Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Stop using the suspicious site: don’t click its links or enter information. A website behaving strangely may be compromised, but that alone does not prove your account or device was hacked. What to do next depends on whether you entered a password, payment details, or downloaded a file.

What should I do first if a website I use was hacked?

  1. Stop interacting with the site. Don’t click links, download files, or submit personal or payment information on the suspicious page. The UK National Cyber Security Centre (NCSC) gives the same advice for suspicious websites: don’t click links or enter information.
  2. Reach the service through a trusted route. Type its established web address yourself, use its official app, or find support details from a source you already trust. Don’t use a recovery link in an unexpected email or text. The US Federal Trade Commission (FTC) recommends contacting a company using a phone number or website known to be real: FTC phishing guidance.
  3. Decide what information, if any, you entered. If you only viewed the page, there is no automatic reason to assume your account or device is compromised. If you entered credentials or payment details, follow the relevant steps below.
  4. Report the suspicious site through the appropriate channel. Reporting options depend on your country and whether you’re reporting a suspicious website, fraud, or a crime. UK-specific routes are covered below.

Is it safe to log in if a website has been hijacked?

Not on the suspicious page. A familiar-looking address or login screen does not establish that the page is safe, especially if the site is redirecting, showing unauthorized content, or asking for information unexpectedly. Use the service’s known official address or app and check its official support instructions before signing in. If you cannot establish that you have reached the genuine service, wait and contact its support through a trusted channel.

What if I already entered my password?

Use the service’s official site or app—not a link from the suspicious page—to change the password. If you reused it on other services, change it there too, starting with important accounts such as email and financial services. The FTC recommends strong, unique passwords and two-factor authentication (2FA): protect your personal information.

  • End other sessions. Use the account’s sign-out option for all devices or sessions if available, then sign back in only on devices you trust.
  • Turn on 2FA. Choose an authenticator app or security key if the service supports one. The FTC says, “The more secure types of two-factor authentication are an authenticator app or a security key.” If neither is available, use the strongest option the service offers.
  • Check recovery settings. Confirm that recovery email addresses and phone numbers are yours. Remove unfamiliar methods and check for unexpected changes to account settings.
  • Secure your email account. Email can be used to reset passwords elsewhere. Review forwarding rules, sent and deleted messages, and recovery details for anything you don’t recognize. Change its password and sign out other sessions if you entered that password or see signs the account was altered.

A password manager can help create and store unique passwords; protect its master password and choose a service carefully. A compatible hardware security key is an optional sign-in hardening measure, not a way to undo a website compromise or recover an account. Check that your account and devices support the key and understand the account’s recovery process before relying on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What if I entered payment or personal information?

Payment details or unfamiliar transactions

If you entered card or bank details, or see a transaction you don’t recognize, contact your bank or payment provider promptly using its official app, website, or the number on your card or statement. Don’t use contact details displayed on the suspicious page. The UK NCSC also advises checking bank statements and online-store accounts and contacting the bank through official details: NCSC hacked-account guidance.

Personal information or suspected identity theft

If you believe personal information was exposed, use the official identity-theft or consumer-reporting service for your country. In the United States, the FTC directs people who suspect identity theft to IdentityTheft.gov. Reporting and notification requirements differ by jurisdiction and by the type of information involved.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Does a hijacked website mean my device has malware?

No. A site compromise by itself does not show that malware reached your device. If you downloaded a file or your device is behaving unusually, stop using it for banking, shopping, and password entry until it has been checked and restored. Don’t respond to unsolicited calls, pop-ups, or messages offering to clean it up: the FTC warns that supposed security software can itself be malware. See the FTC’s guidance on recognizing and avoiding malware.

How do I report a hacked or fake website?

Use the reporting service for your country; routes for reporting a suspicious site are not necessarily the same as routes for reporting a crime. In the UK, the NCSC accepts reports of suspicious websites, but says this is not a crime report. It directs crime victims in England, Wales, and Northern Ireland to Report Fraud, and victims in Scotland to Police Scotland. If you are elsewhere, check your national cyber-security or consumer-protection agency for the correct route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you own or operate the affected website

Prioritize containment and evidence preservation. Involve your incident-response team or trusted technical support, secure affected systems and accounts, and document what happened. Don’t destroy evidence that may be needed to investigate the incident. FTC business data-breach guidance recommends securing systems and credentials quickly while preserving forensic evidence.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Secure affected systems and credentials; change passwords known or suspected to be compromised.
  2. Work with qualified responders to investigate the cause and determine whether personal information was accessed or exposed.
  3. Assess notification duties for the jurisdictions and information involved. Consider applicable state law, the type of data, the likelihood of misuse, and potential harm; consult relevant legal, regulatory, and law-enforcement contacts for your circumstances.
  4. For recovery, follow the FTC’s small-business cybersecurity guidance: keep security updates current, maintain backups that are not connected to the network, disconnect devices suspected of malware, and keep customers informed during recovery.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.