I clicked a link I should not have

The useful question after a suspect click is not "am I infected" but "what did I actually do". Opening a page, entering details into it and running a file it offered are three different events with three different answers. These six questions separate them.

I clicked a link in a text message. What should I do now?

Short answer

Close the page without typing anything into it. If you entered nothing and downloaded nothing, the most likely outcome is that the sender now knows the number is live. Change the password of any account the page imitated, as a precaution, and report the message.

What usually sits behind it

Messages of this kind are sent in bulk to numbers that may or may not exist. The link leads to a page built to look like a delivery company, a bank, a toll road operator or a government service, and its entire purpose is to collect what you type. Simply loading the page does not hand over anything you have not typed.

There is a second, smaller category in which the link offers a file to download. On a desktop computer, that file still has to be opened before it can do anything, and modern browsers and operating systems put several warnings in the way first.

What to try first, at no cost

  1. Close the tab. Do not use any phone number, chat window or "contact support" option that appeared on the page.
  2. If the page imitated a service you use, open that service yourself, by typing its address or using your own saved bookmark, and check your account from there.
  3. Change the password for that service if you have any doubt, and sign out of other sessions while you are in the settings.
  4. Check the downloads folder. If a file arrived, delete it without opening it.
  5. Run a full scan with the protection already on the machine for reassurance.
  6. Delete the message, and report it before you do if you can.

When to ask for official help

Report the message to Scamwatch at scamwatch.gov.au, which is run by the National Anti-Scam Centre and collects reports from people in Australia. If you believe a crime has occurred, ReportCyber through cyber.gov.au is the national reporting route.

Where a paid product may or may not help

Security software on a desktop computer can block some known malicious pages before they load and can catch a downloaded file. It cannot retrieve a password that has already been typed into a convincing imitation. The protective value is real but partial, which is why the password change comes first and the scan second.

I typed my details into the page before I realised. What then?

Short answer

Treat the details as known to someone else and act in this order: bank first if card or account numbers were involved, then the password of the imitated service, then every other account that shared that password.

What usually sits behind it

Credentials entered into a fake page are usually tested within minutes, by automated systems rather than by a person reading them. That is why speed matters more than certainty. Waiting until you are sure is almost always worse than acting on a suspicion that turns out to be unfounded.

Password reuse is what turns one compromised page into several compromised accounts. If the password you typed is used anywhere else, those accounts are now exposed too, regardless of how careful you were with them.

What to try first, at no cost

  1. If bank, card or identity details were entered, telephone your bank using the number printed on your card or in its official app, and describe the message you received.
  2. Change the password of the imitated service, then sign out of all other sessions in its security settings.
  3. Switch on two-factor authentication for that account if it was not already on.
  4. Change the password anywhere else the same one was used, starting with the email account.
  5. Watch the account for unfamiliar activity over the following weeks, including small test transactions.

What to watch out for

A second contact often follows the first, from someone offering to recover the money or to help with the problem. Treat any unexpected approach that arrives after an incident as part of it. Legitimate organisations do not ask for remote access to your computer or for your password in order to help you.

When to ask for official help

If identity documents were involved rather than only a password, IDCARE is the national identity and cyber support service referred to by Australian agencies, and both Scamwatch at scamwatch.gov.au and the Australian Cyber Security Centre at cyber.gov.au publish current guidance on the steps that follow.

Where a paid product may or may not help

No antivirus product reverses a disclosure. What it can do afterwards is confirm that nothing was also installed on the machine during the visit, which is a real but limited reassurance.

How do I tell a fake delivery or bank message from a real one?

Short answer

By refusing to decide from inside the message. Open the service yourself, through your own bookmark or app, and see whether the same thing is waiting for you there. If it is not, the message was not real.

What usually sits behind it

Fakes have become good enough that spelling and layout are no longer reliable tests. Logos are copied exactly, sender names are spoofed, and the web address can be made to look close enough to pass a glance on a small screen. The one thing an imitation cannot do is place a matching message inside your real account.

There are still useful signals, as long as they are treated as suspicion rather than proof.

Signals worth noticing in an unexpected message
SignalWhy it matters
A small fee to release a parcelA card payment is the point of the message; the amount is small to reduce hesitation
A deadline measured in hoursPressure is used to prevent the check described above
A link whose domain is not the organisation's ownLook at the part immediately before the first single slash, not at the whole string
A request to confirm details the organisation already holdsYour bank does not need you to retype your card number to it
An unexpected message about a service you do not useBulk sending; the sender does not know who you are

What to try first, at no cost

  • Open the organisation's app or your own saved bookmark and look for the same notice there.
  • Use a telephone number from the back of your card or from the organisation's own site, never one supplied in the message.
  • Check a tracking number on the courier's own site rather than through the link.
  • If a colleague or family member sent it, ask them through a different channel whether they meant to.

When to ask for official help

Scamwatch publishes current examples of the messages circulating in Australia at scamwatch.gov.au, which is a quick way to recognise a type you have just received.

Where a paid product may or may not help

Protection that includes web filtering can block pages already known to be malicious, which helps when the same campaign has been reported by others first. It cannot judge a message that is new, and it cannot see a text message arriving on your phone when the product is installed on a desktop computer.

I opened an attachment. How worried should I be?

Short answer

It depends on what the attachment was and whether you then allowed it to do something. A document that opened in reading mode without you enabling anything is a far smaller event than a program you agreed to run.

What usually sits behind it

Office documents from the internet open in a protected mode, and the dangerous content generally requires you to click a button that enables editing or content. Archive files do nothing until something inside them is opened. Installers ask for permission before they change the system, and that permission prompt is the moment that matters.

Which is to say the question to ask yourself is not "did I open it" but "did I agree to anything after opening it".

What to try first, at no cost

  1. Disconnect from the internet if you believe something was installed, so that any further download is interrupted.
  2. Run a full scan with the protection already present on the machine.
  3. Look through the list of installed programs for anything added on that date.
  4. Check the browser extension list for the same reason.
  5. Change the passwords of accounts you use on that computer, from a different device, starting with email.
  6. Reconnect and install any pending operating system updates.

When to ask for official help

If the computer belongs to an employer, tell their support team before doing any of the above, because they may need the machine left as it is. If files have become inaccessible or renamed, stop and report through ReportCyber at cyber.gov.au.

Where a paid product may or may not help

This is the situation security software is designed for: a file that reached the machine and may have run. A full scan with a current product is a reasonable response, and running one is more useful than worrying.

Visit the Norton AntiVirus Plus websitePaid affiliate link. Mildfactor receives a commission on purchases made after following it, at no additional cost to you.

Who do I report it to in Australia?

Short answer

Scamwatch for scam messages, ReportCyber for cybercrime, the eSafety Commissioner for abuse and harmful content, and your bank first whenever money is involved.

What each body covers

The division is less confusing than it looks. Scamwatch, operated through the National Anti-Scam Centre, gathers reports about scams and publishes warnings based on them, at scamwatch.gov.au. ReportCyber, reached through the Australian Cyber Security Centre at cyber.gov.au, is the route for reporting cybercrime so that it reaches the relevant police agency. The eSafety Commissioner at esafety.gov.au deals with online abuse, image-based abuse and seriously harmful content. The Office of the Australian Information Commissioner at oaic.gov.au is where privacy complaints and data breach matters go.

What to do first, at no cost

  • Contact your bank immediately if any payment was made or any card detail was entered.
  • Keep the message, the sender's address or number, and a screenshot, before deleting anything.
  • Note the date and time, which reports usually ask for.
  • Make the report even if nothing was lost. Reports with no loss still shape the warnings others receive.

Where a paid product may or may not help

Reporting is free and independent of any product. No purchase changes the reporting process, and no legitimate service charges to make a report on your behalf.

Someone rang claiming to be from a software company. Was that real?

Short answer

Almost certainly not. Major software companies do not telephone private individuals to say their computer has a problem, because they have no way of knowing and no reason to call.

What usually sits behind it

The approach follows a pattern. The caller establishes authority by naming a well-known company, then asks you to install a remote access tool so they can "show" you the problem, then points at ordinary system logs as evidence of it. The payment request comes last, often for a support subscription, and sometimes the remote session is used to reach banking accounts directly.

The same approach also arrives as a web page with a telephone number on it, which is covered on the page about alarming pages.

What to do, at no cost

  1. End the call. There is no obligation to be polite to an unsolicited caller.
  2. If remote access was granted, disconnect the computer from the internet and uninstall the remote access program.
  3. Change the passwords of accounts used on that computer, from a different device.
  4. Telephone your bank if any financial site was open or any payment was discussed.
  5. Run a full scan once the remote tool has been removed.
  6. Report the call to Scamwatch at scamwatch.gov.au.

When to ask for official help

If a payment was made or remote access was granted for any length of time, report through ReportCyber at cyber.gov.au as well as telling your bank. For an older relative who has been targeted repeatedly, Scamwatch publishes material written for exactly that conversation.

Where a paid product may or may not help

Software cannot refuse a telephone call, and it cannot prevent a person from granting access deliberately. A scanner will find and remove the remote access tool afterwards, which is useful but after the fact. The protection that matters here is knowing the pattern.