Confirm what you actually entered or clicked
The fix for phishing depends on what the attacker now has. A 60-second inventory makes the next two steps far more effective.
What 'exposed' means here
- Just clicked a link, didn't enter anything → low risk, but device should still be checked
- Entered username + password → that account is compromised, and any account using the same password
- Entered a 2FA code → assume the attacker is logging in right now
- Downloaded a file → assume malware until you've scanned the device