Confirm what you actually entered or clicked

    Pin down which credentials, codes or files reached the attacker before you start changing things.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    The fix for phishing depends on what the attacker now has. A 60-second inventory makes the next two steps far more effective.

    What 'exposed' means here

      • Just clicked a link, didn't enter anything → low risk, but device should still be checked
      • Entered username + password → that account is compromised, and any account using the same password
      • Entered a 2FA code → assume the attacker is logging in right now
      • Downloaded a file → assume malware until you've scanned the device

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security