What to do if…
you realise you entered your password into a site that may have been fake
Short answer
Stop using the page, open the real site or app by a trusted route, and change the affected password now. If the same password was used for your email, or the account receives password resets for other services, protect that email account next.
Do not do these things
- Don’t enter the password again to check whether the site works.
- Don’t call phone numbers or use chat boxes shown on the suspicious page.
- Don’t wait for a warning email before changing the password.
- Don’t reuse that password anywhere else.
- Don’t share screenshots that show your email address, username, password field, recovery details, or verification codes.
What to do now
- Close the suspicious page. Do not click any more buttons, links, pop-ups, chat boxes, or downloads on it.
- Open the real service safely. Use the official app you already had installed, a saved bookmark you trust, or type the service’s address yourself in a fresh browser tab. Avoid sponsored search results and ads for this step.
- Change the password for the affected account.
- Make it new and unique, not a small change to the old password.
- If the service offers it, choose “sign out of all devices”, “log out other sessions”, or similar.
- Protect your email account if it may be affected. Change the email password if the same or a similar password was used there, or if that email receives password reset messages for the affected service.
- Change reused passwords next, highest risk first.
- Banking, payment, shopping, work, school, social media, messaging, and cloud storage accounts matter most.
- Use a different unique password for each account.
- Turn on multi-factor authentication. Do this for the affected account and your email account. If you have a choice, an authenticator app or security key is generally stronger than text-message codes.
- Check for signs that the account was changed.
- Password reset emails you did not request.
- New login or device alerts.
- Changed recovery email, recovery phone number, or security questions.
- In email: forwarding rules, filters, unexpected sent messages, or deleted messages you do not recognise.
- In banking or shopping accounts: new payment methods, new delivery addresses, or orders you did not make.
- If you are locked out or anything has changed, use the provider’s official recovery route. Reach it through the real app or a typed web address, not through links or phone numbers from the suspicious page.
- If this was a work or school account, tell your IT, helpdesk, or security contact. They may need to reset access, revoke sessions, or check for misuse.
- If money, card details, banking details, or sensitive personal information were involved, act through the relevant official route.
- Contact your bank or card issuer using the number on your card, statement, app, or official website.
- Report scams to the FTC through ReportFraud.ftc.gov.
- Use IdentityTheft.gov if your Social Security number or other identity information may have been misused.
- For internet crime, especially if money was lost or an account was misused, IC3 is an official FBI reporting route.
What can wait
- You do not need to decide now about deleting accounts, changing your phone number, replacing your device, or buying security products.
- You do not need to reset every password you have ever had unless it reused the same or a very similar password.
- You can deal with longer-term identity or credit precautions after the affected accounts and reused passwords are under control.
Important reassurance
Fake login pages can look very convincing, and being caught by one does not mean you were careless. Changing the password, signing out other sessions, turning on multi-factor authentication, and checking account settings can reduce the chance of further harm.
Scope note
These are first steps for the minutes and hours after a suspected phishing login. Later decisions may need help from the account provider, your bank, your workplace or school, or an appropriate specialist support route.
Important note
This is general information, not legal, financial, cybersecurity, or other professional advice. If you see unauthorized access, account changes, transactions, or identity misuse, prioritize account control and contact the relevant provider, bank, or official reporting service promptly.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.