If you typed a password into a page reached from a suspicious message, act as though someone else may know it. You do not need to prove the page was malicious before protecting the account. Start on a device you trust, and open the real service by typing its address yourself or using its app.
Do these first
- Change the password on the real site. Choose a new, unique password; do not use the link from the message.
- If you reused that password anywhere else, change it on those accounts too. Start with your email account, since it may be used to reset other passwords.
- Review recent sign-ins, connected devices and recovery email/phone. Sign out unfamiliar sessions using the service's own security settings.
- Turn on multifactor authentication (MFA) if it is available. Save recovery codes somewhere separate from the account.