You clicked a scam link. Now what?
First, the good news
Opening a link is not the same as handing over your money. On a modern, up to date iPhone, simply loading a scam page usually does nothing by itself. There is no virus waiting the moment the page appears. The danger is never the tap, it is what the page then talks you into doing: typing your details, reading back a code, or downloading something. So the real question is not "did I click," it is "what happened after I clicked." Let that drop your heart rate a notch before you do one more thing.
The only question that matters: what did you type?
Everything from here depends on your honest answer to that. Find your situation and jump to it.
- You opened it and closed it. No forms, no typing, no download. Low risk. Close the tab, delete the message and stay alert for follow ups over the next few days.
- You entered card details. The one to move on fastest. Go to the card steps below now.
- You typed a password. Change it now, and everywhere you reused it.
- You read out or entered a code. That code is a live key to your account. This is urgent, see below.
- You installed an app or "security tool" it told you to. Delete it and work through the device steps.
If you entered card details
- Call your bank now, using the number on the back of your card or inside your official banking app, never a number from the scam message.
- Ask them to freeze the card and watch for charges. They can send a new one in days.
- Brace for the callback. Crews who have your card number often call within the hour posing as your bank's "fraud team" to squeeze out a code or a bigger payment. Hang up and call the bank yourself. Real banks are completely fine with that.
- Never move money to a "safe account." No bank on earth asks you to do this. Anyone who does is the scammer.
If you typed a password
- Change it now, from the official app or by typing the site's address yourself, not through any link.
- Change it everywhere you reused it. This is the exact moment reused passwords come back to bite, so fix them all.
- Turn on two step verification where you can, so a stolen password by itself is not enough to get in.
If you read back a code
A one time code your bank texts you is not a formality, it is the last key in the lock. Handing it to a caller is often how they log in or enroll your Zelle to themselves in real time. Call your bank right away on the number on your card, tell them a code was shared, and have them lock the account and reset your login. This is the same trap at the center of the Zelle fraud alert and fake bank text.
If you installed something or the phone feels off
- Delete any app or profile the page told you to install.
- Restart the phone.
- Open Settings and look under General and VPN & Device Management for any profile you did not add, and remove it. Check for any app with permissions it should not have.
- If it still feels wrong, take it to an Apple Store or your carrier. Do not call a "support" number the scam gave you.
The second wave: the recovery scam
Getting hit once quietly marks you as a target for the next round. In the days after, expect a friendly stranger to reach out offering to "recover" what you lost, sometimes claiming to be from the FTC, your bank or a law firm, usually for an upfront fee or one more code. This is the recovery scam, and it feeds on people who were already burned once. No real agency charges a fee to get your money back. Treat any fast, unexpected contact about the incident as part of the same attack. The rule never changes: hang up, and reach your bank, the FTC or the police yourself through a number or address you looked up, never one handed to you.
Report it and lock down your identity
- Forward the scam text to 7726 (it spells SPAM), then report the details at ReportFraud.ftc.gov.
- If you gave up enough to worry about identity theft, go to IdentityTheft.gov for a step by step recovery plan built for exactly this.
- Consider a free credit freeze at all three bureaus so no one can open accounts in your name. It is reversible whenever you need to borrow.
- For an after the fact report you can also call your local police non-emergency line, or file at IC3.gov if money was lost. Call 911 only if someone is in immediate danger.
- Keep the message as evidence until you have reported it. Do not delete it in a panic.
Which scam was it?
Naming it tells you what they are likely after next. If it posed as your bank or a Zelle fraud alert, see the Zelle fraud alert and fake bank text. If it was a delivery fee, see the USPS package fee text. If a "family member" is the one asking for money, read the Hi Mom family scam before you send a dime.
You are not the problem
These pages are engineered to catch sharp people on a distracted day, and the fact that you went looking for what to do means you very likely caught it in time. Whether the page wore a Chase coat here or a Barclays one in Britain, the aftermath steps are the same, because it is one industry behind all of it. The people most at risk are the ones who never search, often our own parents and grandparents. To see the machine, read how SMS scam gangs actually operate.
That is where the Escudo app helps. It filters known scam patterns on the iPhone and sets them aside before they are read, so there is less to click in the first place. It does not promise to stop every scam or judge any single message, and it cannot tell you whether one specific message is a real threat. Nothing is deleted, it is only moved to a junk folder, and your messages never leave your phone.
Fewer scam texts reaching the people you love
The Escudo app is coming soon to iPhone in the US. Download it free on your iPhone.
Download on the App Store