US
What to do after clicking a phishing link

A VPN Will Not Stop Phishing: What to Do After You Clicked the Link

A VPN protects one part of the connection. It does not erase account history, stop you from typing a password into a phishing page, or replace endpoint security. Marketing that blurs those lines is selling comfort, not a threat model.

Editorial rule: keep the original evidence boundaries. Do not turn untested speed, access, pricing, or support claims into facts.

Where this advice breaks down

  • An encrypted tunnel cannot undo credentials submitted to an attacker.
  • A DNS-level blocker is not an antivirus engine.
  • Signed-in accounts and browser sync can retain activity regardless of the VPN.

Which situation are you in?

What happened Risk Do this now
① Clicked the link, entered nothing Low–medium Close the tab → branch ①
② Entered a username/password High Change that password now → branch ②
③ Downloaded a file or installed an app High Disconnect → scan → branch ③
④ Entered card or bank details Very high Call your bank first → branch ④

① You clicked but entered nothing

Most of the time a single click doesn’t equal infection — but don’t call it closed yet. Close the tab, delete the message, and watch your accounts for a few days. Report the attempt: forward phishing emails to reportphishing@apwg.org (Anti-Phishing Working Group), forward scam texts to 7726 (SPAM), and file at ReportFraud.ftc.gov. As the FTC puts it, “the information you give helps fight scammers.”

② You entered credentials

Change that password immediately — from a different device if you can. If you reuse that password anywhere else, change it there too; leaked combinations get replayed against other sites within hours. Turn on multi-factor authentication wherever it’s offered; it’s the single highest-value move after a credential leak. If you entered your Social Security number or other identity data, go to IdentityTheft.gov — the FTC’s site walks you through “the specific steps to take based on the information that you lost,” including fraud alerts and credit freezes.

③ You downloaded a file or installed something

Follow the FTC’s own sequence: “update your computer’s security software. Then run a scan and remove anything it identifies as a problem.” In practice: disconnect from the network first, update your security software, run a full scan, remove what it flags. On a phone, uninstall the app you just installed; if the device keeps misbehaving, back up your data and consider a factory reset.

④ You entered card or bank details

Order matters. Call your card issuer or bank first to freeze the card and dispute charges — stopping the next transaction is more time-sensitive than filing a report. Then report at ReportFraud.ftc.gov, and use IdentityTheft.gov if identity data went with it.

So what does a VPN actually do against phishing?

Let’s draw the line honestly. A VPN’s job is encrypting traffic and masking your IP — genuinely useful on public Wi-Fi against snooping. What it cannot do: stop you from typing a password into a convincing fake page, inspect a file you download, or block a brand-new scam domain. Some paid VPNs bundle DNS-level blockers (Proton’s NetShield, Nord’s Threat Protection, Surfshark’s CleanWeb) that reduce contact with known malicious domains — helpful, but a reduction layer, not a shield. We map that boundary in VPN ad blocker vs. antivirus.

FAQ

Q. I clicked and nothing seemed to happen. Am I safe?
Probably, but the follow-through is part of the response: watch statements and new-device alerts for a few days, and report the message. It costs two minutes.

Q. Should I install antivirus or a VPN first?
For phishing and malware concerns: security software first. A VPN is the add-on for public Wi-Fi and privacy, not the foundation. If you’re considering a free VPN, read the actual free-tier terms first — Proton Free vs. Plus shows what free really includes.

Q. Where do I report phishing in the US?
Emails → reportphishing@apwg.org. Texts → forward to 7726. Everything → ReportFraud.ftc.gov. Identity theft → IdentityTheft.gov.

Bottom line

Phishing response is about sequence, not software: cut the connection, remove the cause (password change, malware scan), stop the bleeding (bank first), then report. A VPN appears nowhere in that sequence — its real value lives elsewhere, and we keep the two claims separate on purpose. For where a VPN does earn its keep, see our three-way comparison.

Sources (verified 2026-08-11)

General information, not legal or financial advice; follow official agency guidance for your case. Some links are affiliate links (no effect on rankings or your price).
Published 2026-08-11 · Not verified by us: agency procedures may change — official pages take precedence.

Who should not use this approach

  • Anyone looking for one app to replace MFA, updates, and antivirus
  • Anyone who will ignore device or employer security policy
  • Anyone who assumes a connected icon proves every threat is blocked

When this approach actually helps

  • Users who separate connection privacy from device and account security
  • People who pair a VPN with MFA, updates, and careful link handling
  • Travelers using untrusted networks with a defined threat model
Scroll to Top