The first thirty minutes
- Change that password immediately on the real site, from the real app or a typed URL.
- If you entered card details, call the card issuer and have the card blocked.
- If the page asked you to download or run anything, disconnect the device from the internet and run a full antivirus scan before using it again.
- Turn on two-factor authentication on the affected account.
The next day
- Check the account for changes: recovery details, forwarding rules, new devices, recent transactions.
- If it was a work account, tell IT today. Attackers use one mailbox to reach the whole company.
- Forward the phishing email to your provider's abuse address and, where one exists, the national phishing reporting address.
Keep this evidence
- The original message with full headers, and the URL of the fake page.
- The time you entered details, so the account owner can check logs.
Do not
- Do not open the link again to "check".
- Do not assume nothing happened because nothing is visible yet.
Who to report to
National CERT phishing address and the impersonated company. Police only if money or data was actually lost. Find the numbers and portals for your country in the reporting directory.
General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.