Scams & fraud

I clicked a phishing link but didn't enter anything — am I hacked?

Some links on this page may be affiliate links. If you buy through them we may earn a small commission, at no extra cost to you. We only recommend tools we believe are genuinely worth it. Learn more.

You got a text or email, tapped the link before your brain caught up, and now there’s a knot in your stomach. First, breathe. If all you did was open the link and you didn’t type anything in or download a file, you are very probably fine. Let me explain why, and what to actually watch for.

On an up-to-date phone or computer, opening a link usually just loads a web page. A page on its own can’t reach into your phone and empty your bank account. The danger almost always comes from what happens next:

  • You type something in — a password, card number, or login. That’s the real prize for a scammer.
  • You download and open a file — that’s how malware gets on a device.
  • You’re talked into installing an app or granting permissions — for example a “support” tool that hands someone remote control.

If you didn’t do any of those, the click by itself rarely amounts to much.

The rare exceptions

There’s a small caveat for honesty’s sake. Very old, unpatched phones and computers can occasionally be caught by a “drive-by” page that exploits a known flaw. This is uncommon, and the fix is the same boring advice that protects against most things: keep your device and browser updated so those holes are already closed.

What to do right now

  1. Don’t type anything into the page. Close the tab.
  2. Don’t open anything it tried to download. If a file landed in your downloads, delete it without opening it.
  3. Say no to any prompt asking you to install an app, allow notifications, or “verify” yourself.
  4. Run a quick scan if you’re worried. The protection built into your phone or Windows is enough for this — see do you really need antivirus.
  5. Make sure your device is up to date.

The real trap is the follow-up. Plenty of scam pages do nothing until they get you to the *next* step — a fake login, a "call this number" warning, or a file to open. Clicking is rarely the disaster. Doing what the page tells you to is.

Report it so the networks can act, then delete it. Forward scam texts to 7726 (it spells “SPAM”). For the patterns to recognise next time, see how to spot a phishing email and is that ‘missed delivery’ text a scam.

The honest bottom line

Clicked it and closed it without entering anything? You’re very likely in the clear. Keep your guard up for a follow-up message, keep your device updated, and never type details into a page you reached from a surprise link.

The one situation that does need action is if you went a step further and entered your details — here’s exactly what to do if you typed your information into a fake site. And if money was taken, follow what to do if you’ve been scammed. More in our scams and fraud section.