PanicStation.org
uk Technology & digital loss

What to do if…
you realise you entered your password into a site that may have been fake

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Stop using that page. Go to the real website or app independently, change the password, and choose “sign out of all devices” if that option is offered. If your email account was involved, or the same password was reused there, secure the email account first.

Do not do these things

  • Don’t keep trying to log in on the suspicious page to test it.
  • Don’t click support links, pop-ups, adverts, or phone numbers shown on the suspicious site.
  • Don’t reuse the exposed password anywhere else.
  • Don’t post screenshots that show your email address, username, passwords, codes, or recovery details.
  • Don’t ignore it because nothing has happened yet; account changes can happen later.
  • Don’t call a bank, provider, or official body using a number from the suspicious page.

What to do now

  1. Close the suspicious page and stop interacting with it. Do not enter the password again, download anything, or reply through that page.

  2. Go to the real service safely. Open a new tab and type the address you know is correct, use a saved bookmark you already trust, or use the official app you already had installed. Avoid adverts and sponsored search results for this step.

  3. Change the password on the affected account.

    • Use a new, unique password, not a small change to the old one.
    • If the account offers it, choose “sign out of all devices”, “log out of other sessions”, or similar.
    • If you cannot log in, use the real service’s account recovery route from the official website or app.
  4. Secure your email account next if there is any chance it was involved. Change the email password if it was entered, reused, or could be used to reset the affected account. Turn on 2-step verification if available.

  5. Change the same password anywhere else you used it. Start with banking, payment accounts, shopping accounts, social media, messaging, cloud storage, and any account that can reset other accounts.

  6. Turn on 2-step verification where available. Prioritise your email account, the affected account, and any bank or payment account.

  7. Check for quick signs of account takeover.

    • Password reset emails you did not request.
    • New device, new location, or new session alerts.
    • Changes to recovery email, recovery phone number, or security questions.
    • New email forwarding rules, filters, auto-replies, or suspicious sent messages.
    • New payment details, delivery addresses, linked apps, or authorised devices.
  8. If anything looks changed, contact the provider through the real website or app. Use the help pages inside the official service you reached independently. Do not use contact details from the suspicious page or message.

  9. If this involved a work account, work device, or work message, tell your workplace IT or security contact. Give them the time, the account involved, and the suspicious link if you still have it.

  10. If you downloaded software, opened an attachment, or followed instructions to install anything, stop using that device for sensitive logins for now. Run your antivirus or security software if you have it, allow it to clean anything it finds, and consider using a different trusted device to change important passwords.

  11. Report the scam route.

  • If it came by email, forward it to [email protected].
  • If it came by text message, forward it to 7726.
  • If it was a suspicious website, report it through the NCSC suspicious website reporting page.
  1. If you entered bank or card details, or money has left your account, contact your bank or card provider immediately. Use the number on the back of your card, the official app, the official website, or 159 where appropriate. If you are in England, Wales or Northern Ireland, use Report Fraud. If you are in Scotland, report fraud to Police Scotland on 101, or call 999 in an emergency.

What can wait

  • You do not need to decide today whether to delete accounts, change phone numbers, or replace devices.
  • You do not need to do a full security overhaul of everything at once.
  • You can review password managers, old accounts, and wider clean-up later.
  • You can report extra background details later if you do not have them to hand now.

Important reassurance

Convincing fake login pages catch careful people, especially when they are busy or under pressure. Fast, simple steps now, especially changing reused passwords, securing email, enabling 2-step verification, and checking for changes, often reduce the risk of it escalating.

Scope note

These are first steps only to reduce immediate harm after a possible phishing login. If you discover confirmed account takeover, identity fraud, financial loss, or a work-related security incident, later decisions may need help from the service provider, your bank, workplace IT, police reporting routes, or another appropriate specialist.

Important note

This is general information, not legal, financial, technical, or professional advice. If you think an attacker has access to your accounts or you see financial loss, prioritise regaining control through the real provider or bank and use official reporting routes.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us