What to Do After Clicking a Suspicious Link

What to Do After Clicking a Suspicious Link

Clicking a suspicious link does not automatically mean that a device or business account has been compromised. What matters next is what happened after the page opened. If you entered a password or bank details, downloaded a file, or installed an app, take a few practical steps and tell the right person promptly.

For a work laptop or phone, inform your manager or IT support as soon as you can. The Cyber Security Agency of Singapore advises people who clicked a phishing link on a work device to contact their IT department and run a full anti-virus scan. Early reporting gives your workplace a chance to check the device and accounts calmly.

First check what happened

Close the page and do not enter any more information. Think through what you did on the site. Did you only open it, type in a password, provide payment or banking details, download a file, or install an application? This helps your manager or IT support decide what follow-up is needed.

If the page asked you to sign in, do not return through the message link to check it. Open the company or service website using a trusted bookmark or by typing its address yourself. If you are unsure whether the request was genuine, contact the organisation through details from its official website.

If you opened the link on a work device

Let your manager or IT support know which device you used, roughly when you clicked, and whether you downloaded or opened anything. Include the message or sender details if possible. Do not forward the link to colleagues as a warning, since they might open it by mistake. Your IT support can advise whether to scan the device or take any other step.

If the link downloaded a file or asked you to install an app, do not open or install it. If you already did, stop using the device for work and contact IT support straight away. Follow their instructions about disconnecting the device or running a scan. This keeps the response matched to what actually occurred.

If you entered a password

Change the password for the affected account as soon as possible. Go to the service through its official website or app, not through the suspicious message. If you used the same password elsewhere, change it on those accounts too. Use a different password for each account.

For a work account, tell IT support before or while changing the password, especially if the account controls email, accounting, payroll or customer records. They may need to check recent sign-ins and help secure related access. If you approved a sign-in prompt you did not initiate, mention that as well.

If you shared banking or payment details

Contact your bank promptly using the official number in its app, card or website if you entered banking information, card details or a one-time code. Explain what information you shared and follow the bank’s advice. If a business payment was made or supplier bank details were changed, notify the finance lead and bank promptly so they can review the transaction.

If money has been lost, make a police report. In Singapore, CSA advises contacting the bank when banking details have been provided and lodging a police report if money was lost. Use official channels rather than phone numbers or links in the suspicious message.

Keep the message and report it

Keep the original email or message, including the sender and time received, so your IT team can review it. Avoid clicking the link again or replying to the sender. If your organisation has a reporting button or procedure, use it. You can also report phishing attempts to SingCERT through the reporting options on the CSA website.

A clear internal process makes this easier for everyone. Staff should know whom to contact, and managers should respond without blame. Quick reporting helps the business understand what happened and decide whether any follow-up is needed.

A calm response starts with speaking up

If a suspicious link was opened, share what happened and when. The next step depends on whether information was entered, a file was opened or payment details were shared. Reporting promptly lets the right person help, and it gives the business a clearer picture of what to do next.

Need help reviewing how your business responds to cybersecurity issues? Contact 361 Degree Consultancy at 6515 7906 or enquiry@361dc.com for a practical discussion.

FAQs

Close the page and report it to your IT support if it was a work device. If you did not download or open a file, install an app or provide information, tell them that too. They can advise whether a scan or another check is needed.

Follow your IT team's instructions. Let them know what happened and whether you downloaded or opened a file. They can decide whether the device should be disconnected or scanned.

Tell IT support promptly and change the password through the official sign-in page. If you reused that password for other accounts, change those as well.

Call your bank promptly using its official contact details. Explain what you shared and follow its advice. If money was lost, make a police report.

Yes. Use your workplace reporting process if available. In Singapore, you can also report phishing to SingCERT through the Cyber Security Agency of Singapore.

Related Posts