I clicked a link I should not have
The first thing worth saying is that opening a link is not, by itself, the same as losing an account or a sum of money. In almost every case there is a second step between the click and the harm: typing a password, approving a code, entering card details, or running a file that was downloaded. Knowing which of those steps you took, if any, is what determines what you should do next — and it determines it far more usefully than a general scan does.
These answers are written calmly on purpose. The messages themselves are designed to produce the opposite feeling, and acting quickly out of alarm is how most of the avoidable damage happens. Read the question that matches what you did, take the steps in order, and leave the rest.
I clicked a link in a strange message. What happens now?
If you only opened the page and closed it again, the realistic outcome is that the sender learned the message reached a working number or address. Change nothing in a panic. If you went further and entered something or installed something, the next two questions are the ones to read.
What opening a page can and cannot do
A web page runs inside the browser's own boundaries. On an up-to-date browser and operating system, simply loading a page does not install software on a computer or phone. What the page can do is present a convincing copy of a login screen, ask you to download a file, or ask the browser for permission to send notifications. All three of those need you to do something further.
This is the practical reason that keeping the browser and operating system updated matters more than most other advice. Updates close the gaps that would otherwise allow a page to do more than it should.
What to do, in order, at no cost
- Close the page. Do not use any phone number, chat window or support link shown on it.
- Think back over what, if anything, you typed or approved while it was open. That single recollection decides everything that follows.
- If you typed a password, go to the real website or app yourself and change that password now. Read the question below on entering details.
- If a file downloaded, delete it from the downloads folder without opening it.
- If nothing was typed, approved or run, there is nothing further to do beyond deleting the message and blocking the sender.
Where a paid product comes into it
Security products increasingly include a filter that warns before a known imitation site loads, which is useful preventively but does nothing retrospectively. For a click that has already happened, the steps above are what matter.
How do I tell whether a delivery or bank message is genuine?
Do not judge by the message. Judge by going to the organisation yourself — type its address, or open its app — and seeing whether the same thing is waiting for you there. If it is not in the app, the message was not from them.
Why the message itself is unreliable
Sender names on text messages can be set by the sender, so a message can appear in the same conversation thread as genuine ones from a bank or a courier. Email addresses can be spoofed or can use a domain that differs from the real one by a character. Logos and layouts are trivially copied. None of these signals can be trusted, which is why the advice is to leave the message entirely rather than to examine it harder.
| The message says | What it is doing | What to do instead |
|---|---|---|
| A parcel could not be delivered; pay a small fee | Collecting card details through a convincing payment page | Check the courier's own tracking page using the number on your order confirmation |
| Unusual activity on your account; verify immediately | Creating urgency so the login page is not examined | Open the bank's app yourself; real alerts appear there |
| Your subscription will renew unless you cancel | Getting you to phone a number staffed by the sender | Check the subscription in your account settings on the real service |
| You are owed a refund from a government agency | Collecting banking details | Sign in to the agency's own service; refunds appear there |
| A relative messaging from a new number asking for money | Impersonation that relies on not being verified | Phone the person on the number you already have |
Where official information helps
Scamwatch, run by the National Anti-Scam Centre, publishes descriptions of scams currently circulating in Australia, which is a useful place to check whether a message you have received matches something already known. The Australian Cyber Security Centre publishes guidance on recognising and responding to these messages.
Where a paid product comes into it
Nothing you buy can verify a text message for you. The habit of checking with the organisation directly is free and more reliable than any filter.
I typed my details into a page that turned out not to be real
Act on the account, not on the computer. Change the password on the real service immediately, turn on two-factor authentication while you are there, and if card details were entered, contact your bank. A scan is not the priority here and will not undo anything.
What to do, in order
- Change the password on the affected account by going to the service yourself, not through any link in the message.
- Change it anywhere else you used the same password. This is the step people skip, and it is the one that prevents the damage from spreading.
- Turn on two-factor authentication on that account if it is available.
- Check the account's security settings for a recovery email address, phone number or forwarding rule you did not add, and remove anything unfamiliar.
- If card or banking details were entered, contact your bank through the number on your card or in its app. Banks have processes for exactly this and would rather hear early.
- Sign out of all other sessions if the service offers that option, so that any existing access is ended.
What to watch out for afterwards
People who have been through one of these often receive a follow-up contact offering to recover the money, sometimes appearing to come from a bank, a law firm or a government body. Treat any such approach the same way as the first message: go to the organisation yourself rather than responding to the contact. No legitimate recovery process begins with an unsolicited message asking for a fee or for remote access to your computer.
Where to report it
Reports of cybercrime in Australia go to ReportCyber, which is run through the Australian Cyber Security Centre. Scam reports go to Scamwatch. If the incident involved your personal information being mishandled by an organisation, the Office of the Australian Information Commissioner is the relevant body.
I installed something I now regret. What should I do?
This is the situation where a scan genuinely belongs. Disconnect from the internet if the installation is recent, uninstall the program through the normal route, then run a full scan with the protection on the machine and restart.
Why installing is different from clicking
Running an installer grants software the ability to put files on the machine and, often, to run automatically. That is a meaningfully different situation from loading a web page, and it is the case where security software is doing the job it exists to do. The urgency is real but modest: taking twenty careful minutes is better than taking two frantic ones.
What to do, in order, at no cost
- Disconnect from Wi-Fi or unplug the network cable if the installation happened within the last few minutes.
- Uninstall the program through Settings on Windows or by moving the application to the Bin on macOS, then emptying it.
- Check the start-up list for entries the program added, as described on the slow computer page.
- Run a full scan with your security software and let it finish. Act on what it reports rather than on guesswork.
- Restart, reconnect, and change the password on your main email account from a different device if you have one.
- If the program asked for remote access to your screen, treat every account used on that machine as exposed and work through the steps in the previous question.
When to ask for help
If the computer no longer behaves normally after the uninstall, if files have become unreadable, or if a message demands payment to restore access, stop and get help rather than continuing. The Australian Cyber Security Centre publishes specific guidance for ransomware incidents, and paying is not the recommended first response in that guidance.
Where a paid product comes into it
A product with a support channel is worth something in exactly this situation, because you can ask a person rather than guessing. Norton AntiVirus Plus is a paid subscription of that kind for Windows and macOS.
Visit the Norton AntiVirus Plus website to see what the vendor says the subscription includes.
Paid affiliate link. ORYNA s.r.o. receives a commission on sales through it; your price is the same either way.Is opening an email attachment dangerous?
It depends entirely on what the attachment is. A photograph or a plain PDF viewed in a modern reader is low risk. A document that asks you to enable editing or content, or an executable file arriving unexpectedly, is a different matter.
What makes the difference
Documents can carry macros — small programs that run inside the document — and the prompt asking you to enable content is what allows them to run. Legitimate documents from colleagues occasionally use macros, which is why the prompt exists; unexpected documents from strangers that insist on it are the pattern worth refusing. Compressed archives are used to get past filters, so an unexpected archive containing a single file is worth treating with suspicion.
Attachments that are themselves programs, scripts or installers should not arrive by email from people you do not know, and the fact that one has is itself the signal.
What to do, at no cost
- Check whether the message is one you were expecting from someone you know. If not, do not open the attachment at all.
- Never enable content, macros or editing on a document you did not ask for.
- If you need to see what a document says, open it in a web-based viewer rather than the desktop application, which keeps it away from your machine.
- When a message appears to come from a colleague but reads oddly, confirm by another channel before opening anything.
Where do I report this, and does reporting achieve anything?
Report to ReportCyber through the Australian Cyber Security Centre for cybercrime, and to Scamwatch for scams. Reporting rarely recovers money directly, but it is how patterns are identified and warnings issued.
Which body takes which report
| The incident | Where it goes |
|---|---|
| Money lost, account accessed, device compromised | ReportCyber, via cyber.gov.au |
| A scam message or call, whether or not you lost anything | Scamwatch |
| Cyberbullying, image-based abuse or seriously harmful content | eSafety Commissioner |
| An organisation mishandled your personal information | OAIC |
| Misleading advertising or a business behaving deceptively | ACCC |
Before you report
Keep the message rather than deleting it, note the date and time, and record any amount involved and the account it went to. A report with those details is more useful than one without, and gathering them takes a few minutes. Your bank will also ask for the same information.
A few more questions
Reading a text message does not install anything. The risk comes from the link inside it and what you do on the page it opens. Keeping the phone's operating system updated and installing apps only from the official store covers most of what matters on a phone.
No. Any reply confirms the number or address is in use and generally results in more messages, not fewer. Block the sender and, on a phone, use the reporting option built into the messaging app.
Operating system and software vendors do not phone individuals unprompted about problems on their machines. If you granted remote access, disconnect the computer from the network, change passwords from a different device starting with your email account, and contact your bank if any financial site was open during the session.