Five Minute Security
Scam Anatomy

The Five-Minute Response Plan After Someone Clicks the Wrong Link

The Five-Minute Response Plan After Someone Clicks the Wrong Link
This article details an immediate emergency response plan for anyone who mistakenly clicks a phishing link or enters credentials on a fake page. Written by a former threat analyst, it provides a step-by-step checklist for the critical first five minutes—such as disconnecting from the internet, changing passwords, and alerting your bank—alongside subsequent actions to audit password reuse, review linked accounts, and secure your digital identity.

The Call I Didn't Want to Get

It was a Wednesday afternoon. I was in my home office, looking at some logs from the router test I'd been running. Miles was asleep under the desk. The house was quiet.

Then my phone rang. It was Emily's mom.

"Dave, I think I did something stupid."

Her voice was shaky. She'd received an email that looked like it came from her bank. It said there was unusual activity on her account and she needed to verify her identity. She clicked the link. She entered her username and password. Then she realized the URL didn't look right.

"I'm so sorry," she said. "I should have known better."

I told her the same thing I'd tell anyone in that situation:

  • Take a breath. You're not the first person this has happened to. You won't be the last.

  • You called me. That's the right thing to do.

  • Now let's work through this together.

The next 30 minutes were a flurry of password changes, account checks, and alerts. But the first five minutes mattered most.


The First Five Minutes: What to Do Immediately

An adult focused on quickly updating account passwords on a laptop at a clean home desk.

1. Disconnect From the Internet

If you clicked a link and entered credentials on a page you're not sure about—especially a login page for a service you use—the first thing to do is disconnect from the internet. This isn't always practical, but it's the fastest way to prevent the attacker from moving further into your account.

On a computer: turn off Wi-Fi or unplug the Ethernet cable.
On a phone: turn off Wi-Fi and cellular data, or put it in airplane mode.

Why this helps: If you've downloaded malware or if the attacker is actively relaying your session, disconnecting prevents them from continuing to act. It stops the attacker from moving laterally, changing credentials, or extracting data from the account you just accessed.

2. Change Your Password (If You Still Can)

If you can still log into the compromised account, change the password immediately.

If the account is your primary email, this is the most urgent. Your email can be used to reset passwords for other accounts.

If the account is a shared streaming or utility account, change the password there as well.

If you can't log in: Skip this step and go to step 3.

3. Enable or Update Multifactor Authentication

If the compromised account supports MFA, set it up or reset it.

If you already had MFA enabled, update the settings. Generate new backup codes. Remove any devices you don't recognize.

If you weren't using MFA before, now is the time. An authenticator app (not SMS) is the most secure option.

4. Check the Account Activity

Most platforms let you see recent login activity.

Log into the compromised account and look for:

  • Unfamiliar login locations or devices

  • Account changes (passwords, security questions, backup email addresses, phone numbers)

  • Any new sessions you don't recognize

If you see anything unusual: Sign out all other sessions. Remove unfamiliar devices. If you're not sure, change the password again after you remove them.

5. Tell Your Bank

If you entered banking credentials, contact your bank immediately. Even if you're not sure the credentials were captured. The threat is time-sensitive. Let your bank know you may have compromised your credentials. They can monitor your account for unusual activity or issue new card numbers if needed.

Specifically ask your bank to:

  • Place a fraud alert on your account

  • Block any suspicious transactions

  • Issue new card numbers if you entered payment information

  • Monitor for unauthorized account changes

6. Report the Phishing

Forward the phishing email to the organization it impersonates and to the relevant reporting bodies.

  • If it impersonated a bank: Forward to the bank's fraud department.

  • If it impersonated a service you use: Forward to that service's abuse or support address.

  • If you're in the U.S.: Report the attack to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. This helps law enforcement track phishing campaigns.


The Next Five Hours: What to Do After the Crisis Passes

1. Check for Password Reuse

This is the step most people skip.

You entered the password for the compromised account—but that password might have been used elsewhere. If you reused it on any other accounts, change those passwords too.

How to check:

  • Use Have I Been Pwned to see if your email appears in past breaches (this is important if you've used that email address anywhere else)

  • Review your password manager for any accounts that might have been affected

  • Check your browser's saved passwords for duplicates or reused credentials

At minimum: If you have a password manager, audit the accounts stored there and ensure each has a strong, unique password. If you're not using a password manager, prioritize the accounts you use most frequently.

2. Review All Accounts Linked to the Compromised Email

If you changed your email password, that's good. But the attacker may have already used your email to reset passwords for other accounts.

Check the following accounts for unauthorized activity:

  • Email

  • Primary social media

  • Banking and financial accounts

  • Online shopping

  • Any accounts with stored payment methods

What to look for:

  • Password reset emails you didn't request

  • Unfamiliar login notifications

  • Changes to contact information (phone number, backup email, linked account)

  • New devices you don't recognize

3. Remove Unfamiliar Devices and Sessions

If the attacker was able to create a session, they might still be logged in.

Log into each affected account and:

  • Sign out all active sessions

  • Remove any unfamiliar devices

  • Generate new authentication tokens (like API keys)

  • Revoke access for any connected apps

Do this especially for your email, password manager, and financial accounts.

4. Place a Fraud Alert on Your Credit

Even if you think the compromise was limited to one account, it's better to be safe.

If you entered personal information on a fake page, consider placing a fraud alert on your credit. This makes it harder for someone to open new accounts in your name.

If you've already done this in the past: The alert is still active. Check the expiration date and renew if needed.

5. Update Security Questions

If the compromised account had security questions, and you're now logged in, change them.

If the account didn't have security questions: Consider adding them (if the service allows it) and use answers that aren't publicly available information.

A person sitting on a cozy sofa holding a smartphone and reviewing account security notifications.

What Not to Do

The first five minutes are critical. So is avoiding common mistakes that make things worse.

Don't Panic

Panic leads to poor decisions. Take a breath. You've caught the problem. Now you're addressing it.

Don't Use the Same Password for Multiple Accounts

If you use the same password for your compromised account and any other account, change the other accounts immediately.

Don't Call the Number in the Phishing Email

If you received a phishing email and it includes a phone number, don't call it. The number may be part of the scam.

Don't Panic If You're Locked Out of the Account

If the attacker has already changed the password and locked you out, you're not alone. Contact the service provider's support team and be prepared to prove your identity.


How to Check for a Compromised Email Address

If you're not sure whether your email has been compromised, check Have I Been Pwned. It's a free service that tracks data breaches and will show you whether your email has been exposed.

If your email appears in a breach:

  • Change the password on that email account immediately

  • Enable MFA if you haven't

  • Check for password reuse across other accounts

  • Monitor the account for unusual activity


The Bottom Line

A phishing click is not the end of the world. But it requires a structured response.

The first five minutes matter most. Disconnect, change passwords, enable MFA, check account activity, and contact your bank. The next five hours are for reviewing password reuse, checking for account changes, monitoring linked accounts, and reviewing credit reports.

Five minutes now beats five hours later.

If you've recently clicked on a suspicious link or entered your credentials on a fake login page, take a deep breath. You're taking the right steps. Now act on them.


Dave C. — Five minutes now beats five hours later.

Revised · 2026-09-14 11:00
Margin Notes

No notes on this sheet yet.

Add a Note
© 2026 The Five Minute Security. All rights reserved. drawn by hand