What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you only replied and did not share sensitive information, click a link, open an attachment, or grant access to your device, that alone does not prove your account was compromised. Stop responding, work out exactly what you shared or did, and take the steps below that match the exposure. If you gave away a password, change it immediately through the account provider’s official site or app—and change it anywhere you reused it.

What do I do if I replied to a suspicious email?

Stop the exchange. Do not send more information, click another link, open an attachment, or call a number in the email. Avoid replying to the sender even to ask whether the message is genuine.

Make a quick record of the sender, time, what you shared, and what you clicked, opened, downloaded, or approved. Note any account names, passwords, codes, or account numbers you disclosed. This helps you choose the right response and gives your provider or IT team useful details.

If the email might be legitimate, contact the organization using a website address you already know or a phone number from a card, statement, or official website. The Federal Trade Commission (FTC) advises: “If the answer is “Yes,” contact the company using a phone number or website you know is real — not the information in the email.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2024, email was the top method scammers used to contact people, according to an FTC consumer alert published in April 2025. That figure describes FTC data for 2024; it does not mean every unexpected email is a scam or that replying proves an account was taken over. FTC: Protect yourself from phishing scams.

What should I do if I shared my password?

  1. Go to the account provider’s official website or app independently—use a saved bookmark or type a known address, not a link from the email.
  2. Change the exposed password right away. Microsoft Support advises: “Immediately change the passwords on all affected accounts, and anywhere else that you might use the same password.”
  3. Change that password anywhere else you reused it. Give each account a different password; a password manager can help you keep them unique.
  4. Turn on multifactor authentication (MFA), also called two-factor authentication, if the service offers it.
  5. If you cannot sign in, use the provider’s official account-recovery process. Do not trust recovery links sent by the suspicious sender.

Follow the provider’s current recovery instructions, because account menus and options differ. If you regain control after a takeover, sign out other devices where the service allows it, check recovery email addresses and phone numbers, review account settings for changes such as unfamiliar email-forwarding rules, and investigate sign-in alerts or activity you do not recognize. Changing a password does not necessarily invalidate every active session or authorization.

For account-specific guidance, see the FTC’s hacked-account recovery advice and Google’s guidance on security alerts.

What if I shared a code, financial information, or other personal data?

Respond according to what the message obtained. Use a known official contact route, not phone numbers or links in the email.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • One-time sign-in code or MFA approval: Treat this as a possible account-access incident. Contact the service through its official channel, secure the account, review active sessions and recovery details, and report unfamiliar activity. A password change by itself may not revoke every session or authorization; follow the provider’s recovery steps.
  • Bank or card details: Contact your bank or card issuer promptly using the number on your card or statement, or its official website. Report the disclosure and ask what protective steps are appropriate.
  • Social Security number or other identity information: Use IdentityTheft.gov for guidance based on what was exposed. FTC advice and recovery resources cited here are U.S.-specific.
  • Work or school credentials: Tell your organization’s IT or security team promptly. It can investigate its systems and apply its incident-response process. If a work device may have downloaded something, involve IT before attempting cleanup.
  • Money sent: Contact the payment provider or financial institution using a known official route and report the fraud to the FTC at ReportFraud.ftc.gov. Reporting does not guarantee that a payment can be recovered.

What if I clicked a link, opened an attachment, or gave device access?

A click without entering credentials is different from giving away a password, but a link or attachment could still lead to a harmful download. If a file may have downloaded, update your existing security software and run a scan. If the scan identifies a problem, follow the security software’s instructions to address it.

If you gave someone remote access to your computer or phone, update security software, scan the device, and remove identified problems. Then secure affected accounts by changing exposed passwords and enabling two-factor authentication. For a work-managed device, contact IT before trying to clean it yourself.

The FTC’s phishing guidance and scam-response guidance explain these steps. Neither a click nor a reply alone establishes that malware was installed or an account was compromised.

How do I report the suspicious email?

Use the email service’s built-in “Report phishing” or equivalent option when available. Reporting can help the provider identify suspicious messages; it does not replace securing an exposed account or contacting a bank.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Outlook: Microsoft’s instructions say to select Report > Report phishing. For other email clients, Microsoft asks users to submit the original message as an attachment to phish@office365.microsoft.com; its workflow requires the message headers, so do not simply forward it.
  • U.S. readers: The FTC says phishing email can be forwarded to reportphishing@apwg.org, and the attempt can be reported at ReportFraud.ftc.gov.

These routes apply to the named services and U.S. resources. For another provider or country, follow that provider’s current reporting instructions and your local government’s guidance. Microsoft’s phishing-response instructions and the FTC’s phishing advice provide further details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which next step fits what happened?

What happened First priority
You replied, but shared no sensitive information and did not click, open, or approve anything Stop responding, document the interaction, and report the message through your email provider.
You shared a password Change it through the official account route, change reused copies, and enable MFA.
You shared a one-time code or approved a sign-in Contact the account provider, secure the account, and review sessions and recovery details.
You shared financial information or sent money Contact the bank, card issuer, or payment provider through a known official route.
You shared identity information Use the appropriate identity-theft guidance; U.S. readers can start at IdentityTheft.gov.
You clicked, opened a file, or granted device access Update security software and scan; involve organizational IT for managed devices.

Provider recovery steps and reporting options can change. Use the service’s current official support instructions, and do not assume that changing a password alone revokes all access.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.