Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If you clicked a suspicious bank link, the next step depends on what happened after the click. A click without entering details or installing anything does not prove your account or device was compromised. If you entered a password, PIN, or one-time code, installed an app, granted remote access, or noticed unfamiliar activity, contact your bank promptly using a trusted phone number or app—not details in the suspicious message.
I clicked a suspicious bank link—what should I do?
- Stop interacting with it. Do not reopen the link, reply to the message, call a number it provides, or follow instructions from a caller who contacts you afterward.
- Contact your bank through a verified route. Call the number printed on your bank card, or open the bank app or website using an address you already know is genuine. Explain whether you only clicked, entered credentials or a code, installed an app, allowed remote access, or saw an unauthorized transaction. The FTC advises contacting a company through a phone number or site known to be real: FTC phishing guidance.
- Ask the bank to review and protect the account. Request a review of transactions and account changes, help securing online access, and action to stop or recall any unauthorized transfer. Ask whether a card or account number should be replaced and what monitoring is available. Recovery options depend on the bank, payment method, circumstances, and jurisdiction; a transfer cannot always be reversed. The FBI advises contacting the financial institution promptly when account takeover is recognized: FBI account takeover alert.
- Keep evidence. Save the message, sender or caller details, URL, app name, and any transaction records. Do not delete information the bank or law enforcement may need.
A caller ID, search-result ad, text reply path, or phone number in a suspicious message does not prove that you are speaking with your bank. The CFPB warns that real agencies and financial institutions will not threaten you or ask you to move money to “protect it”: CFPB scam guidance.
What to do based on what happened
| Exposure | Bank and account action | Device or phone action |
|---|---|---|
| Clicked only; entered nothing and installed nothing | If the link claimed to be from your bank, contact it through a verified channel and describe what happened. Do not return to the link. | Do not assume the account is compromised based on the click alone. If anything downloaded or the device behaves unexpectedly, treat it as a possible device issue. |
| Entered a username, password, PIN, or one-time code | Call the bank promptly. Change exposed credentials from a trusted device and change any reused password elsewhere. Tell the bank if you shared a one-time code. | Use the genuine bank app or independently reached website, or follow the bank’s instructions. Enable available MFA. |
| Installed an app or allowed remote access | Call the bank using a separate trusted device or phone, and explain the app or remote-access session. | Stop banking from the affected device until it has been checked. Use legitimate security software or trusted technical help; malware-specific reset advice applies only to the threat it addresses. |
| Unfamiliar withdrawal, transfer, purchase, or account change | Contact the bank immediately and ask it to act on the specific transaction or change. Keep the transaction record. | If an app or remote access was also involved, avoid using the affected device for banking. |
| You lost control of your phone number | Tell the bank, particularly if it uses text-message verification, and secure account access with the bank’s guidance. | Contact your mobile provider to recover control of the number. A hijacked number can undermine text-message verification. |
If you entered a password, PIN, or one-time code
Change the exposed bank password using a trusted device and the bank’s genuine app or site. Change it anywhere else you reused it; use a different password for each account. Turn on the bank’s available multi-factor authentication (MFA). The FTC explains that MFA makes it harder for scammers to log in even if they obtain a username and password: FTC phishing guidance.
Tell the bank if you disclosed a one-time password or verification code. Attackers may use credentials and codes to take over accounts, change passwords, and move funds. Do not give a new code to an inbound caller or texter claiming to be the bank. The FBI/IC3 states: “Financial institutions will not ask you for these codes over the phone.” See its mobile banking app advisory.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If you installed an app or granted remote access
Treat the device as potentially compromised rather than continuing to bank on it. Use another trusted device to reach your bank, and ask a trusted technical professional for help if you cannot confidently check the affected device.
- Stop using the affected phone or computer for banking and other sensitive logins.
- Update legitimate security software, run a scan, and remove threats it identifies. A scan is not a guarantee that every threat will be found or removed.
- If a scammer had remote access, contact financial institutions promptly, change passwords from a trusted device, and consider professional device cleaning. The FBI recommends keeping original documentation as well: FBI tech-support scam advice.
There is one specific reset recommendation worth distinguishing from general cleanup advice: Ireland’s National Cyber Security Centre advised factory-resetting an Android device affected by the Flubot malware campaign in its 2021 notice. That advisory also says not to restore backups made after installing the malicious app and recommends contacting the mobile provider. It is guidance for that threat, not a diagnosis that every suspicious app requires a factory reset: Ireland NCSC Flubot advisory.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do not let a follow-up scam deepen the loss
Scammers may impersonate a bank or support employee and ask for passwords, MFA codes, or a transfer to a supposedly “safe” account. Do not follow those instructions. Hang up and call the number on your card or use the bank app you opened independently. The CFPB says real agencies and financial institutions will not threaten consumers or ask them to move money to protect it: CFPB scam guidance.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesFor later account hardening, consider a password manager to help maintain unique passwords. A physical security key is an option only if your bank supports it; buying one does not contain an active incident, recover funds, or remove malware. Confirm supported MFA methods with the bank before choosing one.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Report the scam and retain records
In the United States, report phishing to the FTC and account takeover or related cybercrime to the FBI’s Internet Crime Complaint Center (IC3). The CFPB also points consumers to state attorneys general and local police. Reporting channels and remedies vary by location; outside the U.S., use the relevant national consumer-protection or cybercrime reporting service.
The FBI/IC3’s 2020 mobile banking advisory cited nearly 65,000 fake apps detected on major app stores by U.S. security research organizations in 2018. That is a historical figure, not a measure of current app-store prevalence: FBI/IC3 mobile banking app advisory.
Quick Recap
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

