Clicked a delivery scam text? Three AI answers agreed on resets—and diverged on the checks
You open a suspicious parcel-delivery link, close it, and enter no information. Should you wipe your Android phone anyway? ChatGPT, Gemini and Claude all said an immediate reset was not warranted by that description. The useful differences appeared in what they asked the reader to check next.
The important phrase was “I do not remember”
The person explicitly said they entered no information. For installation and permissions, however, they said they did not remember doing either. A useful answer should convert that uncertainty into checks instead of silently treating it as proof that nothing happened.
I received a text saying my delivery address was wrong and tapped its link on an Android phone. The page looked suspicious, so I closed it immediately. I entered no name, card number or password, and do not remember installing an app or granting permissions. Nothing unusual is visible, but I am worried. Should I reset the phone and change all my bank passwords? What should I do now?
ChatGPT: useful branches, but one trigger was too broad
ChatGPT advised avoiding the link, checking Play Protect, inspecting recent apps and reviewing downloads. It separated conditions for stronger account action. It was also the only response to present external source links directly in the collected answer.
One item in its escalation list was simply using a banking app to transact or authenticate. The explanation immediately after the list concerned banking on a malware-infected device. Leaving that context out of the item could turn ordinary bank-app use into an emergency trigger. Tie it to suspected compromise or exposure.
The suggestion to watch transactions for “today” should not become a one-day all-clear rule. Likewise, its KISA-attributed statement about clicking alone should not be expanded into a universal guarantee against web attacks. Our final checklist uses separately checked Google and FTC guidance.
Opened a financial app to transact or authenticate. [Translated excerpt]
Gemini: clearing history is not a cure
Gemini organized downloads, scanning, browser-data deletion and Korean carrier-payment or identity-protection measures into four blocks. Each had a verification step, making the proposed actions easy to follow.
But one verification checked whether browsing history was gone, while the stated goal was complete removal of malicious scripts or tracking sessions. Chrome documentation [2] describes deletion of selected browser data. It does not make disappearance of history a substitute for inspecting apps or resolving an infection.
The extra financial prevention services also needed to be distinguished from urgent response to this particular click. In an English-language guide, Korean carrier billing controls and identity services are not universal instructions. In the US, the FTC reporting route in [3] is a relevant local option; bank contact should still use the bank’s own verified channel.
Delete all browsing history, cookies and cache to completely remove malicious scripts or tracking sessions from the opened page. [Translated excerpt]
Claude: the best permissions checklist, weakened by certainty
Claude explicitly separated installed apps from accessibility and device-administrator permissions. That addressed the question’s uncertainty about what had been allowed. Its expandable six-step presentation also made the procedure easier to scan.
Then it said an empty APK download list meant there had been no installation attempt. The present contents of one list cannot establish the complete history of the device. That conclusion also undermines the value of its own app and permission checks.
Its closing instruction to move on if nothing was found was too final. A better ending says that no findings do not justify an unnecessary reset, while retaining a response path for new warnings, unfamiliar apps or account activity.
If there is none, that means there was no installation attempt at all. [Translated excerpt]
The longest answer was ChatGPT’s
Excluding whitespace, the captured screen text contained 1,145 Korean characters for ChatGPT, 866 for Gemini and 744 for Claude. These counts include source labels and response controls, so they describe the captured experience rather than a perfectly isolated prose measure.
ChatGPT used its space for references and escalation conditions. Gemini repeated verification labels after its steps. Claude used a shorter checklist. For this particular scenario, WekeyLab AI would start from Claude’s structure, after correcting its claims about empty downloads and conclusive safety. This is a judgment about these responses, not a ranking of the services’ overall security capabilities.
WekeyLab AI: replace uncertain memory with checks
Do not reopen the link. Inspect installed apps, downloads and permissions without opening unfamiliar files. There is no reason to start by indiscriminately deleting the history that may help you understand what happened.
Google’s Android guidance [1] covers Play Protect, updates, untrusted apps and account checks, with further help or resetting if symptoms persist. Checking system and security updates was missing from all three responses, so it belongs in the revised plan.
Exposure of credentials, unfamiliar privileged apps or suspicious transactions changes the response. Where financial information is involved, use another trusted device and the institution’s verified contact details. Do not use the contact route in the suspicious text. The FTC gives the same official-contact principle [3].
A reset deletes data and requires preparation [4]. It should solve an identified problem, not serve as a reflexive answer to anxiety. Equally, a clean scan is not a certificate that nothing happened. Keep the action proportional to what the checks reveal.
WekeyLab AI’s revised advice A click alone is not a reason to start with a factory reset. Check installed apps, downloads and permissions, then use your device’s security checks and updates. If nothing suspicious appears, do not rush into wiping it. If unfamiliar apps, permissions, account warnings or transactions appear, use another trusted device to obtain official support and decide the next action.
Sources and actual records
September 12, 2026, 3 p.m. KST: one identical Korean prompt per service in a new conversation; no length or format limits and no follow-up. ChatGPT Free, Think off, displayed model unverified; Claude Free, Sonnet 5, Medium; Gemini Flash, subscription tier unverified. All six Claude steps were expanded. This English analysis translates the Korean test, not a separate English run. Excerpts are translated; expandable records preserve Korean screen text, including source buttons and other response controls. No malicious link was opened and no device was infected for this test.
[1] Google — Remove malware or unsafe software
[2] Google Chrome — Delete browsing data
[3] FTC — How To Recognize and Avoid Phishing Scams
[4] Google — Reset your Android device to factory settings
ChatGPT · 2026-09-12 15:00 KST session
택배 주소가 잘못됐다는 문자를 받고 링크를 눌렀어. 안드로이드 폰이고, 열린 페이지가 수상해서 바로 닫았어. 이름이나 카드번호, 비밀번호는 입력하지 않았고 앱을 설치하거나 권한을 허용한 기억도 없어. 지금 눈에 띄는 이상은 없는데 불안해. 폰을 바로 초기화하고 은행 비밀번호도 전부 바꿔야 할까? 지금 뭘 하면 좋을까? 우선 지금 설명해 준 상황이라면 휴대폰을 바로 초기화하거나 은행 비밀번호를 전부 바꿀 필요는 없어 보입니다. 특히 링크만 열었고, 개인정보·카드정보·비밀번호를 입력하지 않았으며, 앱 설치나 권한 허용도 하지 않았다면 위험도는 상당히 낮습니다. KISA도 “문자 속 URL을 클릭한 것만으로는 악성 앱에 감염되지 않으며, URL을 통해 앱을 설치한 경우”를 별도로 점검하도록 안내합니다. RISC +1 다만 10~15분 정도 점검은 해보는 것을 권합니다. 지금 바로 할 일 1. 그 문자와 링크를 다시 열지 마세요. 문자는 스팸 신고 후 삭제하세요. KISA는 보호나라의 스미싱·피싱 확인서비스나 스팸 신고 기능을 통한 확인·신고도 안내하고 있습니다. KISA Spam 2. Android의 Play 프로텍트 검사를 실행하세요. Google Play 스토어 → 오른쪽 위 프로필 사진 → Play 프로텍트 → 검사 Play 프로텍트는 설치된 앱을 검사하고 위험한 앱이나 URL을 탐지·차단하는 기능입니다. 구글 도움말 3. 최근 설치된 앱을 한번 확인하세요. 설정 → 앱 → 앱 목록에서 오늘/최근에 설치된 기억 없는 앱이 있는지 봅니다. 특히 이름이 이상하거나, 배송조회·보안·택배·금융기관처럼 위장한 앱이 있다면 일단 실행하지 마세요. 4. 브라우저의 다운로드 목록도 확인하세요. 링크를 누른 뒤 APK 같은 파일이 자동으로 다운로드됐을 가능성을 확인합니다. 다운로드된 파일이 있더라도 열거나 설치하지 말고 삭제하세요. 은행 비밀번호는? 현재 상황이라면 전부 바꿀 필요까지는 없습니다. 다만 다음 중 하나라도 있었다면 이야기가 달라집니다. 사이트에 아이디/비밀번호를 입력함 카드번호·계좌번호 등을 입력함 문자 인증번호를 입력함 APK/앱을 설치함 접근성, 기기 관리자, 알림 접근 등의 권한을 허용함 금융 앱을 열어 거래하거나 인증함 모르는 앱이 설치되어 있음 이 중 하나라도 있었다면 금융기관에 즉시 연락하고 비밀번호·인증수단을 별도로 조치하는 게 좋습니다. KISA도 악성 앱에 감염된 기기에서 금융서비스를 이용한 경우 금융 인증정보 등의 폐기·재발급을 권고합니다. RISC 초기화는? 지금 설명한 조건만으로는 초기화까지 할 필요가 없습니다. 오히려 초기화 전에 먼저 Play 프로텍트 검사 + 설치 앱 확인 + 다운로드 파일 확인을 하는 게 합리적입니다. 그리고 오늘 하루 정도는 은행 계좌·카드의 최근 거래와 휴대폰 소액결제 내역만 확인해 보세요. 이상 거래가 없다면 크게 걱정하지 않으셔도 됩니다. KISA도 스미싱 의심 상황에서 모바일 결제 내역 확인을 권고합니다. RISC 한 줄로 정리하면: 링크를 열었다는 사실만으로 휴대폰을 초기화하거나 은행 비밀번호를 전부 변경할 상황은 아닙니다. 앱 설치·정보 입력이 없었다면 Play 프로텍트 검사와 최근 앱 확인을 먼저 하세요. 혹시 그 문자의 내용이나 링크가 어떻게 생겼는지 캡처가 있다면, 개인정보가 보이지 않게 가리고 올려주셔도 됩니다. 어떤 유형의 스미싱인지 함께 확인해드릴 수 있어요.
Gemini · 2026-09-12 15:00 KST session
택배 주소가 잘못됐다는 문자를 받고 링크를 눌렀어. 안드로이드 폰이고, 열린 페이지가 수상해서 바로 닫았어. 이름이나 카드번호, 비밀번호는 입력하지 않았고 앱을 설치하거나 권한을 허용한 기억도 없어. 지금 눈에 띄는 이상은 없는데 불안해. 폰을 바로 초기화하고 은행 비밀번호도 전부 바꿔야 할까? 지금 뭘 하면 좋을까? 피싱/스미싱 문자 링크를 클릭한 직후라도 개인정보나 금융 정보를 직접 입력하지 않았고, 추가 앱(APK 파일)을 설치하거나 권한을 허용하지 않았다면 즉시 핸드폰을 초기화하거나 모든 금융 비밀번호를 변경할 필요는 없습니다. 단순 웹페이지 접속만으로 기기 주도권이 완전히 넘어가거나 백도어가 설치될 가능성은 상대적으로 낮기 때문입니다. 불안을 해소하고 혹시 모를 위험을 차단하기 위해 지금 바로 진행해야 할 대응 절차를 정리해 드립니다. 1 최근 다운로드 파일 확인 안전 점검 링크를 누르는 과정에서 본인도 모르게 악성 APK 파일이 다운로드되었을 수 있습니다. [내 파일] 앱을 열어 [다운로드] 폴더를 확인하고, 방금 다운로드된 모르는 파일(확장자 .apk)이 있다면 즉시 삭제하세요. 검증: 다운로드 폴더 내에 최근 생성된 수상한 .apk 파일이 없는지 확인합니다. 2 모바일 백신 정밀 검사 악성코드 검출 기본 제공되는 모바일 백신(삼성 스마트 매니저/기기 케어 내 시큐리티 검사) 또는 V3 Mobile Plus, 알약M 등의 백신 앱을 실행하여 정밀 검사를 진행하세요. 검증: 백신 앱 검사 결과에서 감염된 항목이 없는 "안전" 상태인지 확인합니다. 3 웹 브라우저 쿠키 및 캐시 삭제 세션 차단 열렸던 웹페이지의 악성 스크립트나 트래킹 세션을 완전히 제거하기 위해 브라우저(Chrome 등) 설정의 [개인정보 보호 및 보안]에서 방문 기록, 쿠키, 캐시 데이터를 모두 삭제하세요. 검증: 브라우저의 최근 방문 기록이 삭제되었는지 확인합니다. 4 소액결제 차단 및 명의도용 방지 서비스 신청 피해 예방 통신사 앱이나 고객센터를 통해 모바일 소액결제 한도를 차단하거나 최소화하세요. 추가로 한국정보통신진흥협회의 **명명의도용방지서비스(msafer.or.kr)**에 접속해 명의도용 개통 제한을 신청해 두면 안전합니다. 검증: 통신사 앱에서 소액결제 한도가 '차단' 또는 '최소 금액'으로 설정되었는지 확인합니다. 백신 검사 결과 이상이 없고, 이상 앱 설치나 권한 승인이 없었다면 현재 상태로 안심하고 사용하셔도 됩니다. 다만 향후 소액결제 내역이나 알 수 없는 인증번호 문자가 오는지 며칠간 주의 깊게 관찰해 주세요. 추가로 확인이 필요한 사항이 있으신가요? 악성 앱 설치 여부 확인법 보안 서비스 신청 방법
Claude · 2026-09-12 15:00 KST session
택배 주소가 잘못됐다는 문자를 받고 링크를 눌렀어. 안드로이드 폰이고, 열린 페이지가 수상해서 바로 닫았어. 이름이나 카드번호, 비밀번호는 입력하지 않았고 앱을 설치하거나 권한을 허용한 기억도 없어. 지금 눈에 띄는 이상은 없는데 불안해. 폰을 바로 초기화하고 은행 비밀번호도 전부 바꿔야 할까? 지금 뭘 하면 좋을까? 지금 상황이면 초기화까지 갈 필요는 없어 보여요. 정보 입력도 안 했고 앱 설치나 권한 허용도 없었다면, 실제 침해로 이어졌을 가능성은 낮습니다. 다만 확인 차원에서 아래 순서로 점검해보세요. 1 설치 앱 목록 확인 설정 > 앱에서 최근 설치 시각 기준으로 낯선 앱이 있는지 확인하세요. 특히 '알 수 없는 출처 설치' 권한이 켜져 있는지도 같이 확인합니다(보통 기본은 꺼져 있음). 2 접근성/기기 관리자 권한 확인 설정 > 접근성, 설정 > 보안 > 기기 관리자 앱 목록에 처음 보는 항목이 있는지 확인하세요. 스미싱 악성앱은 보통 이 권한을 노립니다. 없으면 안전한 신호입니다. 3 브라우저 기록·다운로드함 확인 클릭한 링크가 열렸던 브라우저의 다운로드 목록에 APK 파일이 자동으로 받아져 있는지 확인하세요. 있다면 삭제하고, 없다면 설치 시도 자체가 없었다는 뜻입니다. 4 백신 앱으로 검사 구글 플레이 프로텍트(플레이스토어 앱 > 프로필 > Play 프로텍트)로 검사를 1회 돌려보세요. 삼성 기기라면 스마트 매니저 보안 검사도 함께 돌릴 수 있습니다. 5 해당 문자·번호 신고 및 차단 문자를 스팸 신고하고 발신 번호를 차단하세요. 필요하면 '보이스피싱지킴이' 또는 118(한국인터넷진흥원)에 스미싱 신고도 가능합니다. 6 은행 앱은 평소처럼 확인만 카드번호·비밀번호를 입력한 적이 없으니 지금 당장 전체 비밀번호를 바꿀 필요는 없습니다. 다만 습관적으로 하던 대로 최근 거래 내역에 이상 거래가 없는지 한 번 훑어보는 정도면 충분합니다. 단계별로 보기 결론부터: 지금 상황만으로는 폰 초기화나 은행 비밀번호 전체 변경까지 갈 단계는 아니에요. 정보를 입력하지 않았고 설치·권한 허용 기억도 없다면 실제 피해로 이어졌을 가능성은 낮습니다. 위 6단계로 확인해보시고, 그래도 이상 앱이나 권한이 하나라도 발견되면 그때 초기화를 고려해도 늦지 않습니다. 만약 위 점검에서 아무것도 안 나온다면, 굳이 초기화까지 갈 필요 없이 그냥 넘어가셔도 됩니다.