and you're not sure if it's real — don't click anything. Call the organization directly using the phone number on their official website or on the back of your card.
Look at the sender's address carefully. Phishing emails often use addresses like "support@amazon-secure-help.com" instead of a real Amazon address. If the domain looks strange or long, it's probably fake.
When in doubt, delete it. No legitimate company will penalize you for not clicking a link in a text or email. You can always log in to your account directly by typing the address into your browser.
You're More Prepared Than You Think
Clicking a suspicious link doesn't make you careless — these messages are designed by professional criminals to fool people. Banks, hospitals, and government agencies have all been tricked by similar tactics.
What matters is that you stopped, looked it up, and took action. That puts you ahead of most people.
Bookmark this page so you have it if this ever happens again. And if you want ongoing protection that watches your accounts automatically, Aura and NordVPN are the two tools we recommend most for seniors who want real security without complexity.
Want weekly safety tips in plain English? Join thousands of seniors who get ClearShield's free newsletter — no technical jargon, just practical advice you can actually use.
Stay Updated
Join our newsletter for the latest updates.
Related reading
Can You Spot the Fake? 5 Real vs. Fake Emails — Phishing Quiz
Think you can tell a real email from a phishing scam? Test yourself with 5 side-by-side examples and learn exactly what to look for.
Online Scams Targeting Seniors: How to Spot & Avoid Them
Seniors lose billions to online scams each year. Learn to spot phishing, tech support fraud, romance scams, and more — plus steps to protect yourself.
Amazon Impersonation Scams: How to Tell a Real Amazon Email From a Fake One
Fake 'your Amazon account has been suspended' and 'unusual order' emails are one of the most common scams targeting seniors. Here's how to spot them in seconds.