Skip to main content

What to do now

I entered my password on a phishing site: what to do now

Last checked

Treat the password as known to the attacker from the moment you typed it, and work through these steps in order. Each one takes a few minutes per account.

Do this now

  1. Change the password on the real site, now

    Type the site’s address yourself or open its app, never the link from the message. Use a device you trust, or run a full antivirus scan on this one first. If you can no longer sign in, use the site’s own account recovery.
  2. If it was your bank, call it

    If you typed your online banking or card details, call your bank’s fraud line now, on the number in its app, on its website or on your card.
  3. Change it everywhere you used it

    Start with your email account, which can reset the others. A stolen password gets tried on other sites, a technique called credential stuffing. Give each account its own password; a password manager remembers them for you.
  4. Sign out other sessions and check the recovery details

    In the account’s security settings, sign out every device and app you do not recognise, and check that the recovery email address and phone number are yours.
  5. Turn on two-step verification

    With a second step, a stolen password is not enough on its own to sign in. Where the site offers a passkey, use it.
  6. For an email account, check forwarding rules

    In the settings, look for forwarding addresses, filters or rules you did not create, and delete them. Setting up a forwarding rule is a common move by attackers.
  7. Warn your contacts if the account sent anything

    If messages went out from the account, tell your contacts through another channel to ignore them.
On this page07

Check it with isMalicious

isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.

Password breach checker

Let a password manager generate the new password, so it is long and used nowhere else. If you still use the old one on other sites, the password breach checker shows whether it already circulates in breach lists. It is hashed in your browser and only the first five characters of its SHA-1 hash are sent.

What it does not mean
Not found does not make the old password safe to keep: you typed it on a phishing site, so change it whatever the check says. It is not a strength rating either.

URL scanner

Paste the address of the fake site into the URL scanner to see whether threat sources list it, then report it below.

What it does not mean
Not listed is not proof of safety: a new phishing page is often unlisted at first.

Report it

Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.

In the United States

In the United Kingdom

Wherever you are

Somewhere else? Report to your national police or your country’s cybercrime reporting service.

In France? The French version of this guide lists the French services.

How to spot the next one

  • Your password manager does not offer to fill in the password. It fills passwords only on the site they were saved for, so a lookalike gets nothing.
  • The address bar shows a domain you do not recognise, even if the page looks exactly like the real sign-in page.
  • You reached the sign-in page from a link in a message rather than from the site or the app.
  • The page asks for details the real site never asks for when you sign in, such as your card number.

Questions

I changed the password. Do I still need two-step verification?

Yes. The new password stops the stolen one from working; two-step verification means the next stolen password is not enough on its own. Sign out other sessions too, in case the attacker is already signed in.

Should I check whether my old password was in a data breach?

For this account, no: typing it on a phishing site is enough to treat it as compromised. Change it everywhere else you used it.

I can no longer sign in. What now?

Use the account recovery of the real site or app, which you open yourself, and report the hacked account to the service. Recovery is easier while the recovery email address and phone number are still yours.

What is a passkey, and should I use one?

A passkey signs you in with your device’s lock (a fingerprint, your face or a PIN) instead of a password, and it works only with the site it was created for. The UK’s NCSC calls passkeys resistant to phishing and recommends them over passwords wherever they are available.

Sources

Free account

Keep checking with a free account

Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.

Create free account

No credit card required