Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Clicked a phishing link and entered your details? A first-hour response plan

Opening a page, entering a password, sharing card details and installing software require different responses. This plan helps you prioritize without panic.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
16 September 2026
READING TIME
12 min read
TOPIC
Human Security
Clicked a phishing link and entered your details? A first-hour response plan

The link looked like your bank, email provider, courier or Microsoft 365. You only noticed the strange domain after entering your details. Perhaps you approved a prompt on your phone, opened an attachment or installed software recommended by a “support agent.” At that moment, it is easy to do two things at once: panic and spend time on actions that do not match what actually happened.

The most useful question is not “did I click?” but “what did I disclose or run?” Merely opening a page, entering a password, sharing card details, approving a sign-in and granting remote access are different incidents. The first hour should limit further access, protect money and preserve the evidence needed for reporting.

Start by naming the event

Before changing everything in sight, write down what you actually did. Use paper or another trusted device:

What happenedMost urgent action
You only opened a page, downloaded nothing and entered nothingClose it, update the browser and preserve the address for reporting
You entered a username and passwordChange the password on the real site and end unfamiliar sessions
You shared a one-time code or approved a sign-inTreat the account as compromised; review devices, recovery methods and active sessions
You provided card details or approved a paymentContact your bank immediately through an official channel
You downloaded a file, app or extensionStop using that device for sign-ins and have it checked
You shared your screen or remote desktopEnd remote access, disconnect the device and contact your bank or IT from another device
You disclosed a national ID or identity-document detailsProtect your identity and monitor attempts to use the information

This distinction avoids both underreacting and needlessly resetting your entire digital life. If you do not know whether the page downloaded something or what you approved, follow the more cautious path and ask for help.

Minutes 0–10: close the easiest route in

If you disclosed a password, do not return to the account through the message link. Open a new tab and type the service address you already know, or use its official app. Prefer another trusted device, especially if you installed anything on the first one.

Start with your email account if its password went into the fake page. Email can often reset passwords for other services, so losing it may expose more accounts. Set a new, unique password. If the old password was reused elsewhere, make a list for later changes — do not reuse the new password across all of them.

Next, end unfamiliar or all active sessions. Review signed-in devices, recovery phone numbers and recovery email addresses. Remove only entries you do not recognize. Enable multi-factor authentication and, after control is restored, consider passkeys where the service supports them.

At work, do not wait until you have completed this article. Call IT or the security team using a known number and give specific facts: the message, affected account, information disclosed and time. Early notice may let an administrator revoke a session, remove the message from other inboxes and investigate follow-on activity.

Minutes 10–30: check what a password change may not fix

A password change matters, but it may not always terminate an attacker’s active session. Review sign-in history, devices and connected apps. Look for a new sign-in method, an unfamiliar passkey, an extra phone number, an unknown recovery address or an app with access to email or files.

In your mailbox, inspect forwarding rules, filters and automatic replies. Someone with access may create quiet forwarding or hide security alerts. Review Sent, Deleted and Trash folders. Warn colleagues or family if your account sent requests for money, files or codes.

If you exposed card details, an authorization code or online-banking information, call the number printed on your card, shown inside the official app or found on a website you typed yourself. Explain exactly what you shared and approved. The bank can decide whether to cancel the card, block access, flag a transaction or start a dispute. Never move money to a “safe account” or follow new instructions from somebody who contacts you in response to the incident.

If you installed a remote-access app, browser extension or file, do not use that device for more password changes. End the visible remote session, disconnect the device from the network and contact a trusted repair provider or corporate IT. Change passwords from another device. Removing the visible app alone does not prove that no other changes remain.

Minutes 30–60: contain secondary effects and preserve evidence

Review accounts where you reused the exposed password. Prioritize email, banking, password managers, Apple or Google accounts, social media and messaging. Each account needs a different password. If you use a password manager, do not change its master password on a device you no longer trust.

Preserve the original message, website address, sender name, phone number, time, payment confirmations and screenshots. You do not need to reopen a suspicious link to capture a better image. Report it to the organization being impersonated and to the relevant national cybercrime or cybersecurity reporting service. Report a workplace incident through your internal route as well.

If you disclosed a national identifier or identity document, move to an identity-protection plan. A credit freeze, fraud alert or local identity-protection mechanism cannot undo the disclosure, but it may limit some misuse. Establish whether the scammer also received a document image, selfie, bank details or access to a mailbox containing contracts.

Once the immediate situation is under control, write a timeline. A note such as “14:08 entered password, 14:14 changed it, 14:18 ended sessions” is more useful to a bank or security team than “I think I was hacked.”

What not to do in a panic

Do not reply to tell the scammer that you recognized the trick. Do not pay someone who promises to recover the account or money. Do not post screenshots containing complete card details, codes, email addresses or document numbers. Do not delete all correspondence before preserving the information required for a report.

Do not assume every click infected the device, either. If you only loaded an ordinary webpage and neither downloaded nor submitted anything, the risk differs from installing software. Updating the browser and operating system and watching the device are sensible, but the key is establishing honestly whether another step occurred.

Conversely, do not declare the incident finished merely because you changed a password. An approved session, connected app, forwarding rule or modified recovery channel may survive that change.

Prepare before an incident happens

Keep the official numbers for your bank and workplace help desk, recovery codes for important accounts and access to a second trusted device. A password manager makes unique passwords practical, so exposing one does not force an emergency change to dozens of identical passwords.

An organization should offer a simple reporting route and explicitly tell employees that promptly admitting a click is the right behavior. A culture of blame encourages delay, even though time can determine whether an incident stops at one password.

What the sources confirm, and what Breachroad recommends

The US Federal Trade Commission’s guidance on what to do after a scam says that someone who disclosed a username and password should create a new strong password, change it anywhere it was reused and enable two-factor authentication. After granting access to a device, it advises updating security software, scanning the device and changing passwords. Google’s compromised-account procedure includes reviewing security events, signed-in devices, recovery methods and Gmail settings. These are primary instructions from the regulator and service provider.

The first-hour time blocks, the “email — money — sessions — remaining accounts” order and the exposure-specific table are Breachroad recommendations. They are a prioritization model, not a guarantee that funds or accounts can be recovered. Learn more in our guide to phishing and why awareness alone is not enough. We help teams rehearse calm reporting and verification through cybersecurity training.

SHARE / COPY