What to do after clicking a suspicious link
Clicking a bad link is not the same as being hacked. What happens next depends entirely on what you did after the click, and the next fifteen minutes matter more than the click did.
The short version
- Opening a page is usually harmless. Typing credentials into it is not.
- If you entered a password, change it now — starting with your email account.
- If you installed anything, treat the device as untrusted until it is removed.
- If money moved, call 1930 and your bank before anything else.
First, work out what actually happened
Simply loading a page in a modern, updated browser very rarely compromises a phone or laptop. Browsers isolate pages deliberately. So the honest first question is not "am I hacked" but "what did I do after the page loaded".
Three answers matter. If you only looked at it and closed it, you are almost certainly fine. If you typed a password, an OTP or card details, that data is gone and you need to act now. If you installed an app, granted a permission or approved a login prompt, treat that as the serious case.
If you entered a password
Change it immediately, and change your email account's password first even if that is not where you typed it. Email is the reset route to everything else, so it is the account an attacker pivots to.
Then change it anywhere you reused it — and be honest with yourself about where that is. Reuse is what turns one phished password into six lost accounts.
Turn on two-factor authentication on those accounts while you are in the settings. It is the difference between a stolen password being an inconvenience and being a takeover. Finally, sign out all other sessions, which most platforms offer as a single button, so an attacker already logged in is thrown out.
If you entered an OTP
An OTP is single-use and short-lived, so the damage is immediate or not at all. Check the account it belonged to right away: recent transactions on a bank account, active sessions and login activity on a social account, and whether the registered email, phone number or 2FA method has been changed. A changed recovery detail is the strongest sign someone is settling in, and it is what you need to reverse first.
If you installed something or approved a prompt
Uninstall it, then check what it was allowed to do. On Android, look at Accessibility services, SMS access and any app holding "display over other apps" — those permissions let an app read your OTPs and overlay a fake login screen. Also revoke it from your Google or Apple account's connected-apps list, because uninstalling does not withdraw an access grant. Until you have done both, do not use banking apps on that device.
If money has moved
Report it at cybercrime.gov.in or call 1930 immediately, then call your bank's official number and ask them to freeze the account and flag the transaction. Speed genuinely changes the outcome here: a transfer that has not yet settled can sometimes still be held, and that window is measured in hours. Do this before you spend time investigating what went wrong.
What not to bother with
Do not factory reset a phone in a panic — it destroys evidence and rarely helps if nothing was installed. Do not pay for a random "security scan" advertised to you afterwards, and do not contact anyone who offers to recover your money for a fee, because that is a second scam aimed at people who have just lost money. Above all, do not stay quiet out of embarrassment: these scripts are rehearsed on millions of people and getting caught by one says nothing about you.
Nothing on this site will ever ask for your password, OTP or recovery codes.
Related guides
Want this handled for you?
Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.
Talk to Our Security Team