I entered my password on a fake site: what to do
In short
Change that password right away, from the real service opened by your own means — a bookmark or the app, never the link you received — then sign out every open session on the account. Then change the same password everywhere you used it, starting with your email. If you also entered a bank card, call your bank before anything else.
Why this works
A fake page doesn't need to break anything: you gave it the password, and it can pass it on at once to someone who signs in in your place while you are still reading the page. Two things follow. First, a session the attacker has already opened survives the password change unless you sign out active sessions. Second, the stolen password is not only worth something for that service: it will be tried everywhere else, and your email matters more than anything because it can reset your other accounts.
Step by step
Change the password from the real service
Close the page you were sent to. Open the service through a saved bookmark or its official app, then change the password. Don't go through any link in the message, not even to “check”: it is what led you to the copy.
Sign out active sessions
In the account's security settings, sign out all devices and sessions. A sign-in relayed in real time by the fake page stays open after the password change: this step is what cuts it off.
Change it everywhere it was reused
The stolen password will be tried on other services. Start with your main email, then your bank, then the rest. Take the opportunity to turn on two-factor authentication, at least for your email and your bank.
Check what the attacker may have changed
Recovery email and number, email forwarding rules, connected devices: these are the first things an attacker changes to keep access. If bank details were entered on the page, block the card with your bank. Then report what happened to Cybermalveillance.gouv.fr (in France); if the link came by text message, the message can be forwarded to 33700 (France's spam-text reporting number).
The most common mistakes
- Going back to the page through the same link to “check” or undo what you typed.
- Changing the password without signing out open sessions, which stay valid.
- Only changing the account concerned, when the same password opens other services.
- Ignoring a verification code you received without asking for it: it means someone already knows the password.
- Waiting to see whether something happens: the delay only helps the attacker.
A tool to do it
- Emergency checklist: you've just been scammedThe first steps, in order, depending on what you gave away: money, bank details, a password, access to a device or an account.
- Link decoder: who really owns this address?Paste a link: the tool shows the real domain name, what is only decoration, and characters that imitate other letters. Nothing is sent.
The attacks this defeats
Official sources
Other guides · Last updated: 2026-10-07.