I gave a scammer my password. What should I do?
Change the password on that account first, then sign out every device. That second step is the one people miss, and it is the one that actually removes the attacker. Here is the full order, and what changes if you also gave a code.
The short answer
- Change the password on that account first, from a device you trust, going to the site directly rather than through any link you were sent.
- Then sign out all devices. A password change alone does not always end a session the attacker already has.
- Change the password anywhere else you used the same one, starting with email, because email resets everything else.
- Check for changes they may have left behind - mail forwarding rules, new recovery addresses, new trusted devices.
- If a scammer had remote access to your computer, run a security scan before you change anything, or the new password is captured too.
Do this first, in this order.
- Change the password on that account, from a device you trust. Type the website address yourself. Do not use any link from the message or the caller.
- Sign out of all devices on that account. Look for "sign out everywhere", "log out of all sessions", or a device list.
- Change the password anywhere else you used the same one, starting with your email.
- Turn on two-factor authentication on that account and on your email.
Step two is the one almost everyone skips, and it is the one that removes the attacker. Steps three and four stop it happening again.
Why the first hour matters
Nothing here is complicated. It is just time-sensitive.
Agari studied this directly by putting more than 8,000 fake login pages in front of real attackers over six months and watching what happened to the credentials. Half of the accounts were opened by a criminal within 12 hours. Nine in ten were opened within a week. Almost a quarter of the phishing sites checked the password automatically, the moment it was typed.
So "I will sort it out tomorrow" is usually too late, and "I will sort it out now" is usually early enough. That is the whole reason this page starts with the steps instead of the explanation.
Why signing out matters more than the password
A password is how you start a session. It is not what keeps one running.
If the attacker signed in before you changed anything, they now hold a live session — the same thing that keeps you logged into a site for weeks without retyping anything. On many services, changing the password does not end it.
That is why the FTC's recovery guidance lists signing out separately, saying that this way "anyone who's logged in to your account on another device will get kicked out". The NCSC says the same thing: make sure any devices and apps that may still be logged in are logged out.
The three big platforms handle it differently, which is why it is worth doing deliberately rather than assuming:
| Account | What happens | Where to look |
|---|---|---|
| A password change signs you out almost everywhere, but not from devices used to verify it is you, some third-party apps, or home devices | Security, then Your devices, then Manage all devices | |
| Microsoft | There is an explicit "Sign out everywhere" button. It can take up to 24 hours and does not cover an Xbox console | Advanced security options |
| Apple | No statement that a password change signs other devices out. You remove them yourself | Settings, then your name, or account.apple.com, then Devices |
Check what they left behind
An attacker who expects to lose the password will try to keep a way back in. These four checks take about five minutes between them, and they are the difference between recovering an account and recovering it twice.
Mail forwarding rules and filters
The most important one, and the least known.
A forwarding rule quietly sends a copy of your incoming mail somewhere else. It keeps working after you change your password. The FBI warned about this specifically, describing rules that auto-forwarded any message containing the words "bank," "payment," "invoice," "wire," or "check" to the criminal's own address. CISA has documented rules that dump security warnings into an RSS folder so the real owner never sees them.
- Gmail — Settings, then "Filters and Blocked Addresses", then "Forwarding and POP/IMAP", then "Accounts and Import" to check "Send mail as" and "Grant access to your account".
- Outlook.com — Settings, then Mail, then Forwarding, and then Rules.
Delete anything you did not create.
Recovery email and phone number
If they changed these, they can reset the password back whenever they like. The FTC's guidance is to make sure the recovery addresses and numbers listed are ones you entered and can actually reach. Apple additionally suggests confirming with your email provider and mobile network that those accounts are still yours.
Trusted devices and second factors
Look for an authenticator app you did not add, a phone number you do not recognise, or a device marked trusted. Remove them and set up two-factor authentication again from scratch.
Sent and deleted mail
Look at what was sent from your account while it was not yours. This tells you who else needs warning, and sometimes shows what the attacker was actually after.
What changes depending on the account
The password matters, but so does the account. Deal with these in order.
Email — always first. Nearly every other account offers "forgot password" to your inbox. Someone with your email does not need your banking password; they can ask the bank for a new one. If the password you gave away is also your email password, that is the emergency, and it comes before everything else.
Banking and payment. Change the password, then ring the bank on the number on the back of your card and tell them. Watch for small test payments, which often come before large ones.
A work account. Tell your IT team immediately, before you try to fix anything yourself. They can end sessions centrally and see things you cannot. Reporting fast is far more useful than looking careful, and IT teams greatly prefer an early call to a late one.
Shopping accounts. Check saved cards, saved addresses and recent orders, including any sent to an address you do not recognise.
Social accounts. Warn your contacts. A compromised account is used to message the people who trust it, and the NCSC and FTC both list telling your contacts as a real step rather than a courtesy.
If you cannot get in at all
If they changed the password before you did, you are into account recovery, which is slower and needs proof rather than speed.
- Use the provider's official recovery page. Every major platform has one, and the FTC's recovery article links to them directly.
- Try from a device and network you have used with that account before. Many services weigh that as evidence.
- If the account is tied to a business or a bank, phone them. Human review exists precisely for this.
- If you cannot recover it, tell your contacts the account is no longer yours, and change the password on anything that used the same one.
Report it
Reporting takes a minute, and it is how patterns are spotted at all. The FBI's complaint centre now averages nearly 3,000 reports a day, and reports are what let it act quickly on money that has just moved.
- United States — ReportFraud.ftc.gov and ic3.gov. If you also gave away a Social Security number, use IdentityTheft.gov.
- United Kingdom — forward the email to report@phishing.gov.uk, forward the text to 7726, and if you lost money report it at reportfraud.police.uk or on 0300 123 2040. In Scotland, call Police Scotland on 101.
- Also report it inside your email app. It improves filtering for everyone.
Then make the repeat impossible
Once things are stable, three changes do almost all the remaining work.
- A password manager, so nothing is reused and one bad day stays one account. Reuse is what turns a single phished password into credential stuffing across your other accounts.
- Two-factor authentication everywhere, starting with email.
- Passkeys wherever they are offered, because a passkey cannot be typed into a fake site at all.
And if you are not certain what you handed over — a password, a code, card details, or only a click — work through I clicked a phishing link, which sorts the response by exactly that question.
Practise the recognition step
Our drills run real credential-phishing pages under time pressure, which is where spotting them actually has to happen.
Try it freeFrequently asked questions
- I gave a scammer my password. How much time do I have?
- Act now rather than tomorrow. In a study that seeded more than 8,000 fake login pages, Agari found half of the compromised accounts were opened by a criminal within 12 hours and 91% within a week. Some phishing kits test the password automatically the moment it is typed. A password changed in the first few minutes usually ends the incident; one changed the next day often does not.
- Is changing my password enough?
- Usually not on its own. If the attacker already signed in, they hold a session that can survive a password change. After changing it, use the account's sign out all devices or revoke sessions option, then check recovery details, mail forwarding rules and trusted devices. Google signs you out of most places automatically when you change your password, Microsoft has a Sign out everywhere button that can take up to 24 hours, and Apple asks you to remove devices one at a time.
- What if I also gave them the code from my phone?
- Treat it as more serious, because a code usually means they completed a login rather than just collecting a secret. Change the password, then sign out all devices - that step, not the password, is what ends their access. The FTC is blunt about the request itself, saying anyone who asks you for your account verification code is a scammer.
- Do I have to change the password on every account I own?
- No. Change it on the account you gave away, and on any account where you used the same or a similar password. If every password you have is unique, the damage stops at one account. If you are not sure, a password manager will show you which ones are reused so you are working from a list rather than memory.
- What is a forwarding rule, and why does it matter?
- It is a setting in your mailbox that automatically sends copies of incoming mail somewhere else. Attackers add one so they keep reading your email after you take the account back, and the FBI has warned about rules built to catch words like bank, payment, invoice and wire. It survives a password change, it is silent, and it takes two minutes to check in your mail settings.
- Should I report it if I did not lose any money?
- Yes, and it takes about a minute. In the US, report to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov. In the UK, forward the email to report@phishing.gov.uk, forward the text to 7726, and report fraud with a loss at reportfraud.police.uk or on 0300 123 2040. Reports are how repeated patterns get identified at all.
Sources
- What To Do if You Were Scammed — Federal Trade Commission, 2026
- How To Recover Your Hacked Email or Social Media Account — Federal Trade Commission, 2023
- Recovering a hacked account — UK National Cyber Security Centre, 2022
- What's a verification code and why would someone ask me for it? — Federal Trade Commission, 2024
- Cyber Criminals Exploit Email Rule Vulnerability to Increase the Likelihood of Successful Business Email Compromise — FBI Internet Crime Complaint Center (IC3), 2020
- Strengthening Security Configurations to Defend Against Attackers Targeting Cloud Services (AR21-013A) — Cybersecurity and Infrastructure Security Agency, 2021
- Anatomy of a Compromised Account — Agari Cyber Intelligence Division, 2021
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center (IC3), 2026
- Change or reset your password — Google Account Help, 2026
- How to sign out of your Microsoft account everywhere — Microsoft Support, 2026
- Refund and Recovery Scams — Federal Trade Commission, 2023
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
I clicked a phishing link. What should I do?
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
- Password Security
Password reuse: why it is the riskiest habit online
Reusing a password means your security is set by the least careful company you ever signed up to. It is the single behaviour that converts an unrelated breach into a break-in on your accounts.
- Password Security
What is credential stuffing? How one breach becomes many
Credential stuffing is not password guessing. It is taking email-and-password pairs already leaked from one service and trying them, automatically, on hundreds of others — which works because people reuse passwords.