Clicking a suspicious email link is unsettling, but the click alone does not prove that your computer has been infected or that an account has been stolen. The risk depends on what happened next: whether a page opened, credentials were entered, a file was downloaded or run, browser permissions were granted, or unusual activity appeared afterward.
Use the steps below in order. If this happened on a work computer, contact your organization’s IT or security team before making extensive changes. Business systems may require specific evidence-preservation and incident-reporting procedures.
First, stop interacting with the message
Close the suspicious page without clicking buttons such as “verify,” “scan,” “allow,” “clean,” or “download.” Do not reply to the email, call a phone number shown on the page, or use contact information supplied by the message.
If the page is frozen or repeatedly showing pop-ups, close the browser window. On Windows, you can use Alt+F4. If necessary, open Task Manager with Ctrl+Shift+Esc, select the browser, and choose End task. This does not remove malware, but it can stop a browser page from continuing to display deceptive content.
Warning: If you entered a password, payment information, Social Security number, recovery code, or other sensitive data, treat the information as exposed. Do not wait for proof of misuse before taking account-protection steps.
Decide what actually happened
Make a quick note of the sequence while you still remember it. Record the sender, approximate time, link destination if visible, and any information you entered. If possible, save the original email or report it through your email provider’s phishing option. Avoid forwarding it to coworkers or friends unless your IT or security team requests that.
Consider which of these situations applies:
- A page opened, but you entered nothing and downloaded nothing: The immediate risk may be limited, but browser notifications, fake support prompts, and malicious redirects are still possible.
- You entered a username or password: Assume that credential is compromised, especially if you reuse it elsewhere.
- You entered banking or payment information: Contact the bank or card provider using the number on a card or an official statement, not the suspicious message.
- A file downloaded: Do not open it. Do not double-click it just to see what it contains.
- You opened or ran a file, installed software, or allowed remote access: Treat this as a higher-risk incident and move to containment and professional assistance if you are unsure what changed.
- You noticed unexpected browser behavior, security warnings, new programs, pop-ups, or account alerts: Record the symptoms and avoid making unnecessary changes until the device has been checked.
If a file was downloaded or executed
Warning: If you opened a downloaded program, enabled macros, installed a browser extension, granted remote-control access, or saw signs of ransomware, disconnect the computer from Wi-Fi or unplug its network cable. Do not sign in to additional accounts from that computer.
Disconnecting the network can limit communication with an attacker, although it does not undo changes already made. If the computer contains important business or personal files, avoid repeatedly restarting it, deleting suspicious files, or running random “cleanup” tools. Those actions can make diagnosis harder and may destroy useful evidence.
For a simple download that was not opened, check the browser’s Downloads folder and remove the file after noting its name and location. Emptying the Recycle Bin is not necessary as a first step. If malware may have executed, let a qualified technician or your organization’s IT team decide whether the device should be scanned, restored, or examined more deeply.
Protect accounts from a trusted device
If you entered credentials, use a different device that you trust, such as a known-clean phone or another computer. Go directly to the real website by typing its address yourself or using a previously saved bookmark. Do not use the suspicious email’s link.
- Change the exposed password to a new, unique password.
- Change the same password anywhere else it was reused.
- Review recent sign-ins, active sessions, forwarding rules, recovery email addresses, phone numbers, and security settings.
- Sign out unfamiliar sessions and remove unknown authentication methods or connected applications.
- Enable multifactor authentication using an authenticator app or security key where available.
Do not share a one-time code with anyone who calls or messages you. A person who already has a password may try to trick you into approving a login or handing over a verification code.
If the exposed account is your email account, secure it first. Email access can allow someone to reset other passwords. Check for unfamiliar forwarding rules, automatic replies, sent messages, deleted messages, and mailbox rules that hide security notices.
Check financial and identity information
If you submitted a card number, bank login, tax information, identity number, or other sensitive details, contact the relevant institution through an independently verified channel. Ask what monitoring, card replacement, transfer review, or account lock options are appropriate. Keep notes of when you reported the exposure.
Be cautious of follow-up calls or texts claiming to be from your bank, email provider, Microsoft, Apple, or a security company. The original phishing attempt may be followed by additional social-engineering attempts based on what you submitted.
Check the computer safely
If you only visited the page and did not download, run, or install anything, update the operating system and browser, then run a full scan using the computer’s built-in security software. On Windows, Windows Security can check for malware through Virus & threat protection. Keep the definitions and system updates current before scanning.
Also review:
- Browser extensions you do not recognize.
- Website notification permissions for unfamiliar domains.
- Recently downloaded files.
- New applications installed around the time of the click.
- Unexpected browser home pages, search engines, or proxy settings.
Remove only items you can identify with confidence. A legitimate program or browser extension can have an unfamiliar name, and deleting system files or registry entries based on an internet search can create new problems. If the security scan reports a threat, follow the security software’s recommended action and note the detection name.
When to stop troubleshooting
Stop and seek assistance if the computer shows ransomware messages, repeated security warnings, disabled antivirus protection, unknown remote-control software, unexplained account changes, missing files, unusual encryption prompts, or persistent redirects. Also stop if you are unsure whether a file ran or whether a password change was completed correctly.
For a home computer, a reputable computer repair professional can help determine whether the issue is limited to a phishing page or involves a broader compromise. For a small business, notify the person responsible for technology or security promptly. The device may need a controlled malware examination, password reset plan, restore from a known-good backup, or—in serious cases—a clean operating-system installation.
Do not rely on these common assumptions
- “The page looked blank, so it was safe.” A page can still collect information or trigger a download.
- “My antivirus did not pop up, so nothing happened.” Credential theft often does not look like traditional malware.
- “I changed one password, so all accounts are safe.” Reused passwords and active sessions may remain exposed.
- “The sender looked familiar.” Mailboxes and display names can be forged or compromised.
- “I should call the number on the warning page.” Fake support pages commonly use phone numbers to obtain payment or remote access.
Prevent the next mistake
Turn on multifactor authentication, use a password manager, and keep Windows, macOS, browsers, phones, and security software updated. Before signing in, inspect the actual website address rather than trusting the logo or page design. Be especially cautious with urgent requests involving payroll, invoices, package delivery, account suspension, gift cards, or password expiration.
If you are in Bellevue, Omaha, Papillion, La Vista, Plattsmouth, Ralston, Council Bluffs, or nearby communities, the safest response is the same: stop interacting with the message, protect exposed accounts from a trusted device, preserve useful details, and get help when the computer may have run something. A suspicious click is a reason to investigate carefully—not a reason to panic or install more unverified software.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

