Lock down the targeted account and any reused passwords
Speed matters. Phishing kits forward your details to the attacker within seconds, so changing the password and revoking sessions is the priority over everything else.
Order of operations
- Change the affected account's password (from a different device)
- Sign out all other sessions
- Re-enrol 2FA
- Repeat password change anywhere you reused it