What to do after entering a password on a fake page
The specific steps to take when you realize you typed a password into a phishing page.
By AlertaSpam Security Team. Published August 7, 2026
Change the compromised password immediately, but do it on the real site — navigate there by typing the address yourself, never through the suspicious link again.
Check whether you reused that password anywhere else. If you did, change it there too; a password manager makes this audit far faster and is worth setting up if you don't already use one.
Enable two-factor authentication if the account offers it and you hadn't already turned it on. If the fake page also asked for a one-time code and you provided one, assume the account may have been accessed already: check the account's recent login activity and sign out of any sessions you don't recognize.
Finally, consider filing a report on AlertaSpam for the domain or link involved, so others researching the same page can see it reflected in the entity's history.
