What matters next is what happened after the click: what the page did, what you entered, whether anything downloaded or ran, and whether you approved access.

Take a breath. Then work through the steps that apply to you.

Close the page

Do not continue clicking, call a phone number shown on the page, or download a tool it recommends. Close the browser tab or app. If a pop-up will not close, quit the browser or restart the device.

Notice what happened

Did the page simply open? Did a file download? Did you enter a password, card number, Social Security number, or one-time code? Your next steps depend on the information or access involved.

Change any password you entered

Use a different, trusted device if possible. Go directly to the real service—not through the message—and change the password. If you used the same password anywhere else, change it there too. Turn on multifactor authentication if it is available.

Contact a bank or card issuer when payment details were involved

Call the number on the back of the card. Explain that the number may have been entered on a fraudulent site. The issuer can advise whether to replace the card, watch the account, or dispute a transaction.

Check the device

If a file downloaded, an app was installed, or the device behaves unexpectedly, stop using the suspicious content and get current, device-specific help from the device maker or a support service you independently choose. Do not call a number from the warning page or rely on one generic cleanup step for every device.

Save useful evidence

Before deleting the original message, take a screenshot or write down the sender, time, and web address if you can do so without reopening the link. This can help a bank, employer, or law-enforcement report.

Quick checklist

  • Close the page
  • Write down what you entered or downloaded
  • Change exposed passwords
  • Call card issuers or banks directly
  • Check the device if anything downloaded
  • Tell a trusted person what happened

Acting quickly is useful. Panicking is not. Work from the most sensitive thing exposed—money, account access, identity information, or device control—and use official contact routes at every step.