If you entered a password, verification code, or financial details on a suspicious website, go directly to the real service using its official app or a web address you type yourself. Change exposed and reused passwords, end other sessions, enable multifactor authentication (MFA), and check account activity and recovery details. If you only opened the page, that alone does not establish that your accounts were compromised; what you entered or downloaded determines the next step.
First, work out what you shared
Do not use links or phone numbers from the suspicious page or the message that led you there. Open the service’s official app, type its known address yourself, or contact it using a number from a payment card or statement. Microsoft also recommends using a known official contact route in its phishing guidance.
- Password: Change it on the real service and anywhere else you reused it.
- Verification code or sign-in approval: Treat the account as potentially exposed. Go to the service directly, check activity, and follow its security prompts. Never give a code to someone who contacts you unexpectedly.
- Bank, payment-card, or identity details: Contact the relevant institution through a known channel. If Social Security, credit-card, or bank-account information may have been exposed, the FTC directs consumers to IdentityTheft.gov.
- Downloaded file or app: Update your existing security software and run a scan.
- No details entered and nothing downloaded: A page visit alone does not establish that your credentials were exposed. The available official guidance does not provide a reliable percentage for the risk from simply loading a suspicious website.
If you entered a password
- Open the genuine account: Use its official app or type the service’s address yourself; do not return through the suspicious link.
- Change the exposed password: Make a new, unique password for that account. Microsoft Support’s “Protect yourself from phishing” guidance says: “Immediately change the passwords on all affected accounts, and anywhere else that you might use the same password.”
- Replace reused passwords: Change the same password on every account where it was reused, starting with email and accounts that can reset other passwords. Use a different password for each account.
- End other sessions: If the service offers a sign-out-everywhere or session-management control, use it to sign out other devices or sessions.
- Turn on MFA: Enable multifactor authentication on important accounts wherever it is available.
- Inspect account security: Review sign-in activity and alerts, and check that recovery email addresses and phone numbers are yours.
A password manager can help keep passwords unique, but it is optional and does not replace changing exposed credentials or reviewing sessions.
If you shared a verification code or approved a sign-in
Go to the account through its official app or a typed address, then review recent activity and respond to any security prompts. A code or approval can help someone complete a sign-in, so do not assume the password alone is the only credential at risk. If you receive an unexpected request for a code or approval, deny it and do not share the code.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Review activity and secure recovery options
Look for sign-ins you do not recognize and use the provider’s own security interface to report them or mark them unauthorized. Check the time, device, and other details the provider shows. Google’s account security guidance recommends responding promptly to alerts and securing the account if activity is unfamiliar. Microsoft account holders can review the Recent activity page and use its security controls for unrecognized events.
Check recovery email addresses and phone numbers as well as any other recovery details the provider allows you to review. Remove details you do not recognize. If the account is for work or school, alert your organization’s IT support team so it can help secure the account.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
If you can no longer sign in
Use the affected provider’s official account-recovery instructions, reached through its app or a known address—not a recovery link in the suspicious message. After regaining control, check recovery email addresses and phone numbers for changes you did not make. The FTC’s hacked-account recovery guidance includes this check.
Choose an MFA method your accounts support
MFA adds a second verification step beyond a password. CISA describes text or email codes, authenticator apps, and biometrics as examples; the FTC also discusses security keys. Which methods you can use depends on the service and account. Compare options by checking what each account supports, how you would recover access if you lost your phone or key, and how easily you can enable the method across important accounts.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
A security key is an optional factor for accounts that support it; getting one does not replace changing exposed passwords, ending sessions, or checking recovery details. For password length, the FTC’s October 2024 consumer alert suggests 12 to 15 characters. That is advice from that alert, not a universal security threshold.
If you only visited the suspicious website
A visit by itself does not prove that an account was compromised. Check whether you typed a password, shared a one-time code, approved a sign-in, entered financial or identity details, or downloaded and opened a file or app. If none of those happened, the guidance cited here does not establish that your account credentials were exposed just because the page loaded. If a download may have occurred, update security software and scan the device.
Rank #4
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
When to contact an institution or report identity theft
If you shared bank or card details, contact the bank or card provider using the number on your card or statement, or its genuine website. For potentially exposed Social Security, credit-card, or bank-account information, use IdentityTheft.gov for official U.S. recovery guidance. If you lost money or experienced identity theft, follow the relevant official reporting and recovery instructions.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute




