Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you clicked a phishing link, stop interacting with it and assess what happened next. A click alone does not prove that an account or device is compromised. If you entered a password, shared financial or identity details, downloaded a file, or approved an app, take the matching steps below using the real service’s app or website—not links or contact details in the suspicious message.

Start with the affected account

  1. Stop using the message and link. Do not revisit the page, reply, or provide more information. Open the service’s known, genuine app or type its address yourself. If you need to call, use a number from a source you independently trust.
  2. Record what happened. Note what you clicked, entered, downloaded, or approved, when it happened, and which account or device was involved. Keep the message if it is safe to do so, but do not forward it or reopen the link just to collect evidence.
  3. Secure the account whose information was exposed. If you entered a password, change it immediately on the genuine service. Change it anywhere else you reused it, and use a different password for each account. Microsoft gives the same advice in its phishing guidance. A password manager can help you maintain unique credentials, but it is not a substitute for responding to an exposure.
  4. Turn on multifactor authentication (MFA). Choose an option the service supports, and make sure you know how to recover access if you lose the device or key.
  5. Review account access and recovery details. Check recent activity, recovery email addresses and phone numbers, signed-in devices, and connected apps. Sign out unfamiliar devices where the service allows it. If you cannot sign in, use the provider’s official account-recovery process.

Choose the response that matches what you did

You clicked, but entered nothing and downloaded nothing

Close the page and do not continue through the message. Check an account only by opening its known app or genuine website independently. A click by itself does not establish that your account or device was compromised. If a file may have downloaded, follow the malware steps below.

You entered a password or shared a work or school login

Change the exposed password promptly on the genuine service and anywhere you reused it, enable MFA, then review account activity, recovery details, devices, and connected apps. If it was a work or school account—or you used a work device—tell your organization’s IT or security team promptly and follow its incident process. A personal password change may not be the only action the organization needs.

You shared bank, card, or other financial information

Contact the bank or card issuer using a genuine phone number or website you already trust. Ask what protective measures fit the information exposed, check for unauthorized transactions, and report any fraud through the institution’s process. Do not use contact details in the suspicious message.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

You shared a Social Security number or other sensitive identity information

In the United States, use the FTC’s IdentityTheft.gov recovery resource for steps tailored to the information exposed. Outside the United States, use the appropriate official local identity-recovery service.

You downloaded an attachment or suspect malware

Update your security software and run a scan. The FTC recommends disconnecting a computer from the network if you believe it may be infected, and consulting a trusted security professional when needed. If you clicked a link but no file was downloaded, do not assume that malware was installed; assess what actually happened.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

You approved an unfamiliar app or permission

Open the account’s own security settings and review connected applications and permissions. Revoke access for anything you do not recognize. The FBI Internet Crime Complaint Center warned in September 2026 that malicious OAuth consent can give an app persistent access that may survive a password change. For that reason, changing the password alone may not remove an app’s access; review and revoke suspicious permissions or tokens through the provider’s controls.

You lost money or experienced identity theft

Report the incident to the relevant institution and official authorities. In the United States, the FTC directs consumers to ReportFraud.ftc.gov for phishing and IdentityTheft.gov for identity-theft recovery. Elsewhere, use the appropriate official service in your country.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

Report the phishing message

Use the email, messaging, or social platform’s built-in phishing-report feature when available, then delete the message if appropriate. Microsoft provides instructions for reporting phishing in Outlook and Teams, as well as suspicious messages in other email clients. You can also report phishing attempts to the FTC at ReportFraud.ftc.gov in the United States. Preserve useful details such as the time, account involved, and what information you shared, without reopening a suspicious link to gather them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What MFA can—and cannot—do

MFA adds a check beyond a password, but it does not replace reviewing account activity, confirming recovery details, or removing suspicious connected-app access. CISA describes phishing-resistant MFA as the most secure form of MFA and identifies physical security keys as one relevant option in its MFA guidance. Availability depends on the account and device: use a method the service supports, and consider recovery before relying on a device or key that could be lost.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.