I clicked a link or opened a file I should not have

Six questions for the hours after a click you regret. The order of the steps matters more than the speed, and most of what helps costs nothing.

The short version for this whole page

Opening a page is rarely the damaging part; entering something into it usually is. Deal with credentials first, money second, the device third. Nothing on this page assumes anything about the state of your computer, because that cannot be determined from a distance.

What should I do in the first hour?

Work in this order: passwords, money, device, report. Doing them out of order wastes the time that matters.

Why that order. If credentials were captured, they are useful to whoever has them immediately, and changing a password removes that usefulness. Money can often be stopped or recalled if a bank hears about it quickly. The device itself can wait an hour; whatever might be on it will still be there. Reporting is valuable but is not urgent in the same way.

What to do, at no cost.

  1. Change the password for the account the message imitated. If you can, do it from a different device, and type the organisation's address into the browser yourself rather than following any link from the message.
  2. Change the password anywhere else you used the same one. Reuse is what turns one compromised password into several compromised accounts.
  3. Turn on multi-factor authentication on that account and on your email account. Email is the recovery route for everything else, so it is the one worth protecting first.
  4. If card or banking details were entered, telephone your bank on the number printed on your card or on its official website. Ask them to note the account and tell you what they can stop.
  5. Restart the computer and install any pending updates, then run a scan with the security software you already have.
  6. Report it, using the links in the final section of this page.

When to ask for official help. If the device is a work machine, tell your employer's IT contact before step five; organisations often want to examine a machine before it is changed. The Australian Cyber Security Centre publishes step-by-step guidance for individuals after an incident at cyber.gov.au, including how to lodge a report through ReportCyber.

Where a paid product may or may not help. Security software is relevant to step five only. It has no bearing on steps one to four, which are the steps that determine how much this costs you.

I only opened the page and typed nothing. Am I affected?

In most cases, no. A modern browser is designed to display a page without letting it reach into the rest of the computer, and loading a page is not the same as running a program.

Likely outcomes. The most common result of opening a link like this is that the sender now knows the message reached a real person, which may mean more messages. The second most common is that a file began downloading. A download that sits unopened in a folder has done nothing; a file only matters once it is run. The uncommon case is a browser or plug-in with an unpatched flaw, which is the reason updates are worth installing promptly.

What to try first, at no cost. Close the tab. Look in your downloads folder for anything that arrived at that time, and delete it without opening it. Check that your browser and operating system are up to date, and restart if an update is waiting. If the page asked for permission to send notifications and you agreed, remove that permission in the browser's site settings, because notification spam is a common follow-on and is easily mistaken for a system message.

When to ask for official help. If the page was imitating a government service, Scamwatch at scamwatch.gov.au collects reports of this kind, and the imitated agency usually publishes its own advice on what it will and will not ask for.

Where a paid product may or may not help. If a file did download and you are unsure whether you opened it, a scan of the downloads folder is a sensible precaution, and any security product including the one built into your system can do that. If nothing downloaded, there is nothing for a product to act on.

I entered my password. What exactly do I change?

That account, every account sharing that password, and then your email account regardless. Be systematic rather than quick.

Why email comes into it. Whoever holds a password will often try it against an email address first, because control of an inbox allows password resets everywhere else. Even if the page was imitating a retailer, the email account is the one with the most to lose.

What to do, at no cost.

  • Change the password on the imitated account, choosing something not used anywhere else.
  • List the other places that password was used and change them too. A browser's saved-password manager can show you where it was stored.
  • Turn on multi-factor authentication on the email account, the imitated account, and any account holding payment details.
  • In the account's security settings, sign out all other sessions and look at the list of recent logins and connected devices.
  • Check the email account's forwarding and filter rules. A rule quietly forwarding or deleting messages is a common way for access to be kept after a password change.
  • Check that the recovery phone number and recovery email address on the account are still yours.

When to ask for official help. If you cannot get back into an account because the password has already been changed, use the provider's own account recovery process; every major provider publishes one. If identity documents such as a driver's licence or passport number were entered, IDCARE is the national identity support service in Australia and the ACSC links to it from its guidance at cyber.gov.au.

Where a paid product may or may not help. No antivirus product can undo a password you typed into a convincing imitation of a sign-in page. Some paid packages bundle a password manager, which helps with the underlying habit of reuse, but free and standalone password managers do the same job, and browsers now include one.

I opened an attachment and nothing happened. Does that mean it was safe?

Not necessarily, but it is a reasonable sign. "Nothing happened" is also what a document that was never harmful looks like.

Likely causes for concern or comfort. A document that opens and asks you to enable editing, enable content or enable macros is asking for permission to run code, and declining that prompt is the decision that matters. An attachment that was actually a program will usually have produced a visible permission prompt from the operating system. A file that opened as an ordinary document and displayed something unremarkable most likely was one. Compressed archives containing a shortcut or installer are the category worth the most caution.

What to try first, at no cost. Do not open it a second time. Note the file name and where it came from. Run a scan with the protection already on your system. Install any waiting updates and restart. Then watch for the practical signs over the following days: programs you did not install, a browser whose settings revert, accounts reporting sign-ins you did not make.

When to ask for official help. If the attachment arrived at a work address, your employer's IT contact should hear about it even if you think nothing came of it, because they can check whether others received the same message.

Where a paid product may or may not help. This is one of the situations the category is designed for: a file of unknown provenance, on a desktop operating system. The protection built into Windows and macOS already does this at no cost, and a paid product is a way of adding further features or covering several machines on one licence rather than a way of getting a capability you do not otherwise have.

When is reinstalling the operating system the right answer?

When something was definitely installed and you need to be certain it is gone. Reinstalling is the dependable option, and it is less disruptive than its reputation suggests.

Why removal is not always enough. Removal tools work from known patterns, and something can leave components behind. If the consequences of being wrong are significant — a machine used for a business, for tax records, for a client's data — a clean installation removes the uncertainty in a way that a scan result cannot.

What to do, at no cost.

  1. Back up your documents, photos and anything else irreplaceable to an external drive or a cloud service. Copy data files, not programs.
  2. Make sure you can sign back into your accounts afterwards: know your email password and have your multi-factor method available.
  3. Use the recovery option built into the operating system. Windows and macOS both include a reinstallation path that does not require a separate purchase or installation media.
  4. After reinstalling, install updates before restoring anything, then copy your documents back. Scan the backup before restoring it if it contains programs or installers.
  5. Change the passwords for accounts you used on that machine, from the freshly reinstalled system.

When to ask for official help. The operating system vendor's own recovery documentation is the right instruction set, because the steps differ between versions and between machines with and without a separate recovery partition. A repairer can do it for a fee if you would rather not.

Where a paid product may or may not help. After a reinstall, the system's own protection is active again from the first boot. Whether you add a paid product on top is a separate decision, covered on the choosing and paying page.

Who do I need to tell?

Your bank if money or card details were involved, your employer if it was a work account, and a reporting body in every case. Telling people is not an admission of carelessness; these messages are designed to work on careful people.

Who to contact and why.

Where to report, and what each organisation covers
SituationWho to contactWhat they do
Money sent, or card or bank details enteredYour bank, on the number on your cardCan act on the account, and may be able to stop or trace a recent payment
Any scam message, whether or not you lost anythingScamwatchRun by the National Anti-Scam Centre at the ACCC; collects reports and publishes warnings about current scams
Cybercrime affecting you or your businessReportCyber, via the ACSCThe national reporting route for cybercrime, referring reports to the relevant police jurisdiction
An organisation has lost your personal informationThe OAICThe national privacy regulator, which oversees the Notifiable Data Breaches scheme
Seriously harmful content, abuse or image-based abuse onlineThe eSafety CommissionerThe online safety regulator, which can act on reported content
A work account or work deviceYour employer's IT contactCan check whether colleagues were targeted and secure the account centrally

Is reporting worth the time? You are unlikely to hear back about an individual message, and that can make it feel pointless. The value is aggregate: reports are how patterns are identified and how warnings get published while a campaign is still running. It takes a few minutes.

What to watch out for afterwards

  • Follow-up contact. People who have been caught once are sometimes contacted again by someone offering to recover the money for a fee. Scamwatch describes this pattern on its own site.
  • Search results for support numbers. Telephone numbers that appear in advertisements above search results are not always the organisation's own. Use the number on your card, your statement, or the organisation's published contact page.
  • Pressure to stay on the line or to keep it to yourself. No legitimate organisation needs either.

Where a paid product sits in all of this

Of the six questions on this page, security software is relevant to two: an attachment of unknown origin, and the scan that forms step five of the first hour. Norton AntiVirus Plus is a paid antivirus product that covers that ground; the vendor's own site is the accurate source for what it includes and what it costs. It cannot undo a password that was entered, recover a transfer, or tell you whether a message was genuine before you opened it.

Visit the Norton AntiVirus Plus website to read the publisher's own description.