Phishing email received: exactly what to do next, based on what you did

Breach / exposure. Updated 2026-09-13. About 5 minutes to read.

If you typed a password, change it on the real site now, change it everywhere you reused it, sign out all sessions and check your email forwarding rules.

What you need to do depends on one thing: how far you got. If you only received or opened the email, you have a two minute job. If you typed a password, handed over card details or let someone connect to your computer, you have a 15 minute job that should start now.

Find your situation in the first section, then jump to the matching steps. Do not reply to the email, do not call any number in it, and do not use its links to check anything. Go to the real website or app by typing the address yourself.

The reporting section at the end lists the right addresses for the US, UK, Australia and Canada. Reporting takes a minute and helps get the sending domain blocked for other people.

First, work out which situation you are in

  • I only received or opened it: follow the check and report steps.
  • I clicked the link but typed nothing: follow the clicked steps.
  • I typed a password on the page: follow the password steps immediately.
  • I opened an attachment, enabled content or macros, or let someone remote into my computer: follow the device steps.
  • I paid, or gave card, bank or ID details: follow the money steps and call your bank first.

If you only received it: check it, report it, delete it

  1. Do not reply, even to say stop. A reply confirms the address is live.
  2. Check the real sender address after the @ sign and hover over or long press any link to read the real destination without opening it.
  3. In Gmail, open the message, click the three dot menu and choose Report phishing. In Outlook, choose Report, then Report phishing.
  4. Forward it to the reporting address for your country, listed at the end of this guide.
  5. Delete it. If it was sent to a work address, tell your IT team, because the same message has usually gone to colleagues.

An email that quotes one of your real passwords and claims you were recorded is a mass mailed extortion scam. The password came from an old breach. Change it wherever you still use it, do not pay, and delete the email.

If you clicked a link but typed nothing

  1. Close the tab or window straight away.
  2. If a file downloaded, delete it without opening it and empty the downloads folder or recycle bin.
  3. Run a full scan with your security software, or Microsoft Defender on Windows.
  4. Update your browser and operating system, since some malicious pages target unpatched browsers.
  5. Watch the account the email impersonated for unusual activity over the next few days.

If you typed a password on the page

  1. Go to the real site by typing its address and change the password immediately. If you cannot log in, use the account recovery process now.
  2. Change the same password on every other account where you used it or something similar.
  3. Sign out of all other sessions. In a Google account open Security, then Your devices. In a Microsoft account open Security, then sign in activity. Most banks and social networks have a similar option.
  4. Turn on two factor authentication with an authenticator app or passkey.
  5. If it was your email account, check forwarding settings, filters and rules, and the recovery email and phone number. Attackers add forwarding rules to keep reading your mail after you change the password.
  6. If you also typed a one time code from a text or app, assume the attacker got into the account and review recent activity closely.

If you opened an attachment or gave someone remote access

  1. Disconnect the device from the internet by turning off Wi-Fi or unplugging the network cable.
  2. If someone was connected remotely, end the session and uninstall any remote access tool they asked you to install.
  3. Using a different, clean device, change passwords for email, banking and your password manager, and turn on two factor authentication.
  4. Run a full security scan on the affected device. If it is a work device, stop and call IT before doing anything else.
  5. If the scan finds malware or the device behaves oddly, have it professionally cleaned or restore it from a backup made before the incident.

If you paid, or handed over card or bank details

  1. Call your bank or card issuer on the number printed on your card or in its app, not a number from the email. In the UK you can also call 159 to reach most major banks.
  2. Ask them to block the card, stop or recall the payment, and tell you whether a chargeback or scam reimbursement claim is possible.
  3. If you gave government ID details such as a Social Security, tax file or passport number, report identity theft: IdentityTheft.gov in the US, IDCARE on 1800 595 160 in Australia, and Report Fraud in the UK.
  4. Consider a credit freeze in the US, or a credit ban in Australia if you believe fraud has occurred.
  5. Expect follow up recovery scams offering to get your money back for a fee. Legitimate agencies do not charge.

Where to report it, by country

  • United States: forward the email to reportphishing@apwg.org and report at ReportFraud.ftc.gov. If you lost money, also report to the FBI at ic3.gov.
  • United Kingdom: forward the email to report@phishing.gov.uk. If you lost money or data, report to Report Fraud, formerly Action Fraud, at reportfraud.police.uk or 0300 123 2040. In Scotland, call Police Scotland on 101.
  • Australia: report at scamwatch.gov.au. If you lost money or an account was compromised, also report at cyber.gov.au.
  • Canada: report to the Canadian Anti-Fraud Centre.
  • Brand specific: Apple asks for phishing emails to be forwarded to reportphishing@apple.com, and most banks publish their own phishing report address.

Frequently asked questions

Can I get hacked just by opening a phishing email?

In a current, updated mail app, opening an email is normally safe. The risk comes from clicking links, opening attachments, enabling macros or entering details. Opening can confirm the address is active if images load, which is why many mail apps block remote images by default.

I clicked the link but did not type anything. Am I safe?

Very likely. Close the page, delete any download without opening it, run a security scan and keep your browser updated. The serious risk begins when you enter a password, a code or payment details.

Should I reply and tell them to stop?

No. Replying confirms that a real person reads the address, which leads to more scam mail and sometimes more targeted follow ups. Report and delete instead.

Why does the phishing email know my name and an old password?

Because that data was exposed in a past breach and is now in lists criminals share. Knowing personal details does not make the email genuine. Check your address on a breach checker and change any password that appears in a breach.

How do I see the real sender behind a display name?

Tap or hover over the sender name to show the full address. For more detail, open the message headers: in Gmail use the three dot menu and Show original, which shows whether SPF, DKIM and DMARC checks passed.

Tools that help

Related guides

Sources