Your child clicked a link they shouldn’t have, and now your stomach is in knots. Take a breath. This happens to smart, careful kids all the time, and in most cases, quick action prevents serious harm. This guide walks you through exactly what to do in the first few minutes, the next few hours, and the days that follow, so you can handle this calmly and turn it into a teaching moment instead of a crisis.
What Should You Do in the First Five Minutes?
Speed matters more than perfection right now. You don’t need to know exactly what the link did before you start protecting your child’s devices and accounts. Work through these steps in order.
- Disconnect from the internet. Turn off Wi-Fi or put the device in airplane mode. If malware is trying to download or communicate with a remote server, cutting the connection can stop it mid-process.
- Don’t enter any more information. If a fake login page popped up and your child hasn’t typed anything yet, close the tab or app immediately. If they already entered a password, move to the account security steps below.
- Take a screenshot before closing anything. A screenshot of the link, the website, or the text message gives you a record to check against later and can help if you need to report it.
- Ask your child to walk you through what happened. Keep your tone neutral and curious, not alarmed. “Show me what you clicked and what happened next” gets better information than “Why would you click that?!”
How Do You Know If the Link Actually Caused Damage?
Not every suspicious click leads to a real problem. Many phishing links simply load a fake page designed to steal information you enter, and if nothing was typed in, no data was taken. Look for these warning signs that something downloaded or ran on the device.
- New apps or icons your child doesn’t recognize
- The device suddenly running slowly, overheating, or draining battery fast
- Pop-up ads appearing even when no browser is open
- Unusual data usage or unfamiliar charges on an app store account
- Friends or contacts saying they received odd messages from your child’s account
- Browser homepage or search engine changed without anyone doing it
If you see any of these, treat the device as compromised and move to the cleanup steps below. If nothing looks unusual after a day or two of normal use, the risk was likely low, but it’s still worth changing passwords as a precaution.
What If the Link Asked for a Password or Payment Info?
This is the scenario that needs the fastest response, because the damage isn’t about the device, it’s about the account. If your child typed a username, password, gift card code, or payment details into a page that turned out to be fake, treat every account tied to that information as exposed, not just the one the link pretended to be.
How Do You Secure Your Child’s Accounts?
Once the device is disconnected and you understand roughly what happened, shift focus to locking down accounts before anyone can use stolen information.
- Change the password immediately on any account your child logged into or that shares a password with the compromised one. Use a different device to do this if possible, in case the original device is still infected.
- Turn on two-factor authentication for email, gaming accounts, and social media if it isn’t already on. This is the single best protection against a stolen password being used.
- Check for password reuse. Kids often use the same password across school accounts, games, and social apps. If that password was exposed, every account using it needs a new, unique password.
- Log out of all sessions. Most email and social platforms let you view “active sessions” or “logged-in devices” and force-log-out everywhere. This kicks out anyone who may have grabbed a login token.
- Review account recovery info. Scammers sometimes change the recovery email or phone number first, so they can lock the real owner out later. Confirm this info is still correct.
Should You Check Bank or Gift Card Accounts?
Yes, if your child has any linked payment method, in-app purchase account, or their own debit card. Check recent transaction history for anything unfamiliar, and consider freezing the card temporarily if you see charges you don’t recognize. For gift cards or app store credit, check the balance and contact the platform’s support line right away if funds are missing, since gift card theft is often irreversible.
What Should You Do to Clean the Device Itself?
If you spotted signs of malware, adware, or an unfamiliar app, the device needs more than a password change.
- Run a security scan. Use built-in protection (like Google Play Protect or Apple’s malware protections) or a reputable antivirus app to scan for threats.
- Delete unfamiliar apps. If your child doesn’t remember installing something, remove it and check whether it requested unusual permissions like access to contacts, texts, or the camera.
- Update the operating system and apps. Software updates often patch the exact vulnerabilities scam links try to exploit.
- Consider a factory reset for serious cases. If the device shows persistent strange behavior after a scan and app removal, a full reset (after backing up photos and important files) guarantees a clean slate.
How Do You Talk to Your Child About What Happened?
How you respond in this conversation shapes whether your child comes to you next time or tries to hide it. Kids who fear punishment often delete evidence, ignore warning signs, or stay quiet when something goes wrong, which makes the next incident far more dangerous.
- Lead with reassurance. Say clearly: “You’re not in trouble. I’m glad you told me.” This single sentence does more for future safety than any lecture.
- Walk through the red flags together. Look at the actual message or link and point out what made it convincing, whether it was urgency (“Your account will be deleted in 24 hours”), a fake prize, or a message pretending to be from a friend or game.
- Explain the “pause and check” habit. Teach your child to stop before clicking anything urgent or too-good-to-be-true, and to check with a parent or verify through an official app or website instead of the link itself.
- Practice spotting scams together regularly. Tools like LanternPhish let families run safe, simulated phishing scenarios so kids learn to recognize the tricks in a low-stakes setting, before a real scammer tests them for the first time.
Should You Report the Link?
Reporting helps protect other families and sometimes triggers a faster response than handling it alone.
- Text message scams: Forward the message to 7726 (SPAM), which reports it to your mobile carrier.
- Email phishing: Use the “Report phishing” option in Gmail, Outlook, or your email provider, and report it to the company being impersonated (most have a security@ email address).
- Social media or gaming scams: Use the platform’s built-in report feature and consider reporting to the FTC at ReportFraud.ftc.gov.
- Identity theft or financial loss: File a report at IdentityTheft.gov, which walks you through recovery steps specific to what was compromised.
Frequently Asked Questions
My child clicked the link but didn’t type anything in. Am I still at risk?
Usually the risk is low if no information was entered and no download happened. Still, it’s smart to run a quick security scan and keep an eye on the device for a few days. If you’re unsure whether something downloaded automatically, treat it cautiously and check for the warning signs listed above.
Should I take away my child’s phone or restrict internet access as a consequence?
This is generally not recommended. Punishing a child for clicking a scam link teaches them to hide future mistakes rather than report them. Instead, use it as a hands-on lesson, and consider it a success that they were willing to tell you at all.
How long should I monitor the device after this happens?
Check in on it for about one to two weeks, watching for unusual behavior, unexpected app store charges, or messages from your child’s accounts that they didn’t send. If everything looks normal after that window, the immediate risk has typically passed.
What’s the difference between a phishing link and a link with a virus?
Phishing links usually lead to a fake website designed to trick someone into typing in personal information, like a password or credit card number. A malicious link with a virus instead tries to secretly install harmful software on the device. Some scam links do both. That’s why it’s important to check both your child’s accounts and the device itself after any suspicious click.
How can I prevent this from happening again?
No family can eliminate risk completely, since scam messages are designed to look increasingly convincing. The best defense is ongoing practice: talk through real examples when they come up, keep communication open so your child reports suspicious messages right away, and use safe simulation tools to build recognition skills before a real scam arrives.
Protect your family from scams — get Lantern Phish free: