← Technology Guides

Email & Account Security

Clicked a phishing link? What to do next

Clicking a suspicious link does not automatically mean an account or computer is compromised. What matters next is whether you entered information, approved a sign-in, downloaded something, or gave someone access to the device.

1. Stop interacting with the message or website

Close the suspicious page and do not reply to the message, call phone numbers shown in the warning, download additional files, or approve unexpected sign-in prompts.

2. If you entered a password, change it from a trusted device

Go directly to the real service using its official app or a known website address. Change the exposed password and any other account that reused the same password. Start with your primary email account because it can often reset other accounts.

3. Check multi-factor authentication

Review recent sign-ins and security settings. Remove unfamiliar sessions or devices when the service allows it. If you approved an MFA prompt you did not initiate, treat the account as potentially exposed and update its security settings immediately.

4. If you downloaded or opened a file, pause before using the computer normally

Unexpected attachments or downloads may need to be investigated. Avoid using the computer for banking or other sensitive activity until you understand what was opened and whether additional cleanup is needed.

5. If someone gained remote access, disconnect them

End the remote session and disconnect the computer from the internet if necessary. Do not provide additional passwords, payment information, gift cards, MFA codes, recovery codes, or access to another device.

6. Preserve the useful details

Keep the sender address, subject, approximate time, website name, downloaded filename, and a description of what you entered or approved. Screenshots can help when they do not expose passwords, account numbers, recovery codes, or other private information.

If payment or financial information was exposed

Contact the bank, card issuer, or financial institution directly using a trusted phone number or official app. Technology support can help secure the device and accounts, but it cannot reverse a transaction or guarantee that information already shared has not been used.

If you are not sure what happened, Potent Technology can help review the computer, account symptoms, Microsoft 365 or email behavior, and the safest next step. If a fake support interaction, remote-access session, or payment request was part of the incident, the scam-help service is the more specific path.