# Clicked a Phishing Link? What to Do in the First Hour

> Clicked a phishing link in Malaysia? What to do depends on what you typed or installed: a password, login code, APK or bank details, and when to call 997.

- URL: https://www.awarexone.com/research/clicked-phishing-link-what-to-do
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-29
- Topics: Account security, Scams, Malaysia
- Related service: Account security: https://www.awarexone.com/services/account-security

## Short answer

It depends on what you did on the page. If you typed a password, change it from the real app, sign out other sessions and check recovery details. If you shared a login code, treat the account as hacked. If you entered bank details or installed an app, call your bank's hotline or the National Scam Response Centre first.

## Summary

- What you do next depends on what you did on the fake page: only opened it, typed a password, typed a login code, installed an app, or entered bank details.
- If you typed a password, change it at once from the real app or a website you type in yourself, then sign out every other session and check your recovery email and phone.
- If you entered card or banking details, or installed an app from the link, call your bank's hotline or the National Scam Response Centre on 997 before anything else.
- Report the link through Gmail's Report phishing option, Meta's phishing address or Cyber999, and keep screenshots of the message and the page address.
- Do not type your password into online hack checker sites, and do not pay anyone who offers to reverse the damage, because banks, agencies and platforms never ask for your codes.
- Acting quickly limits the damage, but a hijacked account is only restored if the platform agrees, and money already moved may not come back.

You tapped a link in an SMS about a parcel, a WhatsApp message from a friend, or an email that looked like it came from Facebook. The page asked you to log in, or to download something, and only afterwards did something feel wrong. Now you are wondering what the person behind it can do.

The short answer: it depends on what you did on that page. Opening a link is one thing. Typing a password, a login code or bank details is another, and installing an app from the link is the most serious. Find your case, then follow its steps in order.

This guide covers a triage table, steps for Google, Facebook and your bank, reporting the link in Malaysia, and the mistakes that make things worse.

Last checked: 29 September 2026.

## What Should You Do Right After Clicking a Phishing Link?

Close the page and type nothing else into it. If you entered a password, change it from the real app or a website you type in yourself, including on any other site that used it, then sign out of all other sessions and check the recovery email and phone. If you shared a login code, treat the account as taken and start the platform's hacked account process. If you entered card or banking details, or installed an app from the link, call your bank's hotline or the National Scam Response Centre (NSRC) on 997 first, then make a police report.

## Triage: What Did You Actually Do on the Page?

Phishing means a fake message or site that copies one you trust, built to steal your login or install harmful software. Google's page on [avoiding and reporting phishing](https://support.google.com/mail/answer/8253) describes it that way, and Meta's page on [phishing on Facebook](https://www.facebook.com/help/166863010078512) warns that one fraudulent link can lead to several accounts being taken over, such as your email, Facebook and WhatsApp. Find your row below.

*Phishing outcomes and first steps, based on Google, Meta, Bank Negara Malaysia and NSRC guidance at the time of writing.*

| What you did | What the scammer may now have | Your first step |
| --- | --- | --- |
| Opened the link, typed nothing, downloaded nothing | Usually very little beyond knowing your number or email is active | Close the page, report the message, and watch for follow-up messages |
| Typed your username and password | Your password, which they can try on the real site and on other sites | Change the password from the real app, sign out other sessions, turn on two-factor authentication |
| Typed a login code, OTP or 2FA code | A live login to your account, possibly already in use | Treat the account as hacked: reset the password, remove unknown devices, use the platform's hacked account route |
| Installed an app or APK file from the link | Access to your phone, including SMS messages and bank alerts | Call your bank or 997, uninstall the app, then change passwords from a different device |
| Entered card, online banking or e-wallet details | What they need to move your money | Call your bank's hotline or 997 immediately, then make a police report |

If you did more than one thing, start with the most serious row. Money and installed apps come first, because an app that reads your SMS can also read the codes you are about to request.

## If You Only Opened the Link

Opening a page without typing or installing anything gives the scammer far less to work with. Close the tab, and delete any file that downloaded without opening it. Google's phishing page warns that scammers use links to deliver unwanted software, so do not tap "Allow", "Install" or "Open" on anything the page offered.

Report the message (see the reporting section below) and expect follow-ups. A scammer who knows your number is active may try again with a different story, often in Bahasa Malaysia or Chinese. Illustrative examples of the wording: "Bungkusan anda tidak dapat dihantar, sila kemas kini alamat anda di pautan ini" or "您的账号存在异常，请点击链接验证".

## If You Typed Your Password on a Fake Login Page

Change the password before the scammer uses it. Meta's page on [what to do if you've been phished](https://www.facebook.com/help/434918221794966) says plainly that anyone who got the username or password from a malicious link might be able to log into your account, and that resetting it helps prevent unwanted logins. Use the real app, or type the website address yourself. Never use a link from an email that arrived in the last hour, even one that looks like a genuine security alert.

1. Change the password on the account you typed it into. Make the new one long and unique.
2. Change it on every other site that used the same password. Google's [hacked account page](https://support.google.com/accounts/answer/6294825) lists apps and sites that share the password, that contact you through that email, or that you sign in to with that email.
3. Sign out of every other session. On Google, open your Google Account, tap "Security & sign-in", then under "Your devices" choose "Manage all devices" and sign out of anything you do not recognise, as Google's [device page](https://support.google.com/accounts/answer/3067630?hl=en) explains. On Facebook, go to Accounts Center, "Password and security", "Where you're logged in", then "Select devices to log out", following Meta's [log out page](https://www.facebook.com/help/211990645501187).
4. Check the recovery email and phone number. If either has changed, correct it at once.
5. Turn on two-factor authentication, preferably with an authentication app, a passkey or a security key rather than SMS.

The method matters. Google's [2-Step Verification page](https://support.google.com/accounts/answer/185839?hl=en) says passkeys and hardware security keys protect against phishing, while codes sent by text or call can be vulnerable to phone number based hacks. Meta's [two-factor page](https://www.facebook.com/help/148233965247823) offers a security key, an authentication app or SMS, plus 10 recovery codes for when your phone is unavailable.

> Note: **Your email account comes first.** If the fake page was an email login, secure that mailbox first. Whoever controls your inbox can reset your other logins. On Gmail, Google says to remove any filters, forwarding rules or mail delegation you did not set up.

## If You Typed a Login Code or OTP

A login code is the last lock. If you typed it into a fake page, assume the scammer used it within seconds and is inside the account now. Changing the password alone may not remove them, so sign out of every other session as well.

- Google: open your Google Account, review "Recent security events" and choose "No, it wasn't me" for anything you did not do, then follow the steps on screen. If you cannot sign in, use Google's account recovery page.
- Facebook: Meta says to report the account as compromised whether or not you can still log in. Its [hacked account page](https://www.facebook.com/help/1216349518398524) points to facebook.com/hacked, used on a device you have logged in from before. Then check recent emails from Facebook and your activity log, and delete posts you did not make.
- WhatsApp: a six digit registration code typed into a stranger's page, or forwarded to a "friend", is a common way WhatsApp accounts are taken. Our guide to [a WhatsApp hacked through a verification code](https://www.awarexone.com/research/whatsapp-hacked-verification-code-malaysia) covers getting the account back.

## If You Installed an App or APK From the Link

This is the case to act on fastest. Bank Negara Malaysia's page on [mobile application scams](https://www.bnm.gov.my/smsscam) says scammers gain access to your phone once you download suspicious apps such as .apk files, and use that access to read and delete your transaction alerts and OTP numbers. In other words, your phone may be showing you nothing while money leaves your account.

1. Call your bank's hotline now, or 997, and say an app from a scam link was installed. The hotline number is on the back of your card or on the bank's own website.
2. Uninstall the app. On Android, Google's [Play Protect page](https://support.google.com/googleplay/answer/2812853?hl=en) says Play Protect checks the phone for harmful apps from other sources and may disable or remove them. Open the Play Store, tap your profile icon, then "Play Protect", and run a scan.
3. Change your banking, email and social media passwords from a different device, such as a laptop or a family member's phone, not the infected one.
4. If the phone still behaves oddly, back up your photos and files and consider a factory reset. Google's hacked account page suggests trusted anti-virus software and, where needed, resetting to factory settings.

Bank Negara also says banks will no longer send clickable links by SMS. Any "bank" SMS with a link to tap is a warning sign on its own.

## If You Entered Card or Banking Details

Call first, tidy up later. The NSRC's [FAQ on the NFCC website](https://nfcc.jpm.gov.my/index.php/en/about-nsrc) says its focus is online financial fraud, including phishing and malware, and tells victims to contact their bank's 24 hour hotline or the NSRC on 997 as soon as they discover the fraud. It adds that quick action can reduce losses, but there is no guarantee you will get your money back.

After the call, make a police report at the nearest station within 24 hours; the NSRC says the police cannot follow up without one. If you cannot get through to 997, it says to call your bank's hotline directly.

## Evidence to Keep Before You Report

The NSRC lists these details for scam reports, and they help with the platform and police too. Collect them before you block or delete anything.

- A screenshot of the message that carried the link, showing the sender's number, email address or profile.
- The full website address (URL) of the fake page. Copy it as text; do not open it again to check.
- A short timeline: when you clicked, what you typed or installed, and when you noticed.
- Transaction details if money moved: account numbers, amounts, times and any receipts.
- Any conversation with the scammer on SMS, WhatsApp, Telegram, email or social media.
- Security alerts you received afterwards from Google, Meta or your bank.

## How to Report the Phishing Link in Malaysia

Reporting does not undo anything, but it helps get the page blocked for the next person. Pick the channels that match where the link reached you.

- Gmail: on a computer, open the message, click "More" next to "Reply", then "Report phishing", as Google's phishing page describes.
- Facebook, Instagram or Messenger: Meta asks for suspected phishing emails to be sent to phish@fb.com and to your email provider, and for suspicious Messenger messages to be reported in the app.
- Any fake website: Google's [Safe Browsing report form](https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en) lets you report a page that should carry a warning but does not.
- Malaysia: CyberSecurity Malaysia's [Cyber999 incident response centre](https://www.cybersecurity.my/portal-main/services/cyber999-overview) takes reports of computer security incidents by online form, email, phone and its app, and lists phishing among its emergency categories.
- Money lost: your bank or 997 first, then the police, as above.

Our overview of [where to report a hacked account in Malaysia](https://www.awarexone.com/research/report-hacked-account-malaysia) goes further into which agency handles what.

## How to Tell a Real Security Email From the Fake One

After a click, real alerts and new fakes arrive side by side. Meta says its emails come only from fb.com, facebook.com, facebookmail.com, instagram.com, meta.com, metamail.com or their subdomains, but warns that phishing partner requests have been sent through the genuine facebookmail.com domain, so a real sender is not proof on its own. Google says its emails will not ask a signed in user for that account's password; to check a Google alert, go directly to myaccount.google.com/notifications.

## Mistakes That Make a Phishing Click Worse

- Typing your password into an online hack checker or account scanner site. That is the same mistake a second time.
- Changing the password by tapping a link in another email instead of opening the app yourself.
- Changing only one password when the same one protects your email, bank or other social accounts.
- Requesting fresh codes on a phone that has an unknown app installed. The app may be reading them.
- Deleting the message before taking a screenshot and copying the link address.
- Paying anyone who offers to reverse the damage or trace the scammer.

> Warning: **The second scam arrives quickly.** People who post about a phishing click often get messages from "recovery experts" and "ethical hackers" within hours, in English, Bahasa Malaysia or Chinese. Meta says its representatives never request money or ask for passwords or payment details over chat or email. The NSRC says NSRC, PDRM, MCMC, BNM and banks will never ask for your username, password, PIN, TAC or OTP. Never share a password, login code or backup code with anyone, and read our guide to [fake Meta support accounts](https://www.awarexone.com/research/fake-meta-support-scam-malaysia) before replying to any of them.

## When a Case Review Makes Sense

Everything above can be done alone, and for most people it is enough. Only the platform can restore a taken account, it alone decides, and some accounts do not come back. A second pair of eyes helps when a click has led to a takeover you cannot undo, when a business Page or ad account is involved, or when you are unsure which accounts the scammer reached. SocialSafe by AwareXone, our recovery service, reviews the case first and tells you honestly whether the official routes still have a chance. You can read how we approach [account security](https://www.awarexone.com/services/account-security), and our [Trust Center](https://www.awarexone.com/trust) explains what we never ask for, starting with your passwords and codes. If you are reacting to a login alert rather than a click, see [what to do when someone logged into your account](https://www.awarexone.com/research/someone-logged-into-my-account).

## Frequently Asked Questions

### Can you get hacked just by clicking a link?

Opening a page without typing or installing anything gives a scammer much less than a password or an app would. The real danger comes from what you enter or install afterwards, so close the page and do not accept any download it offers.

### I clicked a scam link on WhatsApp. Is my WhatsApp hacked?

Not from the click alone. The usual danger is typing your six digit WhatsApp registration code into the page or passing it to the sender, which lets someone else register your number on their phone.

### Should I factory reset my phone after clicking a phishing link?

Only if you installed something from the link and the phone still behaves oddly after you uninstall it and run a scan. Back up your photos and files first, and change your passwords from a different device.

### Will my bank refund money lost to a phishing link?

It depends on your bank and the case. The NSRC says fast reporting can reduce losses but there is no guarantee you will get your money back, so call your bank or 997 as soon as you notice.

## Official sources

- [Gmail Help: Avoid and report phishing emails (read 29 September 2026)](https://support.google.com/mail/answer/8253)
- [Google Account Help: Secure a hacked or compromised Google Account (read 29 September 2026)](https://support.google.com/accounts/answer/6294825)
- [Google Account Help: See devices with account access (read 29 September 2026)](https://support.google.com/accounts/answer/3067630?hl=en)
- [Google Account Help: Turn on 2-Step Verification (read 29 September 2026)](https://support.google.com/accounts/answer/185839?hl=en)
- [Google Play Help: Use Google Play Protect to help keep your apps safe (read 29 September 2026)](https://support.google.com/googleplay/answer/2812853?hl=en)
- [Google Safe Browsing: Report a page (read 29 September 2026)](https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en)
- [Facebook Help Center: Protect yourself from phishing on Facebook (read 29 September 2026)](https://www.facebook.com/help/166863010078512)
- [Facebook Help Center: What to do if you've been phished on Facebook (read 29 September 2026)](https://www.facebook.com/help/434918221794966)
- [Facebook Help Center: Recover a hacked account (read 29 September 2026)](https://www.facebook.com/help/1216349518398524)
- [Facebook Help Center: Log out of Facebook on another device (read 29 September 2026)](https://www.facebook.com/help/211990645501187)
- [Facebook Help Center: How two-factor authentication works on Facebook (read 29 September 2026)](https://www.facebook.com/help/148233965247823)
- [Bank Negara Malaysia: Mobile Application Scam (read 29 September 2026)](https://www.bnm.gov.my/smsscam)
- [NFCC: National Scam Response Centre FAQ (read 29 September 2026)](https://nfcc.jpm.gov.my/index.php/en/about-nsrc)
- [CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 29 September 2026)](https://www.cybersecurity.my/portal-main/services/cyber999-overview)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
