What to do now
I entered my password on a phishing site: what to do now
Last checked
On this page
Do this now
Change the password on the real site, now
Type the site’s address yourself or open its app, never the link from the message. Use a device you trust, or run a full antivirus scan on this one first. If you can no longer sign in, use the site’s own account recovery.If it was your bank, call it
If you typed your online banking or card details, call your bank’s fraud line now, on the number in its app, on its website or on your card.Change it everywhere you used it
Start with your email account, which can reset the others. A stolen password gets tried on other sites, a technique called credential stuffing. Give each account its own password; a password manager remembers them for you.Sign out other sessions and check the recovery details
In the account’s security settings, sign out every device and app you do not recognise, and check that the recovery email address and phone number are yours.Turn on two-step verification
With a second step, a stolen password is not enough on its own to sign in. Where the site offers a passkey, use it.For an email account, check forwarding rules
In the settings, look for forwarding addresses, filters or rules you did not create, and delete them. Setting up a forwarding rule is a common move by attackers.Warn your contacts if the account sent anything
If messages went out from the account, tell your contacts through another channel to ignore them.
On this page07
Check it with isMalicious
isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.
Password breach checker
Let a password manager generate the new password, so it is long and used nowhere else. If you still use the old one on other sites, the password breach checker shows whether it already circulates in breach lists. It is hashed in your browser and only the first five characters of its SHA-1 hash are sent.
- What it does not mean
- Not found does not make the old password safe to keep: you typed it on a phishing site, so change it whatever the check says. It is not a strength rating either.
URL scanner
Paste the address of the fake site into the URL scanner to see whether threat sources list it, then report it below.
- What it does not mean
- Not listed is not proof of safety: a new phishing page is often unlisted at first.
Report it
Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.
In the United States
IdentityTheft.gov (opens in a new tab)
If you gave personal or financial details: the steps for each kind of information you lost.
FTC, ReportFraud.ftc.gov (opens in a new tab)
Report the scam to the Federal Trade Commission, whether or not you lost money.
Anti-Phishing Working Group
The address the FTC gives for forwarding phishing emails.
In the United Kingdom
Report Fraud (opens in a new tab)
If you lost money or were hacked, in England, Wales or Northern Ireland: report online or by phone. It replaced Action Fraud in December 2025.
Police Scotland (opens in a new tab)
In Scotland, report fraud and cyber crime to Police Scotland.
NCSC: report a suspicious website (opens in a new tab)
Report a scam or phishing site.
NCSC Suspicious Email Reporting Service
Forward the suspicious email. The NCSC analyses it and the sites it links to.
Wherever you are
Google Safe Browsing (opens in a new tab)
Report the phishing page to Google.
Somewhere else? Report to your national police or your country’s cybercrime reporting service.
In France? The French version of this guide lists the French services.
How to spot the next one
- Your password manager does not offer to fill in the password. It fills passwords only on the site they were saved for, so a lookalike gets nothing.
- The address bar shows a domain you do not recognise, even if the page looks exactly like the real sign-in page.
- You reached the sign-in page from a link in a message rather than from the site or the app.
- The page asks for details the real site never asks for when you sign in, such as your card number.
Questions
I changed the password. Do I still need two-step verification?
Yes. The new password stops the stolen one from working; two-step verification means the next stolen password is not enough on its own. Sign out other sessions too, in case the attacker is already signed in.
Should I check whether my old password was in a data breach?
For this account, no: typing it on a phishing site is enough to treat it as compromised. Change it everywhere else you used it.
I can no longer sign in. What now?
Use the account recovery of the real site or app, which you open yourself, and report the hacked account to the service. Recovery is easier while the recovery email address and phone number are still yours.
What is a passkey, and should I use one?
A passkey signs you in with your device’s lock (a fingerprint, your face or a PIN) instead of a password, and it works only with the site it was created for. The UK’s NCSC calls passkeys resistant to phishing and recommends them over passwords wherever they are available.
Related guides
Close the page, then deal with what you typed, downloaded or allowed after the click.
A bluff sent in bulk: don’t pay or reply, change any password it quotes, report it.
Hang up, call back on a number you find yourself, and never read out a code.
Sources
The steps follow these official pages, read on :
- NCSCRecovering a hacked account (opens in a new tab)
- MicrosoftHow to recover a hacked or compromised Microsoft account (opens in a new tab)
- NCSCTop tips for staying secure online: managing your passwords (opens in a new tab)
- NCSCPasskeys: what you need to know (opens in a new tab)
- Cybermalveillance.
gouv. frPiratage de compte, que faire ? (opens in a new tab) (in French) - CNILLes conseils de la CNIL pour un bon mot de passe (opens in a new tab) (in French)
Free account
Keep checking with a free account
Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.
No credit card required