Skip to content

I entered my password on a fake site: what to do

In short

Change that password right away, from the real service opened by your own means — a bookmark or the app, never the link you received — then sign out every open session on the account. Then change the same password everywhere you used it, starting with your email. If you also entered a bank card, call your bank before anything else.

Why this works

A fake page doesn't need to break anything: you gave it the password, and it can pass it on at once to someone who signs in in your place while you are still reading the page. Two things follow. First, a session the attacker has already opened survives the password change unless you sign out active sessions. Second, the stolen password is not only worth something for that service: it will be tried everywhere else, and your email matters more than anything because it can reset your other accounts.

Step by step

  1. Change the password from the real service

    Close the page you were sent to. Open the service through a saved bookmark or its official app, then change the password. Don't go through any link in the message, not even to “check”: it is what led you to the copy.

  2. Sign out active sessions

    In the account's security settings, sign out all devices and sessions. A sign-in relayed in real time by the fake page stays open after the password change: this step is what cuts it off.

  3. Change it everywhere it was reused

    The stolen password will be tried on other services. Start with your main email, then your bank, then the rest. Take the opportunity to turn on two-factor authentication, at least for your email and your bank.

  4. Check what the attacker may have changed

    Recovery email and number, email forwarding rules, connected devices: these are the first things an attacker changes to keep access. If bank details were entered on the page, block the card with your bank. Then report what happened to Cybermalveillance.gouv.fr (in France); if the link came by text message, the message can be forwarded to 33700 (France's spam-text reporting number).

The most common mistakes

  • Going back to the page through the same link to “check” or undo what you typed.
  • Changing the password without signing out open sessions, which stay valid.
  • Only changing the account concerned, when the same password opens other services.
  • Ignoring a verification code you received without asking for it: it means someone already knows the password.
  • Waiting to see whether something happens: the delay only helps the attacker.

A tool to do it

The attacks this defeats

Official sources

Other guides · Last updated: 2026-10-07.