Clicked on phishing link is the search made with the browser still open, and the answer has to be short: disconnect the device from the network, tell the person who owns security, change the password of any account whose details were typed, from a different device, and turn on the second factor if it was not already. What to do if you clicked a phishing link and typed nothing is the first two steps; clicked on link in phishing email and typed a password is all four. Phishing vs smishing is the same trick by email against by text, and the response is the same. For the owner or office manager who has been handed security, the point is that the steps should be written before the click, and the free policy sheet on this site sizes the written set the incident response policy belongs to, with no account.
The fifteen minutes
Disconnect: wifi off, cable out. Tell: the named person in the response policy, by phone, not by replying to the email. Change: the password of any account whose details went into the page, from another device, and any other account that shared it. Confirm: the second factor is on, and the sign-in history shows nothing new. Report: to the email provider and, for a US organisation, to the FBI's IC3 if money or data moved.
Why the plan is written first
A person who has just clicked is not going to compose a procedure; they need one with a name and a phone number on it. Incident response is one of the six core policies in the set the policy sheet on this site sizes: 12 people, 8 systems with their own login, remote work, card payments and personal devices is a set of nine policies, 27 hours to draft, 13.5 hours a year to keep reviewed and $1,822.50 in the first year at $45 an hour on the worked example. Hardenvo Pro writes it with the organisation's own names and keeps it current at one flat price.
Phishing vs smishing
Phishing arrives by email and smishing by text message; the link, the fake sign-in page and the theft are the same, and so is the response. Smishing gets past the email filter because there is no email, which is why the training policy covers both and why the second factor matters more than the filter.
Questions people ask about clicked on phishing link
I clicked on a phishing link, what now?
Disconnect the device, tell the named person, change any password you typed from another device, confirm the second factor is on, report it; the written response policy should already say all of this.
What is the difference between phishing and smishing?
Email against text message; same link, same fake page, same response.
Where should the response steps live?
In the incident response policy, one of the six core policies the free policy sheet sizes and Hardenvo Pro writes with your names in it.