Lock down the targeted account and any reused passwords

    Change the password, kill active sessions, and assume the attacker is currently logged in.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Speed matters. Phishing kits forward your details to the attacker within seconds, so changing the password and revoking sessions is the priority over everything else.

    Order of operations

      1. Change the affected account's password (from a different device)
      2. Sign out all other sessions
      3. Re-enrol 2FA
      4. Repeat password change anywhere you reused it

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security