🚨 What to Do Immediately After a Phishing Attack
On this page
If you think you have entered your credentials on a phishing site, act immediately. Speed matters — attackers often automate credential validation within seconds of receiving them. In many cases, phishing kits forward captured credentials to the attacker in real time, and automated scripts begin testing them against other services within minutes. The difference between containing the damage and suffering a full account takeover often comes down to how quickly you respond.
This guide walks through the six most critical steps to take in the first 30 minutes after realising you have fallen for a phishing attack. Follow them in order, and do not skip any — attackers move fast, and your response needs to be methodical.
Why Speed Matters in Phishing Response
Phishing attacks are rarely manual operations. Modern phishing-as-a-service platforms automate the entire credential theft pipeline. When you type your username and password into a fake login page, that information is immediately sent to a command-and-control server. Within seconds, automated scripts begin validating the credentials against the real service. If they work, the attacker's tools immediately begin exploring what they can access — email, cloud storage, connected services, saved payment methods.
Attackers know that many victims do not realise they have been phished until hours or days later. The window for effective response is therefore very narrow. According to incident response research, the average time between credential theft and attacker action can be as little as 12 minutes. By acting within the first half-hour, you dramatically reduce the attacker's opportunity to cause real damage.
Another reason speed matters is session hijacking. Even if you change your password later, an attacker who has already established an active session on the legitimate service can maintain access through session cookies or OAuth tokens. That is why simply changing the password is not enough — you must also revoke all active sessions, which we cover in Step 2.
Step 1: Change the Password Immediately
Navigate directly to the real website — do not click any links, do not use the tab you may still have open — and change your password. Type the URL manually into your browser's address bar or use a trusted bookmark. This is critical because the phishing site or a persistent redirect may still be active in your browser.
When creating a new password, use a randomly generated password that is at least 16 characters long and contains a mix of uppercase letters, lowercase letters, numbers, and symbols. Do not try to invent a password yourself — use a password manager's built-in generator. The password you are replacing was compromised, so the new one must be completely different, not just a minor variation.
If the account uses a recovery email or phone number for password reset, make sure you still have access to those before changing the password. If the attacker has already changed your recovery details, you may need to use the service's account recovery process or contact their support team directly.
Step 2: Revoke All Active Sessions
After changing your password, immediately go to the account's Security Settings and sign out of all devices. Most major services — Google, Microsoft, Facebook, Apple, and others — offer a "sign out of all other sessions" or "revoke all tokens" option. This forces any attacker who logged in before the password change to re-authenticate with the new credentials they do not have.
This step is essential because a changed password only prevents new logins. Any session tokens or cookies that the attacker stole during the initial compromise remain valid until explicitly revoked. Session tokens can persist for days or even weeks, giving the attacker continued access even after you think the account is secured.
After revoking sessions, check the list of recently active sessions or login history. Most services show the device type, browser, IP address, and approximate location for each active session. Look for anything unfamiliar — a session from a different country, an unknown browser, or a device you do not own. This information can help you understand the scope of the compromise.
Step 3: Check and Restore Account Recovery Details
Once an attacker has access to your account, one of the first things they will do is change the recovery email address, phone number, and security questions associated with the account. This locks you out and ensures they retain control even after you realise what happened. Verify immediately that your recovery email and phone number have not been altered.
If the attacker has changed these details, most services allow you to revert the change through an email or SMS notification that was sent when the change was made. Check your email inbox (including spam/junk folders) for any messages from the service about changes to your account settings. If you cannot revert the changes yourself, contact the service's support team immediately — explain that your account was compromised and provide any identity verification information they request.
Also check for any newly added recovery methods you did not set up. Attackers sometimes add their own email address or phone number alongside or instead of yours, creating a backdoor they can use later even after you lock them out.
Step 4: Enable or Rotate MFA
If you did not have multi-factor authentication (MFA) enabled on the compromised account before the phishing attack, enable it now. If MFA was already active, assume the attacker may have captured your MFA session tokens or backup codes during the compromise and rotate everything — generate new authenticator app codes, invalidate old backup codes, and if you use SMS-based MFA, consider switching to an authenticator app or hardware security key.
MFA adds a second layer of security that a password alone cannot bypass. Even if the attacker captures your new password later, they will still need the second factor — typically a time-based code from your phone, a push notification approval, or a physical security key — to access the account. For accounts that support it, use a hardware security key (FIDO2/WebAuthn) as your second factor, as these are resistant to phishing attacks.
It is worth noting that SMS-based MFA, while better than nothing, is vulnerable to SIM-swapping attacks. If you can, use an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy instead. Many password managers, including NordPass, also offer built-in TOTP (time-based one-time password) support, allowing you to manage both passwords and two-factor codes in one place.
Step 5: Run a Full Malware Scan
Some phishing attacks are part of a broader infection chain. The phishing email may have contained a malicious attachment that dropped a keylogger, a remote access trojan (RAT), or credential-stealing malware onto your device. Even if you only entered your password on a fake page, it is possible that the attack planted malware that will continue to steal credentials from your device in the future.
Run a full system scan using a reputable antivirus or anti-malware solution. If you have more than one device — and many people do after being phished on a desktop, then checking compromised accounts on their phone — scan all of them. Make sure your antivirus definitions are up to date before running the scan.
In addition to standard antivirus software, consider running a second opinion scanner like Malwarebytes to catch anything your primary antivirus might miss. If the scan finds malware, follow the recommended removal steps and change any passwords entered on that device again after the malware has been removed.
Step 6: Check Other Accounts
If you reused the compromised password anywhere else — even on a single other account — those accounts are now at risk too. Attackers who phish one credential will almost always try that same email and password combination against other popular services. This is known as credential stuffing, and it happens automatically within minutes of a successful phishing capture.
Make a list of every account where you used the same or a similar password. Change each one to a new, unique, randomly generated password. This is the most important long-term security habit you can adopt: never reuse passwords across different accounts. Using a password manager like NordPass makes it easy to generate and store unique, strong passwords for every account so a single compromise never cascades into a full identity takeover.
If you use the same password for your email account as you did for the compromised account, treat your email as compromised too — change its password immediately and check for any forwarding rules the attacker may have set up to secretly receive copies of your future emails. Email accounts are the most valuable target because they are used for password resets on every other service.
Preventing Future Phishing Attacks
Once you have contained the immediate damage, it is worth taking steps to reduce the likelihood of being phished again. Enable phishing protection features where available — many password managers include domain-matching checks that warn you when the site you are logging into does not match the stored domain. Use browser extensions that flag known phishing sites. And most importantly, cultivate a habit of scepticism: pause before clicking links in emails, inspect URLs carefully, and navigate to websites directly rather than relying on links sent to you.
Consider using a dedicated email alias service for less important accounts, so your primary email address is less widely distributed and therefore less likely to be targeted by phishing campaigns. And if you have not already, adopt a password manager as your central credential hub — it generates strong passwords, stores them securely, autofills them only on the correct domains, and makes it trivial to use unique credentials everywhere.
Conclusion
Falling for a phishing attack is something that happens to experienced security professionals too. The key is not to panic — it is to act methodically and quickly. Change the compromised password, revoke all sessions, secure your recovery details, enable or rotate MFA, scan for malware, and check every account that shares the compromised credential. Following this six-step protocol in the first 30 minutes gives you the best chance of containing the damage and preventing the attacker from gaining a foothold in your digital life.
And once the immediate crisis is over, take the lesson to heart: unique passwords for every account, managed through a reliable password manager, are the single most effective defence against credential theft. They ensure that even if one account is compromised, the damage stops there.