Entered Your Password on a Phishing Page: Next Steps
Typed your password into a fake login page? Act in the next few minutes: change the password, sign out other sessions, check recovery details and forwarding rules. A step-by-step guide.

You realised a moment too late: the login page was fake, and you have typed your password into it. Do not panic, and do not wait. Phishing kits often send passwords to attackers instantly, so the next few minutes matter most.
Do this now
- Change the password on the real site, reached by typing the address or using the app. Make it new and unique.
- Sign out of all other sessions. Most services have a "sign out everywhere" or "devices" option. This kicks out anyone who already got in.
- Turn on or strengthen two-step verification, ideally with a passkey. See passkeys vs phishing.
- Check recovery details: recovery email, phone number and backup codes. Remove anything you do not recognise.
Then check for hidden changes
- Email forwarding and inbox rules that copy or hide your mail. See checking for forwarding rules.
- Connected apps you did not approve. See sessions and connected apps.
- Sent items: were messages sent to your contacts?
- Recent activity or security events in the account settings.
Entered card or bank details too? Call your bank or card issuer on the number on your card now and ask them to block the card.
If it was a work account
Tell your IT or security team straight away, even if you have already changed the password. They can check for access you cannot see. See why reporting quickly matters.
If you reused the password
Change it everywhere else it was used, starting with email and money accounts. A password manager makes unique passwords easy. See why password reuse is dangerous.
Already locked out? Follow recovering a hacked email account. And report the page so it can be taken down: see how to report phishing in our complete guide.
Frequently asked questions
Is changing my password enough?
Not always. Attackers may already be signed in, have added their own recovery details or set up forwarding rules. Sign out all sessions and check those too.
I also entered a two-step code. Does that change anything?
Yes. Assume the attacker has a signed-in session. Signing out all sessions after changing your password is essential.
I used the same password elsewhere. What now?
Change it on every account that used it, starting with email and banking, and use a different password for each.
Sources
- Recovering a hacked account, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Tips to complete account recovery steps, Google Account Help


