First, find out what happened
Ask the child what they saw and what they did after opening the link. The important details are whether they only viewed the page, downloaded something, entered a username and password, provided payment details, shared a verification code or approved a sign-in prompt.
Avoid turning this into an interrogation. You need an accurate timeline more than you need an immediate explanation of why they clicked.
If a password was entered
Go to the real service using its normal app or a trusted bookmark rather than returning through the suspicious message. Change the affected password and make sure the replacement is unique.
If that password was reused on other accounts, change those accounts too. Review active sessions and sign out devices or sessions you do not recognise. Check that account recovery email addresses and phone numbers have not been altered.
If a sign-in code or approval was shared
Treat an unexpected code or approval as a sign that someone may have been attempting to complete a login. Change the password, review active sessions and use the service's security or recovery options.
If the account belongs to a school, contact the school's IT or support team promptly so they can check for unusual activity and help with recovery.
If something was downloaded
Do not open an unexpected downloaded file just to see what it is. Remove the download if it is clearly unwanted and use the device's current security tools to scan for threats.
If the device starts behaving unusually, security settings change, or you are unsure what ran, stop using it for sensitive tasks and seek qualified technical help rather than repeatedly experimenting with the file.
Turn recovery into a future safety habit
Once the immediate issue is handled, revisit the message together. Look for the pressure tactic, unusual request or misleading link that made it convincing.
The goal is to make reporting easier next time. Children who believe they will be punished for admitting a click may wait longer to ask for help. Fast reporting is one of the most useful safety behaviours they can learn.
The key is to match the response to what happened: check, change credentials where necessary, close unknown sessions, verify recovery details and get help early.
Continue with the Cyber Safety Hub, practise the ideas in Ranger Academy, or use the free printable resources at home or in the classroom.