Blog/Phishing

Entered Your Password on a Phishing Page: Next Steps

Typed your password into a fake login page? Act in the next few minutes: change the password, sign out other sessions, check recovery details and forwarding rules. A step-by-step guide.

CyberWatch AI2 October 2026 · 2 min read
A worried person with their head in their hands at a laptop

You realised a moment too late: the login page was fake, and you have typed your password into it. Do not panic, and do not wait. Phishing kits often send passwords to attackers instantly, so the next few minutes matter most.

Do this now

  1. Change the password on the real site, reached by typing the address or using the app. Make it new and unique.
  2. Sign out of all other sessions. Most services have a "sign out everywhere" or "devices" option. This kicks out anyone who already got in.
  3. Turn on or strengthen two-step verification, ideally with a passkey. See passkeys vs phishing.
  4. Check recovery details: recovery email, phone number and backup codes. Remove anything you do not recognise.

Then check for hidden changes

Entered card or bank details too? Call your bank or card issuer on the number on your card now and ask them to block the card.

If it was a work account

Tell your IT or security team straight away, even if you have already changed the password. They can check for access you cannot see. See why reporting quickly matters.

If you reused the password

Change it everywhere else it was used, starting with email and money accounts. A password manager makes unique passwords easy. See why password reuse is dangerous.

Already locked out? Follow recovering a hacked email account. And report the page so it can be taken down: see how to report phishing in our complete guide.

Frequently asked questions

Is changing my password enough?

Not always. Attackers may already be signed in, have added their own recovery details or set up forwarding rules. Sign out all sessions and check those too.

I also entered a two-step code. Does that change anything?

Yes. Assume the attacker has a signed-in session. Signing out all sessions after changing your password is essential.

I used the same password elsewhere. What now?

Change it on every account that used it, starting with email and banking, and use a different password for each.

Sources

  1. Recovering a hacked account, UK National Cyber Security Centre
  2. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  3. Tips to complete account recovery steps, Google Account Help
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.