Yes. You can get hacked when you click a malicious link. The link opens a fake page that steals your password. It can also start a download that installs malware on your device. Most links are safe. This page shows you how to find the dangerous ones, and what to do if you click one.

Can you get hacked by clicking a link

A malicious link is a web address that sends you to a dangerous page. Attackers put these links in emails, text messages and social media posts. The link looks normal. The page behind it is not.

  • Phishing: the page copies a real login page and records what you type. Read more about phishing attacks.
  • Drive-by download: the page installs malware without a second click.
  • Fake update: the page tells you to install a file that contains malware.

Phishing is the most common attack that starts with a link. The link opens a page that looks like your bank or your email service. The page asks for your username and your password. You type them. The attacker records them and uses them on the real site.

For example, an email tells you that your bank account has a problem. The email asks you to click a link and confirm your details. The link goes to a copy of the bank website. The attacker gets your details as soon as you type them.


Yes. Many people say virus, and security engineers say malware. Both words mean software that damages your device or steals your data. A malicious link installs malware in two ways. It downloads a file and asks you to open it. It can also attack a weakness in your browser and install the file with no question.

Old software makes the second attack easy. Update your browser and your operating system every month.

Yes, but this attack is less common than phishing. A dangerous website can attack your browser as soon as the page opens. Engineers call this a drive-by download. The attack needs a weakness in your browser or in a plugin. A current browser stops almost all of these attacks.

The risk grows if you use an old browser. It also grows if you install software that the website offers you. Close the page if a website asks you to install a file.


A malicious link starts one of four attacks.

  1. Phishing: the attacker copies a real website and collects your login details.
  2. Drive-by download: the page installs malware on your device without a second click.
  3. Credential stuffing: the attacker uses your stolen password on other websites.
  4. Ransomware: the malware locks your files and demands money.

Use these steps every time you get a link that you did not expect.

  1. Hold the pointer above the link. Your browser shows the true address at the bottom of the window.
  2. Read the domain name carefully. Attackers use names that look correct, such as facebo0k.com instead of facebook.com.
  3. Look for HTTPS in the address bar. HTTPS does not make a page safe, but its absence is a warning.
  4. Do not click a link in a message that you did not expect.
  5. Type the address in your browser if you are not sure.
  6. Install antivirus software and turn on your firewall.
  7. Turn on two-factor authentication on every important account.
  8. Update your operating system, your browser and your applications every month.

You can also test a web address with our free website safety checker.


Act quickly. The first hour matters more than the first day.

  1. Disconnect the device from the internet.
  2. Change the password for the account that the page asked about.
  3. Change the same password on every other website that uses it.
  4. Turn on two-factor authentication for that account.
  5. Do a full scan of the device with your antivirus software.
  6. Tell your bank if you gave card details or bank details.
  7. Watch the account for messages that you did not send.

You are safe if you closed the page and typed nothing. A click alone rarely gives the attacker your data. The danger starts when you type your details or open a downloaded file.


Can you get hacked just by opening a website?

This is possible, but it is rare. The attacker needs a weakness in your browser. A current browser closes almost every one of these weaknesses.

Yes. The network does not change the risk. The danger comes from the page behind the link, not from the application that shows it.

Yes. A phishing page works the same way on a phone. A small screen hides part of the address, so the domain name is harder to read.

This is unlikely. The attacker gets your data when you type it. Close the page, and scan the device if it asked you to download a file.

One click can expose a customer database or a bank account. SecureWeb helps Moroccan businesses find and close these weaknesses before an attacker does. See our security services, or test your site now with the free website scanner.

Follow Secureweb