Last materially reviewed: September 3, 2026
Direct Answer
If you clicked a phishing link, act immediately but do not panic. Close the page, do not enter more information, disconnect from suspicious downloads or apps, and secure any account whose password, OTP, card details, or recovery code may have been exposed. If you entered banking or e-wallet credentials, contact the provider immediately and ask it to secure the account or stop suspicious transactions.
Primary guidance: Cybercrime Investigation and Coordinating Center and NBI Cybercrime Division guidance.
Key Takeaways
- Clicking a phishing link does not always mean your account is compromised, but entering credentials or installing software significantly increases the risk.
- Change exposed passwords from a trusted device and enable multi-factor authentication.
- Never approve unexpected OTP, login, password-reset, or device-registration prompts.
- Contact your bank or e-wallet immediately if financial information may be exposed.
- Preserve the message, URL, sender number, account, and transaction records before deleting anything.
- Report serious scams through CICC 1326, PNP-ACG, or NBI-CCD.
Jump to a Section
- What to do immediately
- If you entered a password or OTP
- If you downloaded an app or file
- If money was taken
- Where to report
What to Do Immediately After Clicking a Phishing Link
- Close the page. Do not continue navigating, downloading, or entering information.
- Do not respond to the sender. Scammers often use replies to confirm that a number or email address is active.
- Check what you actually did. Did you only open the page, or did you enter a password, OTP, card number, ID number, or recovery code?
- Preserve the evidence. Screenshot the message, sender, link, date and time. Copy the URL without reopening it if possible.
- Update your device. Install current operating-system and browser security updates.
If You Entered a Password, OTP or Recovery Code
Treat the account as potentially compromised. From a trusted device, change the password immediately. If the same password was reused elsewhere, change those accounts too. Sign out of unknown sessions, remove unfamiliar devices, review recovery email and phone settings, and enable multi-factor authentication.
If you disclosed an OTP or approved an unexpected login, contact the affected service immediately. An OTP can be enough to authorize a login, device enrollment, password reset, or transaction.
Decision Snapshot
| What happened? | Recommended response |
|---|---|
| Only opened the page | Close it, update the device, monitor accounts, preserve evidence |
| Entered password | Change password immediately; sign out other sessions; enable MFA |
| Entered OTP or recovery code | Contact the service urgently and secure the account |
| Entered card/bank details | Call bank/e-wallet, freeze or replace credentials as needed |
| Installed an app/file | Disconnect if needed, remove suspicious software, scan device, consider professional help |
| Money was transferred | Contact provider immediately and file a cybercrime report |
If You Downloaded an App, APK or File
Risk is higher when the phishing page convinced you to install an app, browser extension, configuration profile, APK, remote-access tool, or document containing malicious code. Stop using the device for sensitive logins until you have removed the suspicious software and checked the device. Review app permissions, device-administrator access, accessibility permissions, installed profiles, and unknown browser extensions.
If the device behaves unusually, security settings changed, or banking apps show unauthorized activity, use a separate trusted device to secure your accounts.
What If Money Was Already Taken?
- Contact the bank or e-wallet immediately using the official app, website, or phone number.
- Ask for the transaction to be flagged, disputed, held, or traced where possible.
- Secure the account and change credentials.
- Save transaction references, recipient account numbers, wallet names, phone numbers, and timestamps.
- File a cybercrime report. See Where and How to Report Cybercrime in the Philippines.
Where to Report a Phishing Scam
The CICC’s public anti-scam campaign directs victims to hotline 1326 and report@cicc.gov.ph. Serious phishing, account takeover, and online fraud can also be reported to the PNP Anti-Cybercrime Group or NBI Cybercrime Division.
How to Avoid the Next Phishing Attempt
- Open banking and government services from bookmarks or official apps instead of message links.
- Do not share OTPs, PINs, CVVs, passwords, or recovery codes.
- Use unique passwords and a password manager.
- Enable multi-factor authentication wherever available.
- Be suspicious of urgent messages about account suspension, prizes, unpaid parcels, tax refunds, jobs, loans, or government benefits.
- Verify requests using contact details you find independently.
Frequently Asked Questions
Can my phone be hacked just by clicking a link?
It is possible in sophisticated attacks, but most consumer phishing campaigns still depend on getting the victim to enter credentials, approve a prompt, or install something. Treat the click seriously, but focus on what information or permissions were actually given.
Should I factory-reset my phone?
Not every phishing click requires a factory reset. Consider it when malicious software was installed, security controls were altered, compromise persists after cleanup, or a qualified technician recommends it.
Should I change every password?
Change passwords for accounts that used the exposed password and any other account where the same password was reused. Reusing passwords is one of the biggest reasons a single phishing incident spreads.
