Clicked a Suspicious Link? What to Do in the Next Hour: a Newington Guide

You clicked a dodgy link and now you’re not sure what you just logged into. Here’s the first-hour playbook we walk every Newington caller through on the bench.

3 October 2026 9 min read Cybersecurity Alex M.
A phone showing a suspicious delivery text with a shortened link, next to a laptop open in a Newington student flat on a desk by a window

A student in a Newington flat rang us one Tuesday evening in September. She’d had a text that looked like it was from DPD, saying her parcel needed a small redelivery fee, with a link. She clicked, typed her card details and date of birth into a page that looked a lot like the real courier site, closed it, then noticed the URL in her history was something ending in .top. Her first instinct was to run a virus scan on her laptop. The virus scan was almost the least useful thing she could have done. What matters in the hour after a dodgy click is not the PC — it’s the accounts, and the clock is running.

This is the sequence we talk every Newington caller through, in the order it actually works. If you’ve done something you’re not sure about and the panic is setting in, slow your breathing, keep the device in front of you, and go through these steps one at a time. If the account is already compromised, bring the machine to our virus and malware removal team once the account recovery is underway — cleaning the PC first and the accounts second is the mistake we see most often.

1. The First Five Minutes: Stop Making It Worse

The reflex most people have is to keep clicking around on the same machine — refresh the suspicious page, open the email again, hit the virus scanner, maybe reboot. Every one of those is a tiny gift to whoever runs the scam. The useful first move is to stop touching the PC that did the click. Don’t shut it down, because some stealthy persistence only triggers on reboot. Don’t open your banking app on it. Just leave it alone and move to a different device.

If a form actually opened and you typed something into it, write down what you remember entering before you forget: username, which email address, which password (even just “the usual one”), full card number or just last four, date of birth, address. That list decides the order of everything that comes next. If a file downloaded and you ran it, that’s a different, bigger problem — we cover the paste-this-command variant in our fake CAPTCHA ClickFix guide for Fountainbridge, and most of this post still applies on top.

2. Switch to a Second, Trusted Device

Your phone on mobile data is almost always the right second device: a different network, a different browser, not the one the attacker just interacted with. If you only have one device, borrow a flatmate’s laptop or ring us from mobile data and we’ll walk you through on a video call. Avoid university Wi-Fi for this step if the compromised password is your student email — same credential across both means the attacker could be watching the same account from the inside.

Everything in the next four sections happens on this second device. Nothing on the device that did the click. That rule alone fixes about three-quarters of the mistakes we see in the first hour.

3. Lock Down the Email First, Not the Bank

This surprises people. If a phishing form took card details, surely the bank comes first? In practice no. Your email is the master key: every other account on earth has a “forgot password?” button that mails a reset to it. If an attacker owns the email, they own everything, in order, within an hour. If they don’t own the email, most other damage is survivable because you can recover accounts through the email.

So from your second device, open the sign-in page for whichever email provider that account uses — Gmail / Google, Outlook / Microsoft, Yahoo, iCloud, your university webmail. Change the password. Then look for the security page that lists active sessions and signed-in devices and sign everything else out. We’ll come back to why that step is doing the real work. If you reused the email password anywhere else, change it there too, within the hour. Our guide to a hacked email account in Edinburgh is the longer version of this section with the exact dashboard paths for each provider.

4. Kill the Session, Not Just the Password

Here’s the bit nearly everyone misses, and it’s the single most important paragraph in this post. Modern phishing doesn’t just steal a password; it steals the session cookie — the little token your browser gets after you log in that says “this user is already authenticated for the next 30 days”. If the attacker already has that cookie, changing your password doesn’t boot them out. They stay logged in as you, with a valid token, until the token expires or you explicitly end every session.

Every major platform has an “active sessions” or “where you’re signed in” screen tucked inside account security settings. Google calls it “Your devices”. Microsoft calls it “Sign in activity”. Facebook calls it “Where you’re logged in”. Instagram has it under “Login activity”. On every one of them there’s a “sign out of all other sessions” button. Press it. Only then is the password change doing anything. This is identical to the sequence we describe for ClickFix victims — because under the bonnet the mechanic is the same stolen session, just delivered differently.

5. A Newington Bench Story

The student from the opening — the DPD-looking text — walked in the next morning with her laptop. Her instinct had been right that something was wrong; her instinct had been wrong about where. The laptop was clean: no malware, no persistence, nothing had been downloaded. The attack had been purely in the browser, on the fake site, and the browser had done its job and closed when she shut the tab. Running endless scans would have found nothing all week.

What had happened was card-not-present charges on her bank, two of them, within forty minutes of the submission — one at an online grocery, one at a cryptocurrency platform. Her bank’s fraud team caught the second and blocked the card; she rang the number on the back of the card from her phone (not any number from the scam page) and got the first one refunded over the next week. Fifteen minutes after her phone call to the bank, a second phishing text came in — this time pretending to be the bank, “confirm the suspicious transaction”. That one would have given up her full online-banking login. She didn’t click. The scammers often circle back on the same number within the hour precisely because they know people are now looking at their phone and expecting bank contact. Knowing to expect that second text was the only genuinely new thing we taught her — and it’s the thing we tell every caller from Newington, Marchmont and Bruntsfield now because it keeps happening.

6. Then, and Only Then, Check the PC

Once the email, the master accounts and the active sessions are under your control, you can turn to the device. If all that happened was you typed into a form, the PC is almost always fine. Browsers run pages in a sandbox; a web form can collect what you type but can’t silently install software without a download and a run. In those cases we clear the cache, flush the browser profile, check the Scheduled Tasks and the browser extension list as a cross-check, and send the machine home the same day.

If a file downloaded and you opened it, treat it as compromised: isolate, boot from a clean environment, pull out personal data, check for persistence, decide between a deep clean and an OS re-install. If a password manager’s master password was ever typed into the phishing page, change the master password through its own trusted app on your phone, then sign every other device out of the vault. If a document you downloaded was a signed installer, our fake browser update popup guide for Bruntsfield covers the clean-up pattern — the symptoms overlap heavily. And if browser pop-ups started firing even after you closed the tab, the Craigmillar browser pop-ups guide is the next read.

7. The Monitoring Week

Over the week after an account incident, three things need watching. Your email’s sent folder — attackers often reply to your contacts from your inbox, then delete the sent message; check at least once a day for mail you don’t remember writing. Your bank statement — sometimes a stolen card is tested with a tiny transaction, usually under two pounds, a day or two before the big one, so a tiny charge is a warning, not a nuisance. Your phone bill or your mobile carrier’s portal — SIM-swap fraud follows account takeovers surprisingly often; a “your SIM has been activated on a new device” text is the one to never ignore. If any of these fire, we’re a call away and can arrange remote support to walk through the dashboards with you in real time.

When to Hand It Over

If a work laptop or a business email was involved, bring it in: an incident in a business inbox has reporting obligations and contact-point implications we can help you sketch out. If card details went in, your bank runs the fraud process — our role there is making sure the PC is clean so new credentials don’t leak the same way again. If you can’t get into your own email because the attacker already changed the recovery details, that’s a time-sensitive job and ringing us earlier beats later. We cover virus removal in Newington same-day or next-day in most cases, and we can also straighten out the Windows Security, browser profile and sign-in settings that the aftermath leaves in a strange state. For the general pattern of how these messages look before you click them, our phishing scams guide for Edinburgh is the companion piece to this one.

Last updated: 3 October 2026

Frequently Asked Questions

What Newington callers ask us after realising a link they clicked wasn’t what it looked like.

If no file downloaded and you didn’t enter credentials, usually a quick browser-history check, a cache clear and a fresh look at your extensions is enough. The thing to confirm is that nothing downloaded in the background — check your Downloads folder for anything you don’t recognise from the last hour. If anything did download, don’t run it; bring the laptop in and we’ll have a look.

Because modern phishing kits steal the session cookie, which is a signed-in token that doesn’t care about your password being changed afterwards. The cookie keeps the attacker logged in as you until the platform expires it or until you explicitly end every session from the account’s security page. The order is: change password, then sign out of everything else, then turn on two-factor authentication if it wasn’t on already.

Not before you’ve secured the accounts. A scan takes 20–40 minutes and finds nothing useful in a browser-only phishing case — and in those twenty minutes an attacker with the stolen credentials can empty your inbox and start resetting other accounts. Secure the email and the sessions first, then by all means run Windows Defender’s offline scan as a cross-check. If you want certainty before you trust the machine for banking again, drop it in with us.

Yes, and quickly. Credentials from phishing kits are run against the hundred most popular sites by automated tooling within hours. Email first, then anything with a stored payment method (banks, PayPal, Amazon, Uber), then social accounts. A password manager with a unique password per site stops this whole category of problem permanently — and the master-password-plus-two-factor combination is far less to remember than everyone fears.

Clicked Something You Shouldn’t Have?

Bring the laptop into Newington drop-off range or book a slot — we’ll help you sign out the attacker, check the PC for anything that was dropped, and get you back to banking on it safely.