Online Security

Warning Signs Your Online Account Has Been Targeted by Phishing

Laptop screen displaying a suspicious phishing email with warning indicators highlighted

Key Takeaways

  • Unsolicited password reset emails are one of the most reliable early signs of a phishing attempt.
  • Login activity from unfamiliar locations or devices often means someone else is testing your credentials.
  • Missing emails or altered account settings can indicate an attacker has already gained partial access.
  • Enabling multi-factor authentication significantly reduces the damage a phishing attack can cause.
  • Acting within minutes of spotting a warning sign dramatically improves your chances of protecting the account.
15–30 min

Summary

18 items · 15–30 minutes

Why Phishing Targets Your Accounts — Not Just Your Inbox

Phishing is not simply about tricking you into clicking a bad link. The real goal is almost always account access — your email, banking, social media, or cloud storage. Once an attacker controls even one account, they can pivot to others, intercept verification codes, and lock you out entirely.

The good news is that phishing attempts leave traces. Most targeted accounts show recognizable warning signs before a full compromise occurs. This checklist helps you identify those signals quickly and take the right steps before damage is done.

To understand why these signs appear in the first place, see our article on how attackers actually steal passwords. If you believe you've already been caught out, jump ahead to steps to take after being phished.

Don't Click to Investigate a Suspicious Email

If you receive a message that looks like a phishing attempt, go directly to the service's official website by typing the address into your browser — never click links within the suspicious email. Even hovering over a link can sometimes trigger tracking scripts. Report the message as phishing through your email client rather than replying or unsubscribing.

How to Use This Checklist

Work through each group below whenever you receive a suspicious message, notice something unexpected in your account, or just want a routine security audit. Items marked must require immediate attention. Items marked should are strongly recommended as part of any response. Nice-to-have items strengthen your defenses going forward.

You don't need to complete every group in one sitting, but if you trigger multiple warning signs in the Account Activity Red Flags group, treat it as urgent and work through the Immediate Response group right away.

For broader context on why even careful users get caught, read reasons people fall for phishing even when they know better.

Suspicious Message Signs

Check whether you received a password reset email you did not request — this is a strong indicator someone is attempting to access your account. Must
Look for emails claiming to be from a service you use that ask you to verify your identity or click a link urgently. Must
Inspect the sender's actual email address (not just the display name) for subtle misspellings or unfamiliar domains. Must
Note whether the message uses a generic greeting like "Dear User" rather than your actual name. Should
Look for mismatched URLs by hovering over any links before clicking — the displayed text and actual destination should match. Must

Account Activity Red Flags

Review your account's login history for sign-ins from unfamiliar cities, countries, or devices. Must
Check whether your account's recovery email address or phone number has been changed without your knowledge. Must
Look for emails missing from your inbox or sent folder that you did not delete — attackers sometimes delete evidence of access. Must
Check whether forwarding rules have been added to your email account that you did not set up. Must
Review connected third-party apps or OAuth permissions for unfamiliar applications that have been granted access. Should

Immediate Response Steps

Change your account password immediately using a strong, unique passphrase not used on any other service. Must
Enable multi-factor authentication (MFA) on the account if it is not already active — this requires a second proof of identity beyond your password. Must
Terminate all active sessions from the account's security settings to log out any unauthorized users. Must
Alert your contacts if your email or social media was accessed, since attackers may have sent phishing messages on your behalf. Should

Ongoing Hardening

Set up login alerts or notifications so you are informed whenever a new device signs into your account. Should
Use a password manager to ensure all your accounts have distinct, strong passwords that are not repeated. Should
Check whether your email address appears in known data breach databases using a reputable breach-notification service. Should
Review security questions linked to your accounts and replace obvious or guessable answers with randomized strings stored in your password manager. Nice to have

Tools That Support Your Response

You don't need specialized software to work through this checklist, but a few resources make it significantly faster and more effective.

Required

Have I Been Pwned (haveibeenpwned.com)

Check whether your email address has appeared in publicly known data breaches, which often precede targeted phishing.

Required

Password Manager

Generate and store unique, strong passwords for every account so a single compromised credential cannot unlock others.

Required

Authenticator App

Provide time-based one-time codes for multi-factor authentication, making account access significantly harder for attackers.

Required

Email Client Security Settings

Review login history, connected apps, and forwarding rules directly within your email provider's security dashboard.

Act Immediately if Multiple Signs Are Present

If you identify two or more warning signs — for example, an unexpected password reset email combined with unfamiliar login activity — treat it as an active incident, not a precaution. Change your password, enable MFA, and end all sessions before doing anything else. Delays of even a few hours can give attackers enough time to lock you out permanently or harvest sensitive information. See our guide on signs your password has been compromised for a focused response checklist.

For guidance on locking down your passwords as part of your response, visit our Password Safety hub. If you're also concerned about threats to your home or mobile network, the Network Security hub covers those risks in detail.

Online Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Online Security Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.