If you think you have been hacked, clicked a bad link, or entered personal information into a fake website, acting quickly can limit the damage. You do not need to be a computer expert. Work through the steps below one at a time.
First: What information did you give away?
Think about what you entered or what the attacker may have gained access to. This helps you decide which steps are most urgent.
- Password: Change that password immediately.
- Email address and password: Secure your email account first because it can often be used to reset passwords for other accounts.
- Credit or debit card: Contact the card issuer using the number printed on the card or its official app.
- Bank account information: Contact your bank immediately.
- Social Security number or other identity information: Take identity-theft precautions described below.
Step 1: Stop using the suspicious website
Close the suspicious page. Do not click additional buttons, call phone numbers shown in unexpected pop-ups, download anything else, or give the site more information.
If a file was downloaded, do not open it. If you already opened a suspicious file or installed something, disconnect the computer from Wi-Fi or unplug its network cable while you move to a trusted device for the next steps.
Step 2: Use a trusted device if possible
If you believe your computer or phone itself may be infected, use another device you trust to change important passwords. For example, use another computer, tablet, or phone that was not involved in the incident.
Step 3: Secure your email account first
Your email account is especially important because password-reset messages for many other accounts go there.
- Go directly to your email provider using its official app or by typing the website address yourself.
- Change your email password.
- Choose a new password that you have not used on another account.
- Turn on two-factor authentication or multi-factor authentication if it is available.
- Review recent sign-ins and sign out devices or sessions you do not recognize.
- Check that your recovery email address and phone number have not been changed.
Step 4: Change any password you exposed
If you typed a password into a suspicious website, assume someone else may now have it.
- Go directly to the real website or official app for that account.
- Change the password immediately.
- Do not reuse the old password.
- If you used that same password on other websites, change those passwords too.
- Turn on two-factor authentication wherever possible.
Important: Do not return to the link in the suspicious email or text to change the password. Find the real website yourself.
Step 5: Check your important accounts for changes
Look at your email, banking, shopping, social media, and other important accounts. Watch for things you did not do, such as:
- Passwords or recovery information being changed
- Unknown sign-ins or devices
- Messages you did not send
- Purchases or transfers you did not make
- New forwarding rules in your email
- New accounts or profiles you did not create
If the service offers a way to sign out of all devices, use it after changing your password.
Step 6: If you entered credit-card or bank information
Contact your bank or card company immediately using a trusted phone number, such as the number printed on the back of your card or listed in the institution's official app. Explain that your information may have been entered on a fraudulent website.
Ask what steps they recommend. Depending on what was exposed, they may block the card, replace it, watch the account for fraud, or help dispute unauthorized transactions.
Continue checking your statements and transaction alerts for activity you do not recognize.
Step 7: If you gave away your Social Security number or identity information
If highly sensitive identity information may have been exposed, visit the Federal Trade Commission's official identity-theft website at IdentityTheft.gov for a recovery plan.
You can also consider placing a credit freeze with Equifax, Experian, and TransUnion. A credit freeze can make it harder for someone to open a new credit account in your name. Use each credit bureau's official website rather than links from unexpected emails or texts.
Step 8: Scan the device if you downloaded or opened something
If you only entered information on a fake website, changing and securing the affected accounts may be the main priority. If you downloaded a file, opened an unexpected attachment, installed software, or allowed someone remote access to the device, check the device as well.
- Update the operating system and security software.
- Run a full scan using the security software already built into the device or another trusted security product.
- Remove anything the security scan identifies as malicious.
- If someone had remote access to the computer or you are unsure whether the device is safe, consider getting help from a reputable computer professional before using it for banking or other sensitive activity.
Step 9: Watch for follow-up scams
Scammers sometimes contact victims again pretending to be a bank, government agency, security company, or fraud-recovery service. Be suspicious of anyone who unexpectedly contacts you and asks for passwords, verification codes, payment, cryptocurrency, gift cards, or remote access to your computer.
If a bank or company contacts you about the incident, end the call or message and contact the organization yourself using a phone number or website you know is legitimate.
Step 10: Report the scam
In the United States, phishing and fraud can be reported to the Federal Trade Commission at ReportFraud.ftc.gov. Identity theft can be reported and managed through IdentityTheft.gov.
If money was stolen, contact the financial institution immediately. For significant financial loss or other serious crimes, you may also want to contact local law enforcement.
A simple priority checklist
If you are feeling overwhelmed, concentrate on these actions first:
- Secure your email account.
- Change any password you entered on the suspicious site.
- Turn on two-factor authentication.
- Call your bank or card issuer if financial information was exposed.
- Check important accounts for activity you do not recognize.
- Protect your identity if sensitive identity information was exposed.
- Scan the device if you downloaded or installed anything suspicious.
The Know Phishing takeaway
Speed matters after a phishing attack, but you do not need to fix everything at once. Start with your email account and any exposed passwords, then protect financial and identity information. Always reach companies through their official apps, websites, or trusted phone numbers rather than links and numbers supplied by the suspicious message.