Online Security

When a Scam Succeeds: Responding After You've Been Phished

Person at laptop looking concerned after receiving a phishing alert on screen

Key Takeaways

  • Act within the first hour — speed is your biggest advantage after a phishing incident.
  • Change passwords on affected accounts immediately, starting with email and financial accounts.
  • Enable multi-factor authentication on every account you can access as a recovery step.
  • Report the incident to your bank, employer, and relevant consumer protection agencies.
  • Monitor your credit and financial statements closely for several weeks after the incident.
20–60 min
Intermediate

What you will need

Access to the email address or phone number linked to affected accounts (for password resets)
Your financial institution's customer service phone number
A secondary, uncompromised device if you suspect your primary device has malware installed
Basic understanding of how phishing works — see our consumer's complete starting point if you need a refresher

Why Your Response Speed Matters

Being phished is more common than most people realize — and it doesn't reflect a lack of intelligence or caution. As we explain in our guide on why informed users still fall for phishing, attackers have become skilled at replicating trusted brands and creating genuine-looking urgency. What matters now is how quickly and methodically you respond.

Stolen credentials can be sold, tested, or exploited within hours of a successful attack. The steps below are arranged in priority order so you can focus your effort where it counts most, even if you're feeling flustered. For tools and accounts you'll need to complete these steps, see the requirements below.

What you will need

Access to the email address or phone number linked to affected accounts (for password resets)
Your financial institution's customer service phone number
A secondary, uncompromised device if you suspect your primary device has malware installed
Basic understanding of how phishing works — see our consumer's complete starting point if you need a refresher
Required

Password Manager

Generates and securely stores unique passwords for every account you need to update after the incident.

Required

Multi-Factor Authentication (MFA) App

Adds a second verification layer so stolen passwords alone cannot grant access to your accounts.

Required

Antivirus / Malware Scanner

Scans your device for any malware that may have been installed when you clicked a malicious link.

Optional

Credit Monitoring Service

Alerts you to new credit inquiries or account openings that may indicate identity theft.

Act Immediately — Every Minute Counts

Phishing attackers often sell stolen credentials within hours of a successful attack. Do not wait to gather information or assess the situation before taking protective action. Disconnect from the compromised session, change passwords, and contact your financial institutions before doing anything else.

Step-by-Step Recovery Process

Follow these steps in sequence. If you are unsure which accounts were affected, treat any account tied to your compromised email address as potentially at risk.

1

Disconnect and Contain the Damage

If you clicked a suspicious link and suspect your device may be infected, disconnect it from the internet immediately — disable Wi-Fi and turn off mobile data. This limits an attacker's ability to communicate with any malware they may have installed. Do not close the browser tab or application yet; take a screenshot first so you have a record of what you encountered.

Tip: Use a different, trusted device to complete the remaining steps while your potentially compromised device is offline.
2

Change Passwords on Affected and Related Accounts

Start with your email account — it is often the master key to every other account through password-reset links. Then move to banking and financial accounts, then any site where you reused the same password. Use a strong, unique password for each account. If you are not sure where to begin, prioritize accounts in this order:

  1. Primary email
  2. Banking and credit card accounts
  3. Accounts linked to that email address
  4. Any account sharing the same password

Warning: Never reuse any password associated with a compromised account — attackers routinely test stolen credentials on other sites.
3

Enable Multi-Factor Authentication

After resetting passwords, activate multi-factor authentication (MFA) on every account that supports it. MFA requires a second form of verification — typically a code from an authenticator app or a text message — meaning stolen passwords alone are not enough to break in. An authenticator app is generally more secure than SMS-based codes, but either option is far better than a password alone.

Tip: Check your account's security settings under "Sign-in" or "Privacy" — most major platforms now offer MFA setup in just a few steps.
4

Scan Your Device for Malware

Reconnect your device to the internet only long enough to run a full scan using reputable security software. Phishing links sometimes deliver malware silently in the background, even if nothing obvious appeared on screen. Once the scan completes, follow the software's recommended steps to quarantine or remove any threats found before using the device normally again.

Warning: If your security software detects active malware and cannot remove it, consider professional support or a full factory reset of the device before reusing it for sensitive tasks.
5

Contact Your Financial Institutions

If you entered payment card details, banking credentials, or any financial information into a phishing site, call your bank or card issuer directly using the number on the back of your card. Request that they flag your account for suspicious activity, and ask whether a card replacement or account freeze is appropriate. Do this even if you haven't seen any unauthorized transactions yet — early notification gives institutions more tools to protect you.

Tip: Keep a note of the date, time, and name of the representative you speak with for your records.
6

Report the Phishing Attempt

Reporting the incident creates a record and helps protect others. In the US, you can report phishing to the Federal Trade Commission at ReportFraud.ftc.gov, and forward phishing emails to reportphishing@apwg.org (the Anti-Phishing Working Group). If the attack appeared to target your employer, notify your IT or security team immediately. If you shared personal identifying information, consider placing a fraud alert on your credit file with one of the three major credit bureaus — they are required to notify the others.

7

Monitor Accounts and Credit for Several Weeks

Attackers don't always act on stolen data right away. Check your bank and credit card statements every few days for at least four to six weeks after the incident. Review your credit report for new accounts or inquiries you don't recognize. If you notice anything suspicious, report it to your financial institution and the relevant credit bureau immediately.

Tip: You are entitled to a free credit report from each of the three major bureaus annually through AnnualCreditReport.com — this is a legitimate, federally authorized resource.

Don't Reuse Your Old Password

When resetting passwords after a phishing incident, never recycle any password that was previously associated with the compromised account. Attackers frequently attempt the same stolen credentials across multiple sites — a practice called credential stuffing. Choose a completely new, unique password for every account you update.

Use a Password Manager Going Forward

A password manager generates and stores strong, unique passwords for every account, removing the temptation to reuse passwords. This single habit significantly raises the bar for attackers attempting to use stolen credentials on other sites. Most reputable password managers also alert you when a stored password appears in a known data breach.

Strengthening Your Defenses After Recovery

Once the immediate crisis is addressed, use this experience as a reset point for your overall security habits. Review which passwords were weak or reused, and update any that remain at risk. Consider exploring the device protection practices that apply to your phone, tablet, and computer — many phishing attacks exploit device-level vulnerabilities alongside human ones.

For durable, everyday habits that reduce your exposure to future phishing attempts, our article on protective habits that actually hold up offers practical routines that don't require technical expertise. Recovery from a phishing incident isn't just about fixing what went wrong — it's an opportunity to build defenses that are genuinely harder to bypass.

This article is for informational purposes only. Steps recommended here are general guidance and may not cover every situation. Contact relevant institutions and authorities directly for advice specific to your circumstances.

Online Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Online Security Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.