It happens to careful, clever people every day. A text about a parcel, a message “from your bank”, an email that looked just right. You tapped the link, and now your stomach has dropped.

Take a breath. Phishing, where scammers send fake messages with links, was the most-reported crime among people over 60 in the FBI’s latest report. You’re far from alone, and there’s a lot you can do right now.

Plain talk: phishing

Phishing (said “fishing”) is when a scammer sends a fake message that pretends to be from a company or person you trust, hoping you’ll click a link and type in private details.

Step 1: Stop and close the page

Close the web page or app the link opened. Don’t type anything else into it, don’t tap any more buttons, and don’t call any number it shows.

Step 2: Work out what happened

Find the line below that matches what you did, then follow those steps.

You’re very likely fine. On a phone, tablet or computer that’s kept up to date, just opening a page rarely does harm on its own.

  1. Delete the message.
  2. Check that your device’s software is up to date (see Step 4).
  3. Carry on, and keep an eye out for follow-up messages.

You typed in a password

  1. Go to the real website or official app. Type the address yourself; don’t use the link.
  2. Change the password to a new one you haven’t used anywhere else.
  3. If you used the same password on other accounts, change those too, starting with your email.
  4. Turn on two-step verification, so a password alone isn’t enough to get in.

You typed in card or bank details

  1. Call your bank now, using the number on the back of your card or on a statement.
  2. Tell them what happened. Ask them to block the card and watch for strange payments.
  3. Don’t wait to see if anything goes wrong. The sooner the bank knows, the more it can do.

You gave out ID numbers (such as a Social Security or Medicare number)

Contact your country’s identity protection service. In the US, go to IdentityTheft.gov. In Australia, call IDCARE on 1800 595 160. Elsewhere, your bank or the police can tell you who to contact.

You installed an app or let someone “take control” of your device

  1. Turn on Airplane mode (phone or tablet) or unplug the internet cable and turn off Wi-Fi (computer).
  2. Don’t use online banking on that device until it’s been checked.
  3. From a different device, change your email and bank passwords.
  4. Ask a trusted technician, or the store where you bought the device, to check it.

You paid money

Call your bank immediately, then report it. Here’s where to report a scam.

Step 3: Never share a code you didn’t ask for

If a text arrives with a code you didn’t request, someone may be trying to get into your account. Don’t share it with anyone, even someone who says they’re from the company. No real company will ever ask you to read a code back to them.

Safety tip

A caller who asks you to read out a code sent to your phone is a scammer, every time.

Step 4: Update your device

Updates fix the weak spots scammers look for.

  • iPhone or iPad: open Settings, tap General, then Software Update.
  • Android phone: open Settings and search for Software update or System update.
  • Computer: run Windows Update, or Software Update on a Mac.

Step 5: Watch, report and tell someone

  • Check your bank statements and email for a few weeks for anything you don’t recognize.
  • Report the scam. In the US, UK and Canada you can forward scam texts to 7726. See where to report a scam for your country.
  • Tell a friend or family member. Scammers count on embarrassment. Talking about it protects others.

Try this

Next time a message asks you to click, try the “don’t click, go direct” habit: close the message and open the company’s official app or type its website yourself. If there’s really a problem, you’ll see it there.