Problem

You already tapped the link in a suspicious text — a parcel that “could not be delivered”, an unpaid fine, a data-breach “compensation” claim — and only then realised it looked wrong. What should you do first?

Breathe. Opening a link and doing something on the page are very different levels of risk. Find your situation below and start there.

Symptoms

  • The link opened a page dressed up as a bank, courier or government office.
  • It asked for your name, phone number, date of birth, card number or a verification code.
  • It asked you to install a “security app” or “delivery tracking app”.
  • Right after, unknown numbers called you, or friends received odd texts in your name.

Find your situation

1. You opened it and did nothing else. This is the most common case and usually where it ends. Close the page, delete the message and report it. Checking where the link actually led (below) helps you recognise the same scam next time.

2. You typed something in. What you typed decides what to do.

  • Card number, account number or a verification code: call the card company or bank now and ask them to suspend the card or block transactions. If money already left, ask for a payment stop immediately (in Korea, the police at 112 can also request it).
  • Username and password: change it everywhere you reused it and turn on two-step verification.
  • Name, address, ID details: prepare for identity misuse — see the checklist (financial-identity exposure registration, mobile line protection).

3. You installed an app. The most dangerous case: smishing apps can read your texts and contacts or take remote control. Order matters:

  1. Switch the phone to airplane mode.
  2. From another device, contact your bank and card company and lock accounts and cards. Do not open banking apps on the infected phone.
  3. Delete the unknown app and run a mobile security scan.
  4. If remote control is possible, back up your photos and factory-reset.

When you report it or warn others, knowing the real destination helps. Short links (han.gl, bit.ly and the like) hide it, so you cannot tell by looking.

Diagnose with DechoNet

  • Paste the whole message into the phishing link check. It follows short links to the final address and shows when that domain was registered, whether it imitates a bank or courier, and whether it pushes an app (APK) download.
  • Lookalike domain detection shows how many domains are spelled almost like the official one.
  • Domain registration lookup tells you when and where the domain was created. A domain registered a few days ago is almost certainly a scam.

Resolution Checklist

  • Screenshot the message before deleting it — it is your evidence.
  • Report it (in Korea: 118, KISA’s 24-hour spam centre, or your carrier’s spam report).
  • If you entered card or account details, ask the card company or bank to suspend them now.
  • If money was taken, request a payment stop (Korea: 112) and file a police cyber crime report (ecrm.police.go.kr).
  • If you entered personal details, register them with the Financial Supervisory Service’s exposure-prevention system (pd.fss.or.kr) so new accounts and cards cannot be opened in your name.
  • Use M-Safer (msafer.or.kr) to block or get alerts on new mobile lines in your name.
  • If you installed an app: airplane mode → lock finances from another device → remove and scan → reset if needed.
  • Change every password you reused.

When to Escalate

  • If money is gone, call the police and your bank at the same time. A payment stop works best within hours.
  • In Korea, the Financial Supervisory Service (1332) advises on recovery procedures.
  • If texts went out in your name, tell your contacts right away not to tap them.

Paste the message and check it now

Paste the whole message or just the link. The text is not stored; each link is followed to where it really goes.