MYTHOSAI

Security basics / PRACTICAL GUIDE

Clicked a phishing link? Choose the right response

Distinguish viewing a page from disclosing credentials, approving access or running a file.

Before you start

Your browser and access to the real account provider; use a clean device if malware is suspected.

First record what happened

Write down the time, message source and your actual actions. Did you only view a page, type a password, provide a one-time code, approve an app permission, download a file or run it? This distinction decides the next step. Closing a tab cannot undo information already submitted.

If you only opened the page

Close it without interacting further. Check your Downloads folder and browser download history. Do not open an unfamiliar file to identify it. Review browser site permissions for unexpected notification access and remove it. Update the browser and operating system. On a work device, report the event even if you did not type anything.

Opening a page can still carry risk, particularly on outdated software, but it is not automatic proof that all accounts were stolen.

If you entered a password or code

  1. Use the genuine app or a known bookmark from a trustworthy device.
  2. Change that account's password and replace it anywhere else you reused it.
  3. Review active sessions and use the provider's sign-out or session-revocation controls. A password change may not immediately invalidate every session.
  4. Inspect recovery details, MFA methods, forwarding rules and third-party access. Remove unauthorised changes and verify your own recovery route remains usable.

If you approved a consent screen, revoke the unfamiliar application's access too. Some permissions persist independently of the password. Do not respond to a follow-up caller claiming they can reverse the incident if you provide another code.

If you ran a downloaded file

Disconnect the affected computer from the network and contact IT or trusted technical support. Do account recovery from a separate device. Preserve the message and filename for investigation, but avoid sharing the file through ordinary email. Run an appropriate security check; a clean scan alone is not a guarantee that a device is trustworthy.

If you supplied bank or identity details

Contact the bank promptly through its official app or number. Explain whether you disclosed a card, transferred money or approved access. For identity misuse, consult the official Australian recovery guidance. Reporting should not delay urgent steps to stop losses.

Verify recovery

Check recent activity and settings after your changes. Keep a short timeline without passwords or recovery codes. Watch for later attempts using the information you disclosed. Recovery is complete only when access, settings and the original exposure have been addressed.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.