What to Do If You Entered Your Password on a Phishing Website or Downloaded a Malicious Email Attachment – Complete Incident Response Guide
Phishing attacks are among the most common ways cybercriminals steal passwords, compromise email accounts, distribute malware, and gain access to business ne...
Phishing attacks are among the most common ways cybercriminals steal passwords, compromise email accounts, distribute malware, and gain access to business networks.
A phishing attack often starts with an email, SMS message, QR code, social-media message, or fake website designed to look like a legitimate organization. The attacker may impersonate a bank, courier company, cloud-storage provider, Microsoft 365, Google, an employer, supplier, customer, or even someone you personally know.
The situation becomes significantly more serious when you:
- Enter your username and password into the phishing website, or
- Download or open an attachment sent through the phishing email.
These two situations require somewhat different responses.
Microsoft recommends immediately changing passwords associated with affected accounts, enabling multifactor authentication, and notifying IT administrators when a work or school account may have been compromised.
The FTC similarly recommends creating a new strong password immediately when credentials have been given to a scammer and changing that password anywhere else it was reused.
Part 1: What Should I Do If I Entered My Password on a Phishing Website?
If you typed your username and password into a phishing page, assume the password has been compromised even if the website displayed an error afterward.
The attacker does not necessarily need to log in immediately. Credentials can be collected automatically and stored for later use.
Attackers may use stolen credentials to:
- Access your email
- Reset passwords for other accounts
- Access cloud storage
- Read confidential messages
- Steal customer or company information
- Send phishing emails from your account
- Impersonate you
- Access Microsoft 365 or Google Workspace
- Attempt credential-stuffing attacks against other websites
- Modify security settings
- Add malicious email forwarding rules
- Register additional authentication methods
- Attempt financial fraud
Therefore, speed is important.
Step 1: Change the Compromised Password Immediately
Go directly to the legitimate service.
Do not return to the link contained in the phishing email.
Open a new browser window and manually access the legitimate provider's website or use its official application.
Change the compromised password immediately.
For example, if you entered your Microsoft 365 password into a fake Microsoft login page, change the Microsoft 365 password through Microsoft's legitimate account-management interface.
If you entered your Google password, change it through your legitimate Google Account security settings.
Microsoft specifically recommends immediately changing passwords for affected accounts following successful phishing.
Step 2: Change the Password Anywhere Else You Used It
Password reuse dramatically increases the impact of phishing.
Suppose you used the same password for:
- Online banking
- Hosting account
- Domain registrar
- Amazon
- Microsoft 365
- Google Workspace
- Remote-access software
An attacker may automatically test the stolen username/password combination against other services. This technique is commonly known as credential stuffing.
Therefore:
Change the password on every account where the compromised password or a closely related password was used.
The FTC specifically advises changing the password anywhere else where the same password was reused.
Step 3: Use a Completely New Password
Do not simply modify the old password.
For example, if the compromised password was:
Office@2025
changing it to:
Office@2026
is not a strong response.
Instead, create a completely different, long and unique password or passphrase.
A password manager can help generate and store unique passwords for different websites.
CISA recommends using long, strong, unique passwords and notes that password managers can help users maintain different passwords for different accounts.
Step 4: Enable Multi-Factor Authentication
Enable MFA or two-step verification wherever possible.
Depending on the service, MFA may use:
- Authenticator applications
- Hardware security keys
- Passkeys
- Push notifications
- One-time security codes
- SMS verification
MFA provides another layer of protection if an attacker obtains your password. CISA and the FTC both recommend MFA as an important defense against account compromise.
However, remember that sophisticated phishing attacks can also attempt to steal MFA codes or authentication sessions. MFA should complement—not replace—strong phishing awareness.
Step 5: Sign Out Other Sessions and Devices
Changing the password is essential, but you should also review active sessions.
Look for options such as:
Security → Devices → Active Sessions → Sign Out
or:
Sign Out Everywhere
Terminate sessions you do not recognize.
For important accounts, signing out all sessions and signing back in on trusted devices can be a sensible precaution.
This is especially important because some sophisticated attacks target authenticated browser sessions or tokens rather than relying solely on passwords.
Step 6: Check Recent Login Activity
Review your account's recent authentication history.
Look for:
- Unknown countries
- Unknown cities
- Unknown IP addresses
- Unrecognized computers
- Unrecognized mobile phones
- Unusual login times
- Failed MFA attempts
- Successful logins you do not recognize
If suspicious activity appears, document it and notify your organization's IT/security team if it involves a business account.
Step 7: Check Whether Security Information Was Changed
Attackers sometimes modify recovery mechanisms after compromising an account.
Check:
- Recovery email address
- Recovery mobile number
- MFA methods
- Authenticator registrations
- Security keys
- App passwords
- Trusted devices
- Connected applications
Remove anything you do not recognize.
Step 8: Check Your Email Forwarding Rules
This step is especially important for compromised email accounts.
Attackers sometimes create forwarding or inbox rules that silently copy messages to another mailbox or hide selected emails.
Check for suspicious rules such as:
Forward all messages to attacker@example.com
or rules that automatically:
- Delete messages
- Archive messages
- Mark messages as read
- Forward invoices
- Forward banking emails
- Move security notifications
- Hide replies from customers
- Delete password-reset notifications
In business environments, these rules can be part of a Business Email Compromise (BEC) attack.
Step 9: Review Sent Mail and Deleted Items
Check:
- Sent Items
- Deleted Items
- Trash
- Drafts
- Spam/Junk
- Archive
Look for emails you did not send.
Attackers frequently use compromised accounts to send additional phishing messages because recipients are more likely to trust an email coming from someone they know.
The FTC warns that compromised email credentials can allow scammers to take over an account and send scams to the victim's contacts.
Step 10: Check Connected Applications
Modern accounts may authorize third-party applications through OAuth or similar mechanisms.
Review applications connected to your:
- Microsoft account
- Microsoft 365 account
- Google account
- Social-media account
- Cloud-storage account
Remove applications you do not recognize or no longer use.
Step 11: Notify Your IT Department
If the compromised account belongs to your company, do not attempt to quietly handle everything yourself.
Immediately inform:
- IT administrator
- System administrator
- Cybersecurity team
- Microsoft 365 administrator
- Google Workspace administrator
- Managed IT provider
Microsoft specifically recommends contacting IT administrators when phishing affects a work or school account.
Administrators may need to investigate authentication logs, revoke sessions, reset credentials, inspect mailbox rules, review endpoint activity and determine whether other users were targeted.
Part 2: What Should I Do If I Downloaded an Attachment from a Phishing Email?
The first question is:
Did you only download the attachment, or did you actually open/run it?
These are different levels of risk.
Situation A: You Downloaded the File but Did Not Open It
If you only downloaded the attachment but never opened or executed it, the risk is generally lower.
Do not open the file to investigate it.
Delete or quarantine it and run an antivirus/security scan.
However, security teams may prefer to preserve a suspicious attachment for analysis. In a corporate environment, contact IT before permanently deleting evidence.
Situation B: You Opened the Attachment
If you opened the suspicious attachment, treat the device as potentially compromised.
The FTC notes that phishing links and attachments can result in harmful malware being downloaded onto a device.
The type of attachment matters.
Suspicious attachments may include:
.exe.msi.scr.js.vbs.bat.cmd.ps1.hta.lnk.zip.rar.iso.img- Microsoft Word documents
- Microsoft Excel files
- PDFs
- OneNote files
- Password-protected archives
Even apparently ordinary documents can be used as part of an attack chain.
Step 1: Stop Interacting with the Suspicious File
Do not:
- Open it again
- Run it again
- Forward it to colleagues
- Upload it randomly to websites
- Enable macros
- Enable editing because the document asks you to
- Enter credentials requested by the document
Preserve the original phishing email if your IT/security team may need it for investigation.
Step 2: Disconnect a Potentially Infected Computer from the Network
If you executed a suspicious program, enabled malicious content, or have strong reason to believe malware ran, disconnecting the device from the network can help contain the incident.
Disconnect:
- Ethernet
- Wi-Fi
- VPN connections
For business computers, contact IT/security immediately.
Do not automatically power off a corporate computer unless instructed by your incident-response team because security investigators may need information from the running system.
Step 3: Update Your Security Software
Make sure the security software has current malware definitions before performing the appropriate scan, where practical.
CISA recommends regularly updated antivirus, firewall, email-filtering and antispyware protections.
The FTC also advises keeping security software updated.
Step 4: Run a Full Antivirus Scan
On Windows systems using Microsoft Defender:
Open:
Windows Security → Virus & threat protection → Scan options → Full scan
A Full Scan examines substantially more content than a Quick Scan and may take considerable time.
Do not assume the computer is clean simply because no warning appeared when you opened the attachment.
Some malware operates silently.
Step 5: Consider Microsoft Defender Offline Scan
For a Windows computer where malware infection is strongly suspected, an offline scan can provide another layer of inspection.
Open:
Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan
The computer restarts and performs scanning outside the normal Windows environment, which can help identify some threats that attempt to hide while Windows is running.
Step 6: Change Passwords from a Known-Clean Device
This is extremely important.
If the attachment executed malware, the computer could potentially contain:
- Keyloggers
- Information stealers
- Browser credential stealers
- Remote-access malware
- Spyware
Therefore, avoid changing critical passwords from a computer you strongly suspect is infected.
Instead, use a trusted device—for example, another secured computer or smartphone—to change important passwords.
Prioritize:
- Primary email account
- Microsoft/Google account
- Password manager
- Banking accounts
- Business applications
- Cloud-storage accounts
- Domain and hosting accounts
- Social-media accounts
Step 7: Consider Browser Data Exposure
Modern information-stealing malware may target more than passwords.
Depending on the malware and browser configuration, attackers may attempt to obtain:
- Saved passwords
- Cookies
- Session information
- Autofill information
- Browser history
- Cryptocurrency-related information
- Authentication data
Therefore, changing only one password may not always be sufficient following a confirmed malware infection.
Important sessions may also need to be revoked.
Step 8: Inspect the System for Suspicious Persistence
Technical users and administrators may investigate areas commonly abused for persistence, including:
- Startup applications
- Windows services
- Scheduled Tasks
- Browser extensions
- Registry Run keys
- Recently installed applications
- Unknown user accounts
- PowerShell activity
- Unusual processes
However, manually deleting suspicious entries without understanding them can damage Windows or destroy forensic evidence.
In a business environment, endpoint security or incident-response personnel should perform this investigation.
Step 9: Check Browser Extensions
Open your browser's extension-management page and look for:
- Extensions you did not install
- Recently installed extensions
- Extensions requesting excessive permissions
- Extensions claiming to provide security updates
- Unknown PDF converters
- Unknown search extensions
- Unknown coupon or productivity extensions
Remove suspicious extensions and investigate how they were installed.
Step 10: Monitor Financial and Online Accounts
If phishing exposed financial information, contact the appropriate financial institution.
Microsoft recommends notifying banks or credit-card companies when relevant financial information may have been compromised.
Monitor accounts for:
- Unauthorized payments
- Unknown beneficiaries
- Password-reset attempts
- Changed contact information
- Unknown devices
- Unexpected OTP requests
- Suspicious transactions
Never approve an MFA request or OTP that you did not initiate.
Understanding the Difference Between Downloading and Opening an Attachment
| Action | Typical Risk |
|---|---|
| Received phishing email but did nothing | Low |
| Viewed email only | Usually low |
| Downloaded attachment but did not open it | Lower, but investigate |
| Opened PDF/document | Moderate depending on content and vulnerabilities |
| Enabled macros/content | High |
| Opened executable/script | High |
| Entered credentials after opening attachment | Critical |
| Installed software requested by attacker | Critical |
| Gave attacker remote access | Critical |
These are general risk levels rather than guarantees. Actual risk depends on the file, operating system, security controls and what occurred after the attachment was opened.
What If I Entered My Password AND Opened the Attachment?
Treat the situation as both:
Credential compromise + possible endpoint compromise.
Recommended response:
- Stop interacting with the suspicious website/file.
- If malware may have executed, isolate the affected computer.
- Notify IT/security immediately if it is a business device.
- From a known-clean device, change the compromised password.
- Change the same password anywhere else it was reused.
- Enable or verify MFA.
- Revoke suspicious or existing sessions as appropriate.
- Review account recovery methods.
- Review email forwarding and inbox rules.
- Review connected applications.
- Scan the affected computer.
- Investigate suspicious processes, services, scheduled tasks and startup entries.
- Review login history.
- Monitor financial accounts where relevant.
- Preserve evidence for investigation.
Should I Format or Reinstall Windows After Opening a Phishing Attachment?
Not automatically.
If the attachment was downloaded but never executed, reinstalling Windows would normally be excessive.
If malware actually executed, the correct response depends on:
- Malware type
- Antivirus/EDR findings
- Whether administrator privileges were obtained
- Whether persistence was established
- Whether credentials were stolen
- Whether the computer contains sensitive business information
- Whether lateral movement may have occurred
For serious or confirmed compromise, organizations may choose to reimage the endpoint from a known-good source rather than rely solely on malware removal.
Special Warning for Business Users
A phishing incident involving a business email account should be considered potentially more serious than the compromise of an isolated personal account.
Attackers may use the mailbox to:
- Impersonate employees
- Request fraudulent payments
- Change supplier banking information
- Steal invoices
- Intercept customer communications
- Reset other business passwords
- Access cloud storage
- Send phishing messages internally
- Target accounting or finance departments
Therefore, compromised Microsoft 365, Google Workspace, accounting, administrative, domain-management, hosting, VPN or remote-access credentials should be escalated quickly.
What Not to Do After a Phishing Incident
Do not assume everything is safe simply because:
- The fake website disappeared
- The page displayed "Incorrect Password"
- Antivirus displayed no immediate warning
- The attachment appeared blank
- Nothing visibly installed
- The computer appears normal
- Your email account still works
Attackers often design malware and credential-stealing infrastructure to operate without obvious symptoms.
Also avoid entering credentials again into the phishing website to "test" whether it was fake.
How to Prevent Similar Phishing Attacks
Use Unique Passwords
Every important account should have a different password.
A password manager makes this considerably easier.
Enable MFA
Enable multifactor authentication on important services.
Keep Software Updated
Regularly update:
- Windows
- Browsers
- Microsoft Office
- PDF readers
- Antivirus/endpoint protection
- Email clients
- Other internet-facing applications
Never Trust Unexpected Attachments
Microsoft recommends avoiding unexpected links and attachments even when they appear to come from a trusted sender. Instead, confirm the message using another communication method.
Verify Requests Independently
If an email claims to come from your bank, supplier, cloud provider or another organization, access the organization's legitimate website independently instead of using the email's link.
The FTC similarly recommends contacting the organization using a phone number or website you already know is legitimate.
Quick Phishing Incident Response Checklist
If You Entered Your Password
Immediately:
Change password → Change reused passwords → Enable MFA → Review active sessions → Check recovery information → Check login history → Review mailbox rules → Check connected applications → Notify IT if business-related.
If You Opened an Attachment
Immediately:
Stop interacting with file → Isolate computer if malware may have executed → Notify IT → Update security tools → Run security scans → Consider offline scanning → Change critical passwords from a clean device → Revoke sessions → Investigate suspicious system activity.
Frequently Asked Questions (FAQ)
1. What should I do immediately after entering my password on a phishing website?
Immediately access the legitimate service directly and change the compromised password. Change it anywhere else it was reused, enable MFA, review active sessions and inspect the account for unauthorized changes.
2. Should I change my password even if the phishing website said the password was incorrect?
Yes.
A fake website can intentionally display an "incorrect password" message after already capturing the credentials you entered.
3. Should I change my email password first?
If your primary email account was compromised, protecting it should be a top priority because email is commonly used to reset passwords for many other accounts.
4. What happens if I use the same password on several websites?
Change the password on all of them.
Attackers can attempt credential stuffing by testing stolen username/password combinations against other services.
5. Is changing my password enough?
Not necessarily.
You should also consider MFA, active sessions, recovery information, login history, mailbox forwarding rules and connected applications.
6. Can hackers access my account even after I change my password?
Depending on the service and attack technique, previously established sessions or authorized applications may require separate revocation. Review sessions and connected applications after a compromise.
7. Should I enable two-factor authentication after phishing?
Yes. MFA can significantly reduce the risk associated with stolen passwords, although users must still remain alert to phishing attempts targeting MFA itself.
8. I downloaded a phishing attachment but did not open it. Am I infected?
Not necessarily. Merely downloading a file generally presents less risk than executing or opening it. Do not open it; delete/quarantine it appropriately and run a security scan.
9. What if I opened the attachment?
Treat the device as potentially compromised, particularly if you executed a program, enabled macros/content, entered credentials, or observed suspicious behavior.
10. Should I disconnect my computer from the internet?
If you believe malicious code actually executed, network isolation can help prevent further communication or spread. Business users should contact their IT/security team immediately.
11. Should I turn off the infected computer?
Not necessarily. In corporate incidents, shutting down a computer can destroy volatile forensic information. Disconnect it from the network and follow your organization's incident-response procedure.
12. Can a PDF attachment contain malware?
Potentially, yes. PDFs can be part of malicious attack chains, especially when exploiting vulnerable software or directing users toward malicious links or actions.
13. Can Word and Excel attachments be dangerous?
Yes. Documents may contain or trigger malicious content, exploit vulnerabilities, or persuade users to enable dangerous functionality.
14. Are ZIP files dangerous?
A ZIP file itself is an archive, but it may contain malicious executables, scripts, shortcuts or documents. Password-protected archives are also sometimes used to make automated security inspection more difficult.
15. Can antivirus detect every malicious phishing attachment?
No security product can guarantee detection of every malicious file. Layered security, updates, endpoint protection, MFA, email filtering and user awareness remain important.
16. Should I change passwords from the possibly infected computer?
For important accounts, use a known-clean device when you strongly suspect malware executed on the affected computer.
17. Can malware steal passwords saved in my browser?
Some information-stealing malware specifically targets browser-stored credentials and other authentication information. A confirmed infostealer infection therefore requires broader credential and session remediation.
18. Should I check my email forwarding settings?
Yes, especially after an email account compromise. Attackers may create forwarding or inbox rules to monitor communications or hide security notifications.
19. Should businesses report phishing incidents to IT?
Yes. Microsoft recommends notifying IT administrators when a work or school account may have been affected by phishing.
20. How can I prevent phishing attacks in the future?
Use unique passwords, MFA, updated software, reputable endpoint protection and email filtering. Avoid unexpected links and attachments and independently verify unusual requests.
Conclusion
Entering a password on a phishing website or opening a malicious email attachment should never be ignored.
If credentials were entered, assume they are compromised and change them immediately from the legitimate service, change reused passwords, enable MFA, review account activity and revoke suspicious access.
If a suspicious attachment was opened or executed, treat the computer as potentially compromised. Isolate it when appropriate, run security scans, notify IT in business environments, investigate the endpoint and change important credentials from a known-clean device.
Fast action can make the difference between a contained phishing incident and a larger account takeover, malware infection, financial fraud or business email compromise.
Security principle: If you suspect that credentials or a device have been compromised, act on the assumption that the compromise is real until reasonable investigation shows otherwise.
#Tags
#Phishing #PhishingAttack #PhishingEmail #PhishingWebsite #CyberSecurity #CybersecurityAwareness #EmailSecurity #PasswordSecurity #CompromisedPassword #StolenPassword #CredentialTheft #CredentialPhishing #Malware #MalwareAttack #MaliciousAttachment #EmailMalware #Virus #Trojan #Spyware #InfoStealer #PasswordStealer #Ransomware #MicrosoftDefender #WindowsSecurity #Antivirus #MalwareRemoval #IncidentResponse #CyberIncident #AccountSecurity #AccountCompromise #EmailHacked #MFA #MultiFactorAuthentication #TwoFactorAuthentication #PasswordManager #CredentialStuffing #BusinessEmailCompromise #BEC #Microsoft365Security #GoogleWorkspaceSecurity #GmailSecurity #OutlookSecurity #PhishingProtection #PhishingPrevention #DataSecurity #NetworkSecurity #EndpointSecurity #OnlineSafety #CyberAttack #SecurityAwareness
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.