Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Change the exposed password immediately using the service’s official app or website—not a link in the suspicious message. Change it anywhere else you reused it, turn on two-factor authentication, and use the provider’s official recovery process if you can no longer sign in. Once you regain access, end other sessions and check for account changes. If you approved an app-permissions prompt, revoke suspicious app access as well; changing your password alone may not remove it.

What to do first

  1. Open the real service independently. Use its official app or type an address you already know. Do not return to the site through the phishing email, text, or message.
  2. Change the exposed password now. Choose a new, strong password you have not used on another account. The FTC advises changing the compromised account password and every other account where the same password was used. See the FTC’s guidance for people who were scammed.
  3. Turn on two-factor authentication (2FA). Use the account’s security settings to require a second factor in addition to the password. The FTC recommends enabling it after a scam, and CISA explains that MFA makes a stolen password alone less likely to be enough to sign in. See CISA’s MFA guidance.
  4. If you cannot sign in, start official account recovery. Find the provider’s recovery instructions independently, through its app or known website. Do not trust unsolicited callers or messages offering to recover the account for a fee.

After you regain access

Use the provider’s security settings to check for activity or changes you did not make. Provider menus vary, so follow the service’s current official instructions.

  • End other sessions. Sign out of all devices or sessions if the service offers that option. The FTC says this can kick out someone logged in on another device. See its guidance on recovering a hacked email or social-media account.
  • Check your recovery details. Make sure the recovery email address and phone number belong to you and that you can access them.
  • Review sign-ins and account changes. Look for unfamiliar devices, locations, security alerts, or changes to your settings. Google, for example, advises checking unfamiliar sign-in details and securing the account; its instructions explain that selecting “not me” signs the account out on other devices. See Google’s account security instructions.
  • If the compromised account is email, check forwarding rules and folders. Remove forwarding rules you did not create, and look for unfamiliar messages in Sent and Deleted.
  • If the account sent messages, warn affected contacts. Ask them not to click links or respond to unexpected requests for money from the account.

If you approved an app or permissions prompt

A phishing flow may send you to a real sign-in page and then ask you to approve a third-party app’s access. That is different from simply entering your password on a fake page: you may have granted the app permission to access account data or act on your behalf.

Open the account’s security settings, review connected apps or third-party access, and revoke any grant you do not recognize or did not intend to approve. The FBI’s Internet Crime Complaint Center says access granted this way can persist through a token and may not be revoked by changing the password. Its September 1, 2026 alert on consent phishing says immediate removal of the app through account security settings is necessary for remediation. This check applies when you approved an app or permissions prompt; entering a password by itself does not establish that you granted app access.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Report the incident and protect related accounts

  • Report the phishing attempt to the impersonated organization. Find its reporting channel independently, rather than using contact details in the suspicious message.
  • For work or school credentials, notify IT or security promptly. Your organization may need to protect connected systems and accounts.
  • In the United States, report scams to the FTC. The FTC accepts reports at ReportFraud.ftc.gov and says reports help it build cases, identify trends, and share information. For the consent-phishing campaign described in its September 1, 2026 alert, the FBI/IC3 asks victims to report to a local field office or IC3 and preserve screenshots.
  • If you entered bank or card details, contact the issuer immediately. Use the number on your card or the bank’s official app or website, and report any unauthorized activity. The FTC recommends contacting the issuer right away if a card was used without permission.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose stronger sign-in protection for next time

Enable the strongest MFA method the account supports and that you can reliably recover if a device or key is lost. CISA identifies FIDO/WebAuthn as the only widely available phishing-resistant authentication in its cited guidance and recommends MFA on important accounts; it also notes that any MFA is better than none. A compatible FIDO2/WebAuthn security key can help protect future sign-ins, but support varies by provider. It does not undo a password disclosure, end existing sessions, or revoke an app grant.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.