Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteIf you entered your Apple Account password or other personal information on a suspected phishing site, change your password immediately using a trusted Apple device or by typing account.apple.com into your browser. Do not return to the link. Then check account devices and recovery details, and secure any other information you submitted. Apple now calls Apple ID an Apple Account; existing users still sign in with the same email address or phone number and password. Apple’s phishing guidance recommends changing the password and ensuring two-factor authentication is enabled.
What to do right now
- Change your Apple Account password. On iPhone or iPad, go to Settings > [your name] > Sign-In & Security > Change Password. Use a trusted device already signed in, or type
account.apple.comyourself. Do not use the phishing link. Apple notes that Stolen Device Protection may require a one-hour wait before a password change. See Apple’s password-change instructions. - Turn on two-factor authentication if it is off. A new sign-in requires both your password and a six-digit verification code sent to a trusted device or phone number. Never give that code to a caller or message sender; Apple says its support staff will not ask for your password or verification codes. Apple’s scam guidance explains how to recognize these requests.
- Review devices and account details. Go to
account.apple.comor use a signed-in Apple device to check security and personal information. Remove devices you do not recognize, and make sure the account’s email addresses and phone numbers are still yours. Ask your mobile provider to check that unauthorized SMS forwarding has not been set up for an associated number. Apple’s compromised-account guidance and its personal-safety guide cover these checks. - Secure any other information you entered. If you reused that password on another site, change it there too, using that service’s official site or app. If you entered payment-card or bank details, contact the financial institution using the number on your card or its official app or site, monitor transactions, and follow its instructions.
- Report the phishing message if you can do so safely. Forward suspicious emails that appear to be from Apple to reportphishing@apple.com. For an Apple-lookalike SMS, Apple says to take a screenshot and email it to the same address. Do not click the link again to gather evidence. Apple’s guidance on identifying legitimate messages includes reporting instructions.
If you cannot sign in or change the password
Try Apple’s supported reset options rather than any recovery link in the message. Use a trusted Apple device if you have one. If you do not, Apple describes using a borrowed Apple device with the Apple Support app when you can access your trusted phone number, or starting at iforgot.apple.com. Web recovery may take longer. If you still cannot reset the password or sign in, start account recovery through Apple; a waiting period may apply, and Apple does not promise a fixed duration. Review Apple’s password-reset options and compromised-account steps.
When you regain access, check which Apple Account is signed in on your devices and other Apple services. Removing an unfamiliar device prevents it from displaying verification codes or accessing iCloud and other Apple services until it signs in again with two-factor authentication, according to Apple’s personal-safety guide.
What a submitted password does—and does not—tell you
Entering a password on a fake page puts the account at risk, but it does not by itself prove that someone successfully signed in or viewed your data. If an attacker gains account access, synced information such as Messages and location may be exposed. That is why checking the device list, account details, and recovery channels matters; do not assume either that data was accessed or that the account is safe without checking. Apple’s account-security guide describes the services and information connected to an Apple Account.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Reduce the chance of another account takeover
Keep two-factor authentication enabled and treat verification codes like passwords: enter them only into an Apple sign-in you initiated, never share them with someone who contacts you. For additional protection against targeted phishing, Apple recommends considering Security Keys for Apple Account. A physical key is an optional preventive measure, not a fix for a password already exposed; check Apple’s current setup requirements and preserve backup access before relying on keys. Apple’s security guide explains these protections.
For account changes, open Settings or type account.apple.com yourself. If you are unsure whether a message is genuine, do not use its links or phone numbers; go to Apple’s support site independently.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

