SteadyScope Questions and fixes, explained calmly

I clicked a link or opened an attachment

Six questions for the hour after something was clicked, in the order people usually need them. Answers reviewed 8 October 2026.

The short version

Viewing a page is not the same as giving anything away. What matters is the step that came next: whether you typed a password, entered card details, approved a prompt, or ran a file you downloaded. Deal with accounts before devices — change the password you typed, starting with the one protecting your email — and ring your bank on the number printed on your card if money is involved.

Short answer: in the great majority of cases, nothing at all. A link opens a page. The page can show you something convincing, but it cannot reach into your computer and take anything.

Likely causes of harm, in order

The sequence that actually causes trouble is longer than one click. It usually runs: you open the page, the page imitates a service you use, you type a password or card number, and that information is sent to whoever built the page. A second route is a download: the page offers a file, you save it, you open it, and your operating system asks whether you want to allow it to make changes — and you say yes. A third, less common route exploits a fault in an out-of-date browser, which is why keeping the browser current matters more than most advice admits.

If none of those happened — you looked, the page seemed wrong, you closed it — the realistic outcome is that the people behind the page now know that the address they sent the message to is in use. That is worth something to them, which is why the messages keep coming, but it is not a compromise of your computer or your accounts.

What to try first, at no cost

  1. Close the tab. Do not fill in anything it asks for, even to "check" whether it is genuine.
  2. Write down what you did and did not type. This single note decides every other step.
  3. If you downloaded a file but did not open it, delete it from the downloads folder.
  4. Run a scan with the protection already included in your operating system.
  5. Install any pending browser and operating system updates before you go back to normal use.

When to ask for official help

If you believe information was handed over, report it. Scamwatch collects reports about scams of this kind, and the Australian Cyber Security Centre takes incident reports through ReportCyber and publishes step-by-step guidance for people who have been caught out.

Where a paid product may or may not help

Security software can block some known bad pages before they load and can catch a file that was downloaded. It cannot undo a password you have already typed into a convincing imitation, and that is the part that most often causes real loss. The free action — changing the password — is both faster and more effective than any purchase.

I typed my password into the page. What do I change first?

Short answer: your email password, before anything else, even if the page you typed into was not your email provider.

Why email comes first

Email is the master key to almost everything else you own online, because it is where password reset links arrive. Somebody with your email can reset your banking, shopping, social and government accounts in sequence. If you used the same password on your email as on the page you typed into, that is the first thing to change. If you used a different one, change the account you actually typed into, then still check your email account for unfamiliar sign-ins and forwarding rules.

What to try first, at no cost

  • Change the password on your email account from a device you trust, and sign out of all other sessions.
  • Change the password on the account you typed into, and on any other account using that same password.
  • Switch on two-factor authentication on email first, then on banking and anything holding payment details.
  • Check your email settings for forwarding rules or filters you did not create, which are a common way of staying hidden.
  • Look at recent sign-in activity, which most large providers show, and note anything unfamiliar.

Choosing the replacement password

Length matters more than symbols. Several unrelated words in a row make a password that is long, memorable and hard to guess, and the Australian Cyber Security Centre's guidance for individuals at cyber.gov.au explains the passphrase approach in detail. The important rule is that the new password is not reused anywhere else.

When to ask for official help

If banking or card details were entered, telephone your bank immediately using the number on the back of your card or on your own statement — never a number supplied in the message. If identity documents were involved, report through Scamwatch and cyber.gov.au, both of which set out the steps for replacing compromised identity credentials.

Where a paid product may or may not help

A password manager, whether free or part of a paid bundle, makes the practical problem — a different password everywhere — manageable, and that is a genuine benefit. An antivirus subscription by itself does not change passwords or monitor accounts unless the particular product includes that, which you would need to confirm with the vendor.

I opened an attachment from an address I did not know

Short answer: it depends what the file was and whether you approved anything after opening it. A document that simply opened and displayed text is a far smaller matter than an installer you allowed to run.

Likely causes

The attachments that cause trouble are usually one of three kinds: a program that pretends to be a document, a document containing macros that asks permission to enable content, and an archive that hides the real file type inside. All three depend on you taking a further step — running it, enabling it, or extracting and opening it. Modern operating systems and mail services block a great deal of this before it reaches you, which is why these messages often arrive with the file renamed or inside a password-protected archive.

What to try first, at no cost

Note the exact file name and extension if you still have it, then delete the message. Run a full scan with the protection built into your operating system rather than a quick one. Restart the machine and watch for anything that now starts automatically that did not before. If the attachment arrived while you were signed in to a work account, see the last question on this page.

What to watch out for

  • Replying to the message to ask whether it is genuine. A reply confirms the address is live and read.
  • Opening the file "just to see" on a second computer. The second computer is not safer.
  • Any file that asks you to enable content, enable macros, or disable your protection in order to display itself.
  • Archives supplied with a password in the message body — that combination exists to get past mail scanning.

When to ask for official help

If files on the machine become inaccessible or are renamed in bulk, disconnect it from the network and seek help before paying anyone anything. The Australian Cyber Security Centre publishes guidance on ransomware for individuals and small businesses at cyber.gov.au, including how to report it.

Where a paid product may or may not help

This is the scenario security software is built for, and it is a reasonable place for either the built-in protection or a paid subscription to earn its keep. Run what you already have first; it costs nothing and takes minutes.

Short answer: read the domain, not the words. Everything to the left of the first single slash is the address; the part immediately before it is what matters.

How to read an address

In an address such as example-bank.secure-login.example.net/au, the real destination is example.net, not example-bank. Anything can be placed in front of the real domain, and that is the most common trick in use. On a computer, hovering over a link shows the destination in the corner of the window without opening it. On a phone, pressing and holding a link usually shows the full address in a preview. Shortened links hide the destination entirely, which is reason enough to treat them cautiously in an unexpected message.

What to try first, at no cost

Instead of checking a link at all, ignore it and reach the organisation yourself: type the address you already know, or open the app you already have installed. This takes a few seconds longer and removes the question completely. Where an organisation has a published way of forwarding suspicious messages, use it rather than engaging with the sender.

When to ask for official help

Current scam patterns in Australia — the themes in circulation this month, rather than general advice — are published by Scamwatch, which is the most useful single page to check when a message looks plausible but unexpected.

Where a paid product may or may not help

Some security products include a browser component that warns about known bad addresses. That is useful but partial: a page created an hour ago is not on any list yet. Reading the domain yourself remains the step that works regardless of what is installed.

Why do I keep getting parcel delivery texts?

Short answer: because the message costs almost nothing to send and almost everybody is expecting a parcel at some point. It is volume, not targeting.

Likely causes

Mobile numbers circulate widely, and a message claiming a delivery problem works on the small fraction of recipients who happen to be waiting for something that day. The same applies to messages about tolls, fines, rebates and account suspensions. The pattern is always the same: a short deadline, a small payment or a sign-in, and a link. Receiving one says nothing about your phone's security and does not mean anything has been installed on it.

What to try first, at no cost

  • Do not reply, and do not use the link. Check any genuine delivery through the courier's own app or website.
  • Report the message using your phone's built-in reporting option, which forwards it to the relevant service.
  • Block the sending number, accepting that the next message will come from a different one.
  • Tell anyone in the household who might be less certain about these messages what the current pattern looks like.

When to ask for official help

Report scam messages to Scamwatch. If you followed a link and entered details, treat it as the password question above and contact your bank if payment information was involved.

Where a paid product may or may not help

Message filtering on phones is largely handled by the operating system and the mobile carrier rather than by antivirus software. Some paid security subscriptions include a filtering component on mobile, with results that vary by network and country; it is worth confirming what is actually offered in Australia before buying for that reason alone.

Should I tell my employer if it happened on a work laptop?

Short answer: yes, promptly, and the earlier the better for everyone including you.

Why reporting early is the better course

Organisations have tools that a person sitting at the laptop does not: they can see which accounts were used, reset credentials centrally, and check whether anything spread. Every hour of delay makes that harder. Most organisations in Australia have a policy that explicitly favours prompt reporting over perfect behaviour, because the alternative is finding out weeks later. If personal information belonging to other people may have been exposed, the organisation may also have obligations under the notifiable data breaches scheme administered by the Office of the Australian Information Commissioner, which it cannot meet if nobody tells it.

What to try first, at no cost

Tell your IT contact or manager in plain terms what took place: the time, the message, what you clicked, and what you typed. Leave the laptop on and connected unless you are told otherwise, since disconnecting can remove evidence. Do not attempt to clean the machine yourself; on a managed device that can interfere with the organisation's own tools.

When to ask for official help

Reporting within the organisation comes first. The organisation decides whether to report externally, usually to the Australian Cyber Security Centre and, where personal information is involved, to the OAIC.

Where a paid product may or may not help

A personal subscription has no role on a managed work device, and installing one may breach the organisation's policy or conflict with the protection already deployed. Keep personal purchases for personal machines.