10.02.26

Unsolicited direct message link? Don’t click it—here’s what to do instead

A message pops up from a stranger—or even a familiar account—with a link and a personal hook: “Is this you in the photo?” “You won a prize.” “Your account will be locked.” Pause before curiosity takes over. An unsolicited direct-message link can lead to a fake login page, a payment scam or a malicious download. The risk is widespread: Federal Trade Commission data shows consumers reported losing $2.1 billion to scams that started on social media in 2025. A few seconds of caution can protect your accounts, money and identity.

Why do scammers send suspicious links in direct messages?

Direct messages feel private and immediate, which makes them ideal for social engineering. A scammer may impersonate a friend, brand, employer or platform support team. They often create urgency, fear or curiosity so you react before checking the details. A compromised friend’s account can make the message look especially convincing. CISA explains that phishing commonly aims to steal login credentials or deploy malware, which attackers can then use to access more accounts, monitor activity or spread the same lure to your contacts.

What are the warning signs of a malicious DM?

Do not trust a message simply because it uses your name, mentions a real event or comes from an account you recognize. Scammers can copy public details and hijack profiles. Watch for:

  • An unexpected link or attachment with little context
  • A claim that you appear in a photo, video or embarrassing post
  • Pressure to act now, claim a prize or prevent an account closure
  • A request for a password, verification code, payment or personal details
  • Odd wording, a changed username or behavior that feels unlike the sender
  • A shortened, misspelled or unfamiliar web address

Remember that polished grammar, a logo and a familiar profile photo do not prove authenticity. Today’s scam messages can look professional and highly personalized.

What should you do when an unexpected DM contains a link?

  1. Stop and do not interact. Do not click, reply, download a file or call a number in the message.
  2. Verify through another channel. Contact the person using a saved phone number or a separate conversation. For a company, open its official app or type its known website yourself. The FTC recommends contacting the organization through a phone number, email address or website you already know is real.
  3. Inspect the account. Look for a recently changed handle, sparse history, copied posts or unusual requests. These clues can support your decision, but verification matters more.
  4. Report and block. Use the platform’s reporting tools, then delete the message. This can help limit the account’s reach.
  5. Warn the real person. If a friend’s profile appears compromised, contact them elsewhere so they can secure it.

What if you already clicked the link?

Do not panic, but act quickly. Close the page without entering information. Update your device and security software, then run a malware scan; the FTC specifically recommends updating security software and scanning after clicking an unexpected link. If you entered a password, change it immediately from the official app or site, change it anywhere you reused it and enable multifactor authentication. If you shared financial details, contact your bank or card issuer using the number on your card. Review active sessions, recent logins and account recovery information, and sign out unfamiliar devices.

How should you report a suspicious message?

Capture the sender’s username and the message before deleting it, but avoid reopening the link. Report the account inside the social platform. If the attempt involved fraud, identity theft or financial loss, file a report with the FBI’s Internet Crime Complaint Center and the FTC’s fraud-reporting service. Preserve receipts, transaction records and relevant messages for your report.

How does avoiding unsolicited links make you safer online?

Refusing to click breaks the attack at its earliest point. You deny scammers the chance to capture your password, install malware, collect payment details or take over your account to target people who trust you. Strengthen that habit by limiting who can message you, turning on login alerts, using unique passwords and enabling multifactor authentication. Make “pause, verify, report” your default response whenever a DM tries to rush or surprise you.

The safest link is the one you reach independently. If a message might be legitimate, navigate to the service yourself instead of using the shortcut a stranger provided. Share this rule with family and friends today; one quick reminder may stop the next account takeover before it starts.