Skip to content
Cyber SecurityAdvanced

What to Do If You Entered Your Password on a Phishing Website or Downloaded a Malicious Email Attachment – Complete Incident Response Guide

Phishing attacks are among the most common ways cybercriminals steal passwords, compromise email accounts, distribute malware, and gain access to business ne...

BI
Bison Technical Team Enterprise IT specialists
Updated 24 Aug 2026 16 min read 0 total views

Phishing attacks are among the most common ways cybercriminals steal passwords, compromise email accounts, distribute malware, and gain access to business networks.

A phishing attack often starts with an email, SMS message, QR code, social-media message, or fake website designed to look like a legitimate organization. The attacker may impersonate a bank, courier company, cloud-storage provider, Microsoft 365, Google, an employer, supplier, customer, or even someone you personally know.

Advertisement

The situation becomes significantly more serious when you:

  1. Enter your username and password into the phishing website, or
  2. Download or open an attachment sent through the phishing email.

These two situations require somewhat different responses.

Microsoft recommends immediately changing passwords associated with affected accounts, enabling multifactor authentication, and notifying IT administrators when a work or school account may have been compromised.

The FTC similarly recommends creating a new strong password immediately when credentials have been given to a scammer and changing that password anywhere else it was reused.


Part 1: What Should I Do If I Entered My Password on a Phishing Website?

If you typed your username and password into a phishing page, assume the password has been compromised even if the website displayed an error afterward.

The attacker does not necessarily need to log in immediately. Credentials can be collected automatically and stored for later use.

Attackers may use stolen credentials to:

  • Access your email
  • Reset passwords for other accounts
  • Access cloud storage
  • Read confidential messages
  • Steal customer or company information
  • Send phishing emails from your account
  • Impersonate you
  • Access Microsoft 365 or Google Workspace
  • Attempt credential-stuffing attacks against other websites
  • Modify security settings
  • Add malicious email forwarding rules
  • Register additional authentication methods
  • Attempt financial fraud

Therefore, speed is important.

Step 1: Change the Compromised Password Immediately

Go directly to the legitimate service.

Do not return to the link contained in the phishing email.

Open a new browser window and manually access the legitimate provider's website or use its official application.

Change the compromised password immediately.

For example, if you entered your Microsoft 365 password into a fake Microsoft login page, change the Microsoft 365 password through Microsoft's legitimate account-management interface.

If you entered your Google password, change it through your legitimate Google Account security settings.

Microsoft specifically recommends immediately changing passwords for affected accounts following successful phishing.


Step 2: Change the Password Anywhere Else You Used It

Password reuse dramatically increases the impact of phishing.

Suppose you used the same password for:

  • Email
  • Facebook
  • Online banking
  • Hosting account
  • Domain registrar
  • Amazon
  • Microsoft 365
  • Google Workspace
  • Remote-access software

An attacker may automatically test the stolen username/password combination against other services. This technique is commonly known as credential stuffing.

Therefore:

Change the password on every account where the compromised password or a closely related password was used.

The FTC specifically advises changing the password anywhere else where the same password was reused.


Step 3: Use a Completely New Password

Do not simply modify the old password.

For example, if the compromised password was:

Office@2025

changing it to:

Office@2026

is not a strong response.

Instead, create a completely different, long and unique password or passphrase.

A password manager can help generate and store unique passwords for different websites.

CISA recommends using long, strong, unique passwords and notes that password managers can help users maintain different passwords for different accounts.


Step 4: Enable Multi-Factor Authentication

Enable MFA or two-step verification wherever possible.

Depending on the service, MFA may use:

  • Authenticator applications
  • Hardware security keys
  • Passkeys
  • Push notifications
  • One-time security codes
  • SMS verification

MFA provides another layer of protection if an attacker obtains your password. CISA and the FTC both recommend MFA as an important defense against account compromise.

However, remember that sophisticated phishing attacks can also attempt to steal MFA codes or authentication sessions. MFA should complement—not replace—strong phishing awareness.


Step 5: Sign Out Other Sessions and Devices

Changing the password is essential, but you should also review active sessions.

Look for options such as:

Security → Devices → Active Sessions → Sign Out

or:

Sign Out Everywhere

Terminate sessions you do not recognize.

For important accounts, signing out all sessions and signing back in on trusted devices can be a sensible precaution.

This is especially important because some sophisticated attacks target authenticated browser sessions or tokens rather than relying solely on passwords.


Step 6: Check Recent Login Activity

Review your account's recent authentication history.

Look for:

  • Unknown countries
  • Unknown cities
  • Unknown IP addresses
  • Unrecognized computers
  • Unrecognized mobile phones
  • Unusual login times
  • Failed MFA attempts
  • Successful logins you do not recognize

If suspicious activity appears, document it and notify your organization's IT/security team if it involves a business account.


Step 7: Check Whether Security Information Was Changed

Attackers sometimes modify recovery mechanisms after compromising an account.

Check:

  • Recovery email address
  • Recovery mobile number
  • MFA methods
  • Authenticator registrations
  • Security keys
  • App passwords
  • Trusted devices
  • Connected applications

Remove anything you do not recognize.


Step 8: Check Your Email Forwarding Rules

This step is especially important for compromised email accounts.

Attackers sometimes create forwarding or inbox rules that silently copy messages to another mailbox or hide selected emails.

Check for suspicious rules such as:

Forward all messages to attacker@example.com

or rules that automatically:

  • Delete messages
  • Archive messages
  • Mark messages as read
  • Forward invoices
  • Forward banking emails
  • Move security notifications
  • Hide replies from customers
  • Delete password-reset notifications

In business environments, these rules can be part of a Business Email Compromise (BEC) attack.


Step 9: Review Sent Mail and Deleted Items

Check:

  • Sent Items
  • Deleted Items
  • Trash
  • Drafts
  • Spam/Junk
  • Archive

Look for emails you did not send.

Attackers frequently use compromised accounts to send additional phishing messages because recipients are more likely to trust an email coming from someone they know.

The FTC warns that compromised email credentials can allow scammers to take over an account and send scams to the victim's contacts.


Step 10: Check Connected Applications

Modern accounts may authorize third-party applications through OAuth or similar mechanisms.

Review applications connected to your:

  • Microsoft account
  • Microsoft 365 account
  • Google account
  • Social-media account
  • Cloud-storage account

Remove applications you do not recognize or no longer use.


Step 11: Notify Your IT Department

If the compromised account belongs to your company, do not attempt to quietly handle everything yourself.

Immediately inform:

  • IT administrator
  • System administrator
  • Cybersecurity team
  • Microsoft 365 administrator
  • Google Workspace administrator
  • Managed IT provider

Microsoft specifically recommends contacting IT administrators when phishing affects a work or school account.

Administrators may need to investigate authentication logs, revoke sessions, reset credentials, inspect mailbox rules, review endpoint activity and determine whether other users were targeted.


Part 2: What Should I Do If I Downloaded an Attachment from a Phishing Email?

The first question is:

Did you only download the attachment, or did you actually open/run it?

These are different levels of risk.

Situation A: You Downloaded the File but Did Not Open It

If you only downloaded the attachment but never opened or executed it, the risk is generally lower.

Do not open the file to investigate it.

Delete or quarantine it and run an antivirus/security scan.

However, security teams may prefer to preserve a suspicious attachment for analysis. In a corporate environment, contact IT before permanently deleting evidence.


Situation B: You Opened the Attachment

If you opened the suspicious attachment, treat the device as potentially compromised.

The FTC notes that phishing links and attachments can result in harmful malware being downloaded onto a device.

The type of attachment matters.

Suspicious attachments may include:

  • .exe
  • .msi
  • .scr
  • .js
  • .vbs
  • .bat
  • .cmd
  • .ps1
  • .hta
  • .lnk
  • .zip
  • .rar
  • .iso
  • .img
  • Microsoft Word documents
  • Microsoft Excel files
  • PDFs
  • OneNote files
  • Password-protected archives

Even apparently ordinary documents can be used as part of an attack chain.


Step 1: Stop Interacting with the Suspicious File

Do not:

  • Open it again
  • Run it again
  • Forward it to colleagues
  • Upload it randomly to websites
  • Enable macros
  • Enable editing because the document asks you to
  • Enter credentials requested by the document

Preserve the original phishing email if your IT/security team may need it for investigation.


Step 2: Disconnect a Potentially Infected Computer from the Network

If you executed a suspicious program, enabled malicious content, or have strong reason to believe malware ran, disconnecting the device from the network can help contain the incident.

Disconnect:

  • Ethernet
  • Wi-Fi
  • VPN connections

For business computers, contact IT/security immediately.

Do not automatically power off a corporate computer unless instructed by your incident-response team because security investigators may need information from the running system.


Step 3: Update Your Security Software

Make sure the security software has current malware definitions before performing the appropriate scan, where practical.

CISA recommends regularly updated antivirus, firewall, email-filtering and antispyware protections.

The FTC also advises keeping security software updated.


Step 4: Run a Full Antivirus Scan

On Windows systems using Microsoft Defender:

Open:

Windows Security → Virus & threat protection → Scan options → Full scan

A Full Scan examines substantially more content than a Quick Scan and may take considerable time.

Do not assume the computer is clean simply because no warning appeared when you opened the attachment.

Some malware operates silently.


Step 5: Consider Microsoft Defender Offline Scan

For a Windows computer where malware infection is strongly suspected, an offline scan can provide another layer of inspection.

Open:

Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan

The computer restarts and performs scanning outside the normal Windows environment, which can help identify some threats that attempt to hide while Windows is running.


Step 6: Change Passwords from a Known-Clean Device

This is extremely important.

If the attachment executed malware, the computer could potentially contain:

  • Keyloggers
  • Information stealers
  • Browser credential stealers
  • Remote-access malware
  • Spyware

Therefore, avoid changing critical passwords from a computer you strongly suspect is infected.

Instead, use a trusted device—for example, another secured computer or smartphone—to change important passwords.

Prioritize:

  1. Primary email account
  2. Microsoft/Google account
  3. Password manager
  4. Banking accounts
  5. Business applications
  6. Cloud-storage accounts
  7. Domain and hosting accounts
  8. Social-media accounts

Step 7: Consider Browser Data Exposure

Modern information-stealing malware may target more than passwords.

Depending on the malware and browser configuration, attackers may attempt to obtain:

  • Saved passwords
  • Cookies
  • Session information
  • Autofill information
  • Browser history
  • Cryptocurrency-related information
  • Authentication data

Therefore, changing only one password may not always be sufficient following a confirmed malware infection.

Important sessions may also need to be revoked.


Step 8: Inspect the System for Suspicious Persistence

Technical users and administrators may investigate areas commonly abused for persistence, including:

  • Startup applications
  • Windows services
  • Scheduled Tasks
  • Browser extensions
  • Registry Run keys
  • Recently installed applications
  • Unknown user accounts
  • PowerShell activity
  • Unusual processes

However, manually deleting suspicious entries without understanding them can damage Windows or destroy forensic evidence.

In a business environment, endpoint security or incident-response personnel should perform this investigation.


Step 9: Check Browser Extensions

Open your browser's extension-management page and look for:

  • Extensions you did not install
  • Recently installed extensions
  • Extensions requesting excessive permissions
  • Extensions claiming to provide security updates
  • Unknown PDF converters
  • Unknown search extensions
  • Unknown coupon or productivity extensions

Remove suspicious extensions and investigate how they were installed.


Step 10: Monitor Financial and Online Accounts

If phishing exposed financial information, contact the appropriate financial institution.

Microsoft recommends notifying banks or credit-card companies when relevant financial information may have been compromised.

Monitor accounts for:

  • Unauthorized payments
  • Unknown beneficiaries
  • Password-reset attempts
  • Changed contact information
  • Unknown devices
  • Unexpected OTP requests
  • Suspicious transactions

Never approve an MFA request or OTP that you did not initiate.


Understanding the Difference Between Downloading and Opening an Attachment

Action Typical Risk
Received phishing email but did nothing Low
Viewed email only Usually low
Downloaded attachment but did not open it Lower, but investigate
Opened PDF/document Moderate depending on content and vulnerabilities
Enabled macros/content High
Opened executable/script High
Entered credentials after opening attachment Critical
Installed software requested by attacker Critical
Gave attacker remote access Critical

These are general risk levels rather than guarantees. Actual risk depends on the file, operating system, security controls and what occurred after the attachment was opened.


What If I Entered My Password AND Opened the Attachment?

Treat the situation as both:

Credential compromise + possible endpoint compromise.

Recommended response:

  1. Stop interacting with the suspicious website/file.
  2. If malware may have executed, isolate the affected computer.
  3. Notify IT/security immediately if it is a business device.
  4. From a known-clean device, change the compromised password.
  5. Change the same password anywhere else it was reused.
  6. Enable or verify MFA.
  7. Revoke suspicious or existing sessions as appropriate.
  8. Review account recovery methods.
  9. Review email forwarding and inbox rules.
  10. Review connected applications.
  11. Scan the affected computer.
  12. Investigate suspicious processes, services, scheduled tasks and startup entries.
  13. Review login history.
  14. Monitor financial accounts where relevant.
  15. Preserve evidence for investigation.

Should I Format or Reinstall Windows After Opening a Phishing Attachment?

Not automatically.

If the attachment was downloaded but never executed, reinstalling Windows would normally be excessive.

If malware actually executed, the correct response depends on:

  • Malware type
  • Antivirus/EDR findings
  • Whether administrator privileges were obtained
  • Whether persistence was established
  • Whether credentials were stolen
  • Whether the computer contains sensitive business information
  • Whether lateral movement may have occurred

For serious or confirmed compromise, organizations may choose to reimage the endpoint from a known-good source rather than rely solely on malware removal.


Special Warning for Business Users

A phishing incident involving a business email account should be considered potentially more serious than the compromise of an isolated personal account.

Attackers may use the mailbox to:

  • Impersonate employees
  • Request fraudulent payments
  • Change supplier banking information
  • Steal invoices
  • Intercept customer communications
  • Reset other business passwords
  • Access cloud storage
  • Send phishing messages internally
  • Target accounting or finance departments

Therefore, compromised Microsoft 365, Google Workspace, accounting, administrative, domain-management, hosting, VPN or remote-access credentials should be escalated quickly.


What Not to Do After a Phishing Incident

Do not assume everything is safe simply because:

  • The fake website disappeared
  • The page displayed "Incorrect Password"
  • Antivirus displayed no immediate warning
  • The attachment appeared blank
  • Nothing visibly installed
  • The computer appears normal
  • Your email account still works

Attackers often design malware and credential-stealing infrastructure to operate without obvious symptoms.

Also avoid entering credentials again into the phishing website to "test" whether it was fake.


How to Prevent Similar Phishing Attacks

Use Unique Passwords

Every important account should have a different password.

A password manager makes this considerably easier.

Enable MFA

Enable multifactor authentication on important services.

Keep Software Updated

Regularly update:

  • Windows
  • Browsers
  • Microsoft Office
  • PDF readers
  • Antivirus/endpoint protection
  • Email clients
  • Other internet-facing applications

Never Trust Unexpected Attachments

Microsoft recommends avoiding unexpected links and attachments even when they appear to come from a trusted sender. Instead, confirm the message using another communication method.

Verify Requests Independently

If an email claims to come from your bank, supplier, cloud provider or another organization, access the organization's legitimate website independently instead of using the email's link.

The FTC similarly recommends contacting the organization using a phone number or website you already know is legitimate.


Quick Phishing Incident Response Checklist

If You Entered Your Password

Immediately:

Change password → Change reused passwords → Enable MFA → Review active sessions → Check recovery information → Check login history → Review mailbox rules → Check connected applications → Notify IT if business-related.

If You Opened an Attachment

Immediately:

Stop interacting with file → Isolate computer if malware may have executed → Notify IT → Update security tools → Run security scans → Consider offline scanning → Change critical passwords from a clean device → Revoke sessions → Investigate suspicious system activity.


Frequently Asked Questions (FAQ)

1. What should I do immediately after entering my password on a phishing website?

Immediately access the legitimate service directly and change the compromised password. Change it anywhere else it was reused, enable MFA, review active sessions and inspect the account for unauthorized changes.

2. Should I change my password even if the phishing website said the password was incorrect?

Yes.

A fake website can intentionally display an "incorrect password" message after already capturing the credentials you entered.

3. Should I change my email password first?

If your primary email account was compromised, protecting it should be a top priority because email is commonly used to reset passwords for many other accounts.

4. What happens if I use the same password on several websites?

Change the password on all of them.

Attackers can attempt credential stuffing by testing stolen username/password combinations against other services.

5. Is changing my password enough?

Not necessarily.

You should also consider MFA, active sessions, recovery information, login history, mailbox forwarding rules and connected applications.

6. Can hackers access my account even after I change my password?

Depending on the service and attack technique, previously established sessions or authorized applications may require separate revocation. Review sessions and connected applications after a compromise.

7. Should I enable two-factor authentication after phishing?

Yes. MFA can significantly reduce the risk associated with stolen passwords, although users must still remain alert to phishing attempts targeting MFA itself.

8. I downloaded a phishing attachment but did not open it. Am I infected?

Not necessarily. Merely downloading a file generally presents less risk than executing or opening it. Do not open it; delete/quarantine it appropriately and run a security scan.

9. What if I opened the attachment?

Treat the device as potentially compromised, particularly if you executed a program, enabled macros/content, entered credentials, or observed suspicious behavior.

10. Should I disconnect my computer from the internet?

If you believe malicious code actually executed, network isolation can help prevent further communication or spread. Business users should contact their IT/security team immediately.

11. Should I turn off the infected computer?

Not necessarily. In corporate incidents, shutting down a computer can destroy volatile forensic information. Disconnect it from the network and follow your organization's incident-response procedure.

12. Can a PDF attachment contain malware?

Potentially, yes. PDFs can be part of malicious attack chains, especially when exploiting vulnerable software or directing users toward malicious links or actions.

13. Can Word and Excel attachments be dangerous?

Yes. Documents may contain or trigger malicious content, exploit vulnerabilities, or persuade users to enable dangerous functionality.

14. Are ZIP files dangerous?

A ZIP file itself is an archive, but it may contain malicious executables, scripts, shortcuts or documents. Password-protected archives are also sometimes used to make automated security inspection more difficult.

15. Can antivirus detect every malicious phishing attachment?

No security product can guarantee detection of every malicious file. Layered security, updates, endpoint protection, MFA, email filtering and user awareness remain important.

16. Should I change passwords from the possibly infected computer?

For important accounts, use a known-clean device when you strongly suspect malware executed on the affected computer.

17. Can malware steal passwords saved in my browser?

Some information-stealing malware specifically targets browser-stored credentials and other authentication information. A confirmed infostealer infection therefore requires broader credential and session remediation.

18. Should I check my email forwarding settings?

Yes, especially after an email account compromise. Attackers may create forwarding or inbox rules to monitor communications or hide security notifications.

19. Should businesses report phishing incidents to IT?

Yes. Microsoft recommends notifying IT administrators when a work or school account may have been affected by phishing.

20. How can I prevent phishing attacks in the future?

Use unique passwords, MFA, updated software, reputable endpoint protection and email filtering. Avoid unexpected links and attachments and independently verify unusual requests.


Conclusion

Entering a password on a phishing website or opening a malicious email attachment should never be ignored.

If credentials were entered, assume they are compromised and change them immediately from the legitimate service, change reused passwords, enable MFA, review account activity and revoke suspicious access.

If a suspicious attachment was opened or executed, treat the computer as potentially compromised. Isolate it when appropriate, run security scans, notify IT in business environments, investigate the endpoint and change important credentials from a known-clean device.

Fast action can make the difference between a contained phishing incident and a larger account takeover, malware infection, financial fraud or business email compromise.

Security principle: If you suspect that credentials or a device have been compromised, act on the assumption that the compromise is real until reasonable investigation shows otherwise.

#Tags

#Phishing #PhishingAttack #PhishingEmail #PhishingWebsite #CyberSecurity #CybersecurityAwareness #EmailSecurity #PasswordSecurity #CompromisedPassword #StolenPassword #CredentialTheft #CredentialPhishing #Malware #MalwareAttack #MaliciousAttachment #EmailMalware #Virus #Trojan #Spyware #InfoStealer #PasswordStealer #Ransomware #MicrosoftDefender #WindowsSecurity #Antivirus #MalwareRemoval #IncidentResponse #CyberIncident #AccountSecurity #AccountCompromise #EmailHacked #MFA #MultiFactorAuthentication #TwoFactorAuthentication #PasswordManager #CredentialStuffing #BusinessEmailCompromise #BEC #Microsoft365Security #GoogleWorkspaceSecurity #GmailSecurity #OutlookSecurity #PhishingProtection #PhishingPrevention #DataSecurity #NetworkSecurity #EndpointSecurity #OnlineSafety #CyberAttack #SecurityAwareness

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “What to Do If You Entered Your Password on a Phishing Website or Downloaded a Malicious Email Attachment – Complete Incident Response Guide”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.