AI can explain the warning. Shield organizes the next move.
Free first check
Spot pressure, money, identity, and access signals in a redacted example.
Paid early access · USD 19 reference
Turn one redacted situation into a one-page decision brief, official routes, and 15-minute / 24-hour actions.
Clear boundary
No guaranteed verdict or recovery promise. Scope and timing come before payment.
Clicked a scam link? Start here.
Do not panic and do not keep interacting with the page. Your next steps depend on what happened after the click, so work through the checklist in order.
The first ten minutes
Stop the interaction
Close the tab or message. Do not call numbers shown on the page, install “support” software, or enter another code to cancel the request.
If you entered a password, change it
Use the real service website or app, not the link you received. Change the password anywhere else you reused it and turn on multi-factor authentication.
If payment details were shared, contact the provider
Call your bank, card issuer, payment app, or cryptocurrency exchange through an official number or app. Explain what was shared and ask what protective action is available.
If you downloaded or installed something, get device help
Disconnect the device from sensitive accounts if needed and use your operating system’s trusted security guidance. Do not download a second unknown “cleaner” offered by the scam.
Save evidence and report it
Keep the sender, URL, timestamps, receipts, and screenshots. Report the account or message to the platform and the relevant service.
What if you only clicked?
A click does not automatically mean your account or device was compromised. The risk is higher when you entered credentials, approved a login, downloaded software, shared a code, or sent money. Focus your response on what you actually did, then verify through official support.
Quick answers after a click
What if I only clicked?
Close the page and verify through the real app or website. A click alone does not prove compromise, but take extra action if you entered credentials, downloaded software, approved a login, shared a code, or sent money.
What if I entered a password?
Change it through the official service, change reused copies, turn on multi-factor authentication, and review active sessions.
Should I paste the original message into a public checker?
No. Use only a fictional or fully redacted example. Keep passwords, payment details, one-time codes, recovery keys, identity documents, and private addresses private.
Where should I report it?
Contact the real bank or provider first when money or account access is at risk, then use the official fraud or cybercrime route for your country.
Share the calm response checklist.
Send it to someone who may need it, without forwarding the suspicious message itself.
Prevention is easier before the click.
Check the message while you still have time to verify it.
Read the checker guide →