Key Takeaways
- Act within the first hour — speed is your biggest advantage after a phishing incident.
- Change passwords on affected accounts immediately, starting with email and financial accounts.
- Enable multi-factor authentication on every account you can access as a recovery step.
- Report the incident to your bank, employer, and relevant consumer protection agencies.
- Monitor your credit and financial statements closely for several weeks after the incident.
What you will need
Why Your Response Speed Matters
Being phished is more common than most people realize — and it doesn't reflect a lack of intelligence or caution. As we explain in our guide on why informed users still fall for phishing, attackers have become skilled at replicating trusted brands and creating genuine-looking urgency. What matters now is how quickly and methodically you respond.
Stolen credentials can be sold, tested, or exploited within hours of a successful attack. The steps below are arranged in priority order so you can focus your effort where it counts most, even if you're feeling flustered. For tools and accounts you'll need to complete these steps, see the requirements below.
What you will need
Password Manager
Generates and securely stores unique passwords for every account you need to update after the incident.
Multi-Factor Authentication (MFA) App
Adds a second verification layer so stolen passwords alone cannot grant access to your accounts.
Antivirus / Malware Scanner
Scans your device for any malware that may have been installed when you clicked a malicious link.
Credit Monitoring Service
Alerts you to new credit inquiries or account openings that may indicate identity theft.
Act Immediately — Every Minute Counts
Phishing attackers often sell stolen credentials within hours of a successful attack. Do not wait to gather information or assess the situation before taking protective action. Disconnect from the compromised session, change passwords, and contact your financial institutions before doing anything else.
Step-by-Step Recovery Process
Follow these steps in sequence. If you are unsure which accounts were affected, treat any account tied to your compromised email address as potentially at risk.
Disconnect and Contain the Damage
If you clicked a suspicious link and suspect your device may be infected, disconnect it from the internet immediately — disable Wi-Fi and turn off mobile data. This limits an attacker's ability to communicate with any malware they may have installed. Do not close the browser tab or application yet; take a screenshot first so you have a record of what you encountered.
Change Passwords on Affected and Related Accounts
Start with your email account — it is often the master key to every other account through password-reset links. Then move to banking and financial accounts, then any site where you reused the same password. Use a strong, unique password for each account. If you are not sure where to begin, prioritize accounts in this order:
- Primary email
- Banking and credit card accounts
- Accounts linked to that email address
- Any account sharing the same password
Enable Multi-Factor Authentication
After resetting passwords, activate multi-factor authentication (MFA) on every account that supports it. MFA requires a second form of verification — typically a code from an authenticator app or a text message — meaning stolen passwords alone are not enough to break in. An authenticator app is generally more secure than SMS-based codes, but either option is far better than a password alone.
Scan Your Device for Malware
Reconnect your device to the internet only long enough to run a full scan using reputable security software. Phishing links sometimes deliver malware silently in the background, even if nothing obvious appeared on screen. Once the scan completes, follow the software's recommended steps to quarantine or remove any threats found before using the device normally again.
Contact Your Financial Institutions
If you entered payment card details, banking credentials, or any financial information into a phishing site, call your bank or card issuer directly using the number on the back of your card. Request that they flag your account for suspicious activity, and ask whether a card replacement or account freeze is appropriate. Do this even if you haven't seen any unauthorized transactions yet — early notification gives institutions more tools to protect you.
Report the Phishing Attempt
Reporting the incident creates a record and helps protect others. In the US, you can report phishing to the Federal Trade Commission at ReportFraud.ftc.gov, and forward phishing emails to reportphishing@apwg.org (the Anti-Phishing Working Group). If the attack appeared to target your employer, notify your IT or security team immediately. If you shared personal identifying information, consider placing a fraud alert on your credit file with one of the three major credit bureaus — they are required to notify the others.
Monitor Accounts and Credit for Several Weeks
Attackers don't always act on stolen data right away. Check your bank and credit card statements every few days for at least four to six weeks after the incident. Review your credit report for new accounts or inquiries you don't recognize. If you notice anything suspicious, report it to your financial institution and the relevant credit bureau immediately.
Don't Reuse Your Old Password
When resetting passwords after a phishing incident, never recycle any password that was previously associated with the compromised account. Attackers frequently attempt the same stolen credentials across multiple sites — a practice called credential stuffing. Choose a completely new, unique password for every account you update.
Use a Password Manager Going Forward
A password manager generates and stores strong, unique passwords for every account, removing the temptation to reuse passwords. This single habit significantly raises the bar for attackers attempting to use stolen credentials on other sites. Most reputable password managers also alert you when a stored password appears in a known data breach.
Strengthening Your Defenses After Recovery
Once the immediate crisis is addressed, use this experience as a reset point for your overall security habits. Review which passwords were weak or reused, and update any that remain at risk. Consider exploring the device protection practices that apply to your phone, tablet, and computer — many phishing attacks exploit device-level vulnerabilities alongside human ones.
For durable, everyday habits that reduce your exposure to future phishing attempts, our article on protective habits that actually hold up offers practical routines that don't require technical expertise. Recovery from a phishing incident isn't just about fixing what went wrong — it's an opportunity to build defenses that are genuinely harder to bypass.
This article is for informational purposes only. Steps recommended here are general guidance and may not cover every situation. Contact relevant institutions and authorities directly for advice specific to your circumstances.
