You clicked before you thought, it happens to everyone. What matters now is doing these steps in order, right away.
If the page is asking for a password, card number, or any personal details, do not type anything into it, even if you've already clicked through. Close the tab immediately, Ctrl+W on Windows or Command+W on Mac.
If the link may have downloaded something or asked you to install anything, disconnect your device from the internet, turn off Wi-Fi or unplug the network cable. This stops any malware from communicating out or spreading further while you sort things out.
If you did enter a password on the fake page, go directly to the real website yourself, type the address in by hand, don't click any link, and change that password right away. If you reuse that same password anywhere else, change it there too.
Never click a "reset your password" link from the same message that led you to the phishing page in the first place. Always navigate to the real site independently.
Run a virus and malware scan on your device. Keep an eye on your bank accounts, email, and any account you're worried might be affected for a week or two afterward, unusual login alerts or password reset emails you didn't request are the clearest sign something took hold.
Don't stay quiet about it out of embarrassment, reporting quickly is what actually limits the damage. File a report with the FTC at ReportFraud.ftc.gov if you're in the US, or your country's equivalent, and forward the original phishing message to your email provider if it's still there.
You just learned this the hard way. The Scam-Proof Playbook covers 30+ scam types, phishing, phone scams, fake job offers, and more, so you can spot the next one before you ever click.